Exposição de PHP

Programming languages
891
score de exposição
4.429.701
sites usam
2
em exploração
45
críticos
Análise Vexday

Com 1.079 CVEs catalogadas e 74 surgidas apenas nos últimos 90 dias, o PHP apresenta um volume de vulnerabilidades que exige monitoramento contínuo. A taxa de exploração ativa — 2 entradas no catálogo KEV, equivalente a 0,19% do total — está abaixo da média geral do catálogo (0,45%), o que não elimina o risco, mas indica que a conversão de vulnerabilidades em exploração confirmada tem sido relativamente contida. Atenção especial merece a CVE-2024-4577, atualmente a falha mais perigosa em exploração ativa, com EPSS de 0,9999 — valor que sinaliza probabilidade altíssima de exploração —, reforçando a necessidade de aplicação imediata de correções em ambientes expostos. O tipo de falha mais recorrente, CWE-89 (injeção de SQL), combinado com 43 vulnerabilidades críticas no histórico, indica que revisão de práticas de codificação segura e atualização de versões continuam sendo controles prioritários para quem opera aplicações baseadas em PHP.

CVEs

1.117 resultados
CVE-2020-5558CuteNews 2.0.1 allows remote authenticated attackers to execute arbitrary PHP code via unspecified vectors.EPSS 2.1%CVE-2022-31627HIGHHeap buffer overflow in finfo_bufferEPSS 2.0%CVE-2019-11037MEDIUMOut of bounds memory write in PHP Imagick extensionEPSS 2.0%CVE-2021-29454HIGHSandbox Escape by math function in smartyEPSS 1.9%CVE-2024-2757HIGHPHP mb_encode_mimeheader runs endlessly for some inputsEPSS 1.9%CVE-2021-21704MEDIUMMultiple vulnerabilities in Firebird client extensionEPSS 1.9%CVE-2023-4110LOWPHP Jabbers Availability Booking Calendar index.php cross site scriptingEPSS 1.8%CVE-2025-7160MEDIUMPHPGurukul Zoo Management System index.php sql injectionEPSS 1.7%CVE-2011-4082A local file inclusion flaw was found in the way the phpLDAPadmin before 0.9.8 processed certain values of the "Accept-Language" HTTP headerEPSS 1.7%CVE-2020-7068MEDIUMUse of freed hash key in the phar_parse_zipfile functionEPSS 1.7%CVE-2020-7063MEDIUMFiles added to tar with Phar::buildFromIterator have all-access permissionsEPSS 1.6%CVE-2021-47749HIGHYouPHPTube <= 7.8 - Directory TraversalEPSS 1.6%CVE-2024-11233MEDIUMSingle byte overread with convert.quoted-printable-decode filterEPSS 1.6%CVE-2010-4657PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This resultEPSS 1.5%CVE-2023-4117MEDIUMPHP Jabbers Rental Property Booking index.php cross site scriptingEPSS 1.5%CVE-2023-0676LOWCross-site Scripting (XSS) - Reflected in phpipam/phpipamEPSS 1.5%CVE-2016-9493PHP forms generated using the PHP FormMail Generator are vulnerable to stored cross-site scriptingEPSS 1.5%CVE-2024-3096MEDIUMPHP function password_verify can erroneously return true when argument contains NULEPSS 1.5%CVE-2023-3767CRITICALOS command injection on EasyPHP Webserver EPSS 1.5%CVE-2023-7173MEDIUMPHPGurukul Hospital Management System registration.php cross site scriptingEPSS 1.5%