CVE-2015-9253medium · CVSS 6.5 — An issue was discovered in PHP 7.3.x before 7.3.0alpha3, 7.2.x before 7.2.8, and before 7.1.20. The php-fpm master process restarts a child
CVE-2018-19395high · CVSS 7.5 — ext/standard/var.c in PHP 5.x through 7.1.24 on Windows allows attackers to cause a denial of service (NULL pointer dereference and applicat
CVE-2018-19396high · CVSS 7.5 — ext/standard/var_unserializer.c in PHP 5.x through 7.1.24 allows attackers to cause a denial of service (application crash) via an unseriali
CVE-2019-9637high · CVSS 7.5 — An issue was discovered in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. Due to the way rename() across filesystems is imp
CVE-2019-9638high · CVSS 7.5 — An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized r
CVE-2019-9639high · CVSS 7.5 — An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized r
CVE-2019-9641critical · CVSS 9.8 — An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized r
CVE-2022-31628low · CVSS 2.3 — In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in
CVE-2022-31629medium · CVSS 6.5 — In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cooki
CVE-2022-4900medium · CVSS 6.2 — A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overf
CVE-2024-3566critical · CVSS 9.8 — A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateP