Known vulnerabilities in PHP - page 22

Vendor: PHP Group
Software: PHP
Software CPE: cpe:2.3:a:php_group:php:*:*:*:*:*:*:*:*
Total vulnerabilities: 695
Public exploits: 156
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting PHP PHP is affected by 695 known vulnerabilities: 6 critical, 124 high, 373 medium, 192 low Critical High Medium Low

Vulnerabilities (695)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU10880 - Resource exhaustion
CVE-2015-9253
CWE-400 Low
No
No
- 07.03.2018 SB2018021618
SB2018091805
SB2020021722
and 3 more
#VU10390 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2018-5711
CWE-835 Low
No
No
- 07.02.2018 SB2018020401
SB2018020703
SB2018020902
and 13 more
#VU10389 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-5712
CWE-79 Low
No
No
- 06.02.2018 SB2018020401
SB2018020703
SB2018020902
and 14 more
#VU10351 - Improper input validation
CWE-20 Low
No
No
- 01.02.2018 SB2018020113
#VU10350 - Missing release of memory after effective lifetime
CWE-401 Low
No
No
- 01.02.2018 SB2018020113
#VU10349 - Improper Access Control
CWE-284 Low
No
No
- 01.02.2018 SB2018020113
#VU10348 - Memory corruption
CWE-119 Low
No
No
- 01.02.2018 SB2018020113
#VU10347 - Memory corruption
CWE-119 Low
No
No
- 01.02.2018 SB2018020113
#VU9869 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-5712
CWE-79 Low
No
No
- 04.01.2018 SB2018010412
SB2018011109
#VU9868 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2018-5711
CWE-835 Low
No
No
- 04.01.2018 SB2018010412
SB2018011109
#VU9467 - Type confusion
CWE-843 Low
No
No
- 30.11.2017 SB2017113007
#VU9466 - Improper input validation
CWE-20 Low
No
No
- 30.11.2017 SB2017113007
#VU9465 - Deserialization of Untrusted Data
CWE-502 Low
No
No
- 30.11.2017 SB2017113007
#VU9464 - Buffer overflow
CWE-120 Low
No
No
- 30.11.2017 SB2017113007
#VU9407 - Missing release of memory after effective lifetime
CWE-401 Low
No
No
- 23.11.2017 SB2017112302
#VU9406 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-22 Low
No
No
- 23.11.2017 SB2017112302
#VU9405 - Improper Access Control
CWE-284 Low
No
No
- 23.11.2017 SB2017112302
#VU8966 - NULL Pointer Dereference
CWE-476 Low
No
No
- 27.10.2017 SB2017102708
#VU8965 - Out-of-bounds read
CVE-2017-11145
CWE-125 Low
No
No
- 27.10.2017 SB2017102708
SB2017121805
SB2018011105
and 2 more
#VU9867 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2015-8866
CWE-611 Medium
No
No
- 22.05.2016 SB2018010412
SB2018011109


Showing elements 421 - 440 out of 695