首页 > 专栏 > PHP Bugs PHP Bugs 共 248 条资讯 [$15000] HackerOne: IDOR allows user to access report details via reference.json endpoint 2026-06-27 16:20:01 MariaDB: Connector/J: malicious server crashes client JVM via unbounded result-set field-count allocation in ClientMessage.readPacket 2026-06-27 16:20:01 MariaDB: Connector/C Out-of-bounds read in `unpack_fields()` from short metadata field 2026-06-27 16:20:01 Nextcloud: SSRF via User-Controlled Push proxyServer in Notifications Push Registration 2026-06-27 16:20:01 WordPress: Unauthenticated disclosure of draft/private/pending post titles & IDs via Secure Custom Fields nopriv AJAX field-query handlers (post_object/relations 2026-06-27 16:20:01 curl: Missing applicability validation allows non-applicable HTTPS RR to reach ECH processing 2026-06-27 16:20:01 curl: [HIGH] CWE-22 — Path Traversal in FTP Wildcard Download via Unencoded `.` in Escaped Filenames 2026-06-27 16:20:01 [$200] HackerOne: HackerOne Code sends live password-reset tokens to Segment in automatic page events 2026-06-27 16:20:01 curl: Windows filename sanitizer misses Unicode COM/LPT reserved device names 2026-06-27 16:20:01 [$150] Nextcloud: PIN bypass in PassCodeActivity via back button 2026-06-27 16:20:01 curl: TELNET control and environment data bypass HTTPS-proxy TLS 2026-06-27 16:20:01 curl: Use-after-free of the internal multi->admin easy handle via the documented CURLMOPT_NOTIFYFUNCTION callback 2026-06-27 16:20:01 curl: HTTP/1.1 response framing violation and unsafe connection reuse when transfer decoding is disabled 2026-06-27 16:20:01 Nextcloud: Improper input validation in emoji field leads to sidebar UI denial of service 2026-06-27 16:20:01 Essity: Unauthenticated API allows reading, writing to and deleting any user's private chat history on ████████ 2026-06-27 16:20:01 [$150] Nextcloud: Group restriction bypass via bearer token in user_oidc (SETTING_RESTRICT_LOGIN_TO_GROUPS not enforced in Backend::getCurrentUserId) 2026-06-27 16:20:01 curl: Socket API drops expired timeouts for transfers queued behind a connection limit 2026-06-27 16:20:01 Nextcloud: Persistent SMTP header injection via identity `organization` / `name` 2026-06-27 16:20:01 Nextcloud: files_lock: a write-share collaborator can place a TYPE_TOKEN lock that permanently denies the file owner, survives share revocation and account delet 2026-06-27 16:20:01 AWS VDP: Incomplete Input Sanitization in CodeInterpreter install_packages Allows Command Injection via pip Flags 2026-06-27 16:20:01 123…13下一页 » 相关分类 P #!/slash/note #UNTAG (B)(F)uzzing on my world (Hi)story (IN)SECURE Magazine Notification (gdb) break *0x972 - 带鱼博客 BeltfishBlog - ./kwaa.dev .NET Blog .Trash /home/rook1e 00's Adventure 0kami's Blog 0x41414141 in ?? () 0x7f Blog 0xRick Owned Root ! 0xd00's blog 1 Byte 1A23 Blog 1A23 Studio 1Link.Fun 1stwebdesigner 251 2BAB 的工程博客 2ch中文网 360 CERT 360 Netlab Blog - Network Securi 38号车评中心 3o米的微博