Exposição de PHP

Programming languages
885
score de exposição
4.429.701
sites usam
2
em exploração
45
críticos
Análise Vexday

Com 1.079 CVEs catalogadas e 74 surgidas apenas nos últimos 90 dias, o PHP apresenta um volume de vulnerabilidades que exige monitoramento contínuo. A taxa de exploração ativa — 2 entradas no catálogo KEV, equivalente a 0,19% do total — está abaixo da média geral do catálogo (0,45%), o que não elimina o risco, mas indica que a conversão de vulnerabilidades em exploração confirmada tem sido relativamente contida. Atenção especial merece a CVE-2024-4577, atualmente a falha mais perigosa em exploração ativa, com EPSS de 0,9999 — valor que sinaliza probabilidade altíssima de exploração —, reforçando a necessidade de aplicação imediata de correções em ambientes expostos. O tipo de falha mais recorrente, CWE-89 (injeção de SQL), combinado com 43 vulnerabilidades críticas no histórico, indica que revisão de práticas de codificação segura e atualização de versões continuam sendo controles prioritários para quem opera aplicações baseadas em PHP.

CVEs

1.117 resultados
CVE-2023-1211HIGH SQL Injection in phpipam/phpipamEPSS 3.0%CVE-2021-21708HIGHUAF due to php_filter_float() failingEPSS 3.0%CVE-2020-7071MEDIUMFILTER_VALIDATE_URL accepts URLs with invalid userinfoEPSS 3.0%CVE-2013-4462WordPress Portable phpMyAdmin Plugin has an authentication bypass vulnerabilityEPSS 2.8%CVE-2024-45293HIGHXML External Entity Reference (XXE) in PHPSpreadsheet's XLSX readerEPSS 2.8%CVE-2020-7066MEDIUMget_headers() silently truncates after a null byteEPSS 2.8%CVE-2020-4043HIGHPhar unserialization vulnerability in phpMusselEPSS 2.6%CVE-2023-3187MEDIUMPHPGurukul Teachers Record Management System Profile Picture changeimage.php unrestricted uploadEPSS 2.6%CVE-2023-4117MEDIUMPHP Jabbers Rental Property Booking index.php cross site scriptingEPSS 2.5%CVE-2023-4111MEDIUMPHP Jabbers Bus Reservation System index.php cross site scriptingEPSS 2.5%CVE-2022-39261HIGHTwig may load a template outside a configured directory when using the filesystem loaderEPSS 2.5%CVE-2025-2473MEDIUMPHPGurukul Company Visitor Management System Sign In index.php sql injectionEPSS 2.4%CVE-2020-13567HIGHMultiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker canEPSS 2.3%CVE-2024-8929MEDIUMLeak partial content of the heap through heap buffer over-read in mysqlndEPSS 2.3%CVE-2021-3603HIGHInclusion of Functionality from Untrusted Control Sphere in PHPMailer/PHPMailerEPSS 2.3%CVE-2021-21408HIGHAccess to restricted PHP code by dynamic static class access in smartyEPSS 2.2%CVE-2022-31630MEDIUMOOB read due to insufficient input validation in imageloadfont()EPSS 2.2%CVE-2022-31631CRITICALPDO::quote() may return unquoted stringEPSS 2.1%CVE-2021-21705MEDIUMIncorrect URL validation in FILTER_VALIDATE_URLEPSS 2.1%CVE-2024-11236CRITICALInteger overflow in the firebird and dblib quoters causing OOB writesEPSS 2.1%