Exposição de PHP

Programming languages
891
score de exposição
4.429.701
sites usam
2
em exploração
45
críticos
Análise Vexday

Com 1.079 CVEs catalogadas e 74 surgidas apenas nos últimos 90 dias, o PHP apresenta um volume de vulnerabilidades que exige monitoramento contínuo. A taxa de exploração ativa — 2 entradas no catálogo KEV, equivalente a 0,19% do total — está abaixo da média geral do catálogo (0,45%), o que não elimina o risco, mas indica que a conversão de vulnerabilidades em exploração confirmada tem sido relativamente contida. Atenção especial merece a CVE-2024-4577, atualmente a falha mais perigosa em exploração ativa, com EPSS de 0,9999 — valor que sinaliza probabilidade altíssima de exploração —, reforçando a necessidade de aplicação imediata de correções em ambientes expostos. O tipo de falha mais recorrente, CWE-89 (injeção de SQL), combinado com 43 vulnerabilidades críticas no histórico, indica que revisão de práticas de codificação segura e atualização de versões continuam sendo controles prioritários para quem opera aplicações baseadas em PHP.

CVEs

1.117 resultados
CVE-2023-7172HIGHPHPGurukul Hospital Management System Admin Dashboard sql injectionEPSS 1.5%CVE-2013-10070CRITICALPHP-Charts v1.0 PHP Code ExecutionEPSS 1.5%CVE-2024-9326MEDIUMPHPGurukul Online Shopping Portal Admin Panel index.php sql injectionEPSS 1.4%CVE-2021-21706MEDIUMZipArchive::extractTo may extract outside of destination dirEPSS 1.4%CVE-2023-0662HIGHDoS vulnerability when parsing multipart request bodyEPSS 1.4%CVE-2020-8521SQL injection with start and length parameters in Records.php for phpzag live add edit delete data tables records with ajax php mysqlEPSS 1.4%CVE-2020-8520SQL injection in order and column parameters in Records.php for phpzag live add edit delete data tables records with ajax php mysqlEPSS 1.4%CVE-2020-8519SQL injection with the search parameter in Records.php for phpzag live add edit delete data tables records with ajax php mysqlEPSS 1.4%CVE-2024-11235CRITICALReference counting in php_request_shutdown causes Use-After-FreeEPSS 1.4%CVE-2023-3823HIGHSecurity issue with external entity loading in XML without enabling itEPSS 1.4%CVE-2021-21703HIGHPHP-FPM memory access in root process leading to privilege escalationEPSS 1.3%CVE-2022-0813MEDIUMPhpMyAdmin exposure of sensitive informationEPSS 1.3%CVE-2024-8932CRITICALOOB access in ldap_escapeEPSS 1.3%CVE-2024-3690MEDIUMPHPGurukul Small CRM Change Password sql injectionEPSS 1.3%CVE-2023-0568HIGHArray overrun in common path resolve codeEPSS 1.2%CVE-2019-16774MEDIUMObject injection in cookie driverEPSS 1.2%CVE-2012-10037CRITICALPhpTax pfilez Parameter Exec Remote Code InjectionEPSS 1.2%CVE-2026-42569CRITICALphpvms: /importer authorization bypass causing full database wipeEPSS 1.2%CVE-2024-2408MEDIUMPHP is vulnerable to the Marvin AttackEPSS 1.2%CVE-2024-11234MEDIUMConfiguring a proxy in a stream context might allow for CRLF injection in URIsEPSS 1.1%