CVE-2024-4577: PHP CGI Argument Injection
A critical argument injection vulnerability in PHP CGI, used by Evooo1Bot.
A critical argument injection vulnerability in PHP CGI, used by Evooo1Bot.
emer-run.php is a PHP web shell installed via a fake plugin in the BdThemes supply chain attack, enabling remote code execution on…
A public proof-of-concept (PoC) has been released for CVE-2026-55200, a critical vulnerability in the libssh2 client-side SSH library. The flaw, with a…
PHP deployments often include libssh2, making them a common carrier for the vulnerability.
Packagist is the main package repository for PHP that was used to distribute malicious development versions of 10 packages associated with a…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a maximum-severity vulnerability affecting the Widget Factory Joomla Content Editor (JCE) to…