CVE Tracker
6 recordsEvery published CVE from the last 120 days with CVSS score, vendor and product, cross-referenced against CISA's Known Exploited Vulnerabilities catalog. 10 added to KEV in the last 7 days.
| CVE | CVSS | EPSS | KEV sources | Patch window | Vendor / product | Summary | Published |
|---|
| CVE-2026-17544 | 9.8 | — | — | — | php / php | Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP ve | 37d ago |
| CVE-2026-17543 | 9.8 | — | — | — | php / php | Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP vers | 37d ago |
| CVE-2026-7261 | 9.8 | — | — | — | php / php | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapSer | 119d ago |
| CVE-2026-6722 | 9.8 | — | — | — | php / php | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP ext | 119d ago |
| CVE-2025-14179 | 9.8 | — | — | — | php / php | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Fir | 119d ago |
| CVE-2026-6104 | 9.1 | — | — | — | php / php | In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte i | 119d ago |
Sources: NIST National Vulnerability Database (descriptions, CVSS, CPE); CISA KEV, ENISA EUVD, CIRCL and VulnCheck (exploitation status, three catalogues counted; CIRCL shown as an aggregator); FIRST EPSS (exploitation probability). Patch window is the gap between CVE publication and the earliest KEV listing, so a negative value means a catalogue called it exploited before it was disclosed. Data refreshes every five hours.