Loading HuntDB...

PHP Group

2 Products 65 CVEs

CVE Severity Distribution (All Time)

Critical
5
High
16
Medium
36
Low
8

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 9 CVEs

Recent CVEs

View all
CVE-2024-11233 MEDIUM 7 months, 1 week ago

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data…

CVE-2024-11234 MEDIUM 7 months, 1 week ago

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, when using streams with configured proxy and "request_fulluri" option,…

CVE-2024-11236 CRITICAL 7 months, 1 week ago

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit sy…

CVE-2024-8929 MEDIUM 7 months, 1 week ago

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of…

CVE-2024-8932 CRITICAL 7 months, 1 week ago

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit sy…

CVE-2024-9026 LOW 8 months, 3 weeks ago

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configured to catch workers output t…

CVE-2024-8927 HIGH 8 months, 3 weeks ago

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI bina…

CVE-2024-8926 HIGH 8 months, 3 weeks ago

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using a certain non-standard configurations of Windows codepages,…

CVE-2024-8925 LOW 8 months, 3 weeks ago

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST req…

Related Security News

GreenboneOS: Escalating Attacks Targeting CVE-2024-4577 in PHP-CGI for Windows
2025-03-26 12:48 Greenbone.net

CVE-2024-4577 (CVSS 9.8 Critical) is currently climbing the winners’ podium of the most malicious security vulnerabilities. Disclosed in early June 2024 by Devcore security researchers, weaponization…

Hackers Exploit Severe PHP Flaw to Deploy Quasar RAT and XMRig Miners
2025-03-19 15:52 Internet

Threat actors are exploiting a severe security flaw in PHP to deliver cryptocurrency miners and remote access trojans (RATs) like Quasar RAT. The vulnerability, assigned the CVE identifier CVE-2024-4…

Experts warn of mass exploitation of critical PHP flaw CVE-2024-4577
2025-03-10 14:52 Securityaffairs.com

Threat actors exploit PHP flaw CVE-2024-4577 for remote code execution. Over 1,000 attacks detected globally. GreyNoise researchers warn of a large-scale exploitation of a critical vulnerability, tra…

Grootschalig misbruik van kritieke PHP-CGI-kwetsbaarheid gemeld
2025-03-10 09:41 Security.nl

Aanvallers maken op grote schaal misbruik van een bekende, kritieke PHP-CGI-kwetsbaarheid aangeduid als CVE-2024-4577, zo meldt ...

PHP-CGI RCE Flaw Exploited in Attacks on Japan's Tech, Telecom, and E-Commerce Sectors
2025-03-07 04:42 Internet

Threat actors of unknown provenance have been attributed to a malicious campaign predominantly targeting organizations in Japan since January 2025. "The attacker has exploited the vulnerability CVE-2…