[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2020-7066":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T08:55:32.481Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":27,"aliases":37,"duplicate_of":9,"upstream":38,"downstream":39,"duplicates":70,"related":71,"reserved_at":9,"published_at":78,"modified_at":79,"state":80,"summary":81,"references_raw":89,"kevs":134,"epss":135,"epss_history":138,"metrics":406,"affected":421},"CVE-2020-7066","In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using get_headers() with user-supplied URL, if the URL contains zero (\\0) character, the URL will be silently truncated at it. This may cause some software to make incorrect assumptions about the target of the get_headers() and possibly send some information to a wrong server.",null,[11,18],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":9,"likelihood_of_exploit":9,"capec":17},"NVD-CWE-OTHER","Other","NVD uses this CWE ID when the weakness does not map to any existing CWE entry.","placeholder","NVD-Reserved",[],{"_key":19,"id":19,"name":20,"description":21,"type":22,"status":23,"abstraction":24,"likelihood_of_exploit":25,"capec":26},"CWE-170","Improper Null Termination","The product does not terminate or incorrectly terminates a string or array with a null character or equivalent terminator.","weakness","Incomplete","Base","Medium",[],[28],{"_key":29,"name":30,"source":31,"url":32,"maturity":33,"reliability_score":34,"verified":35,"type":9,"platforms":36,"requires_auth":9,"exploitdb":9,"metasploit":9},"REF_DD2160F72ABB5327","Exploit Reference (bugs.php.net)","reference","https://bugs.php.net/bug.php?id=79329","unknown",0.2,false,[],[],[],[40,42,44,46,48,50,52,54,56,58,60,62,64,66,68],{"_key":41},"SUSE-SU-2020:1199-1",{"_key":43},"SUSE-SU-2020:1546-1",{"_key":45},"SUSE-SU-2020:1714-1",{"_key":47},"SUSE-SU-2022:4067-1",{"_key":49},"OPENSUSE-SU-2020:0642-1",{"_key":51},"RHSA-2020:5275",{"_key":53},"DLA-2188-1",{"_key":55},"DSA-4717-1",{"_key":57},"DSA-4719-1",{"_key":59},"MGASA-2020-0148",{"_key":61},"UBUNTU-CVE-2020-7066",{"_key":63},"USN-4330-1",{"_key":65},"USN-4330-2",{"_key":67},"DEBIAN-CVE-2020-7066",{"_key":69},"RHSA-2020:3662",[],[72,73,74,75,76,77],{"_key":41},{"_key":43},{"_key":45},{"_key":47},{"_key":49},{"_key":59},"2020-04-01T03:35:14.021Z","2024-09-17T01:51:01.194Z","Modified",{"cisa_kev":35,"cisa_ransomware":35,"cisa_vendor":9,"epss_severity":82,"epss_score":83,"severity":84,"severity_score":85,"severity_version":86,"severity_source":87,"severity_vector":88,"severity_status":80},"low",0.02189,"medium",5.3,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",[90,99,105,111,116,121,126,130],{"url":32,"sources":91,"tags":93},[87,92],"nvd",[94,95,96,97,98],"X Refsource MISC","Exploit","Issue Tracking","Patch","Vendor Advisory",{"url":100,"sources":101,"tags":102},"https://security.netapp.com/advisory/ntap-20200403-0001/",[87,92],[103,104],"X Refsource CONFIRM","Third Party Advisory",{"url":106,"sources":107,"tags":108},"https://lists.debian.org/debian-lts-announce/2020/04/msg00021.html",[87,92],[109,110,104],"Mailing List","X Refsource MLIST",{"url":112,"sources":113,"tags":114},"https://usn.ubuntu.com/4330-2/",[87,92],[98,115,104],"X Refsource UBUNTU",{"url":117,"sources":118,"tags":119},"http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00025.html",[87,92],[98,120,104],"X Refsource SUSE",{"url":122,"sources":123,"tags":124},"https://www.debian.org/security/2020/dsa-4717",[87,92],[98,125,104],"X Refsource DEBIAN",{"url":127,"sources":128,"tags":129},"https://www.debian.org/security/2020/dsa-4719",[87,92],[98,125,104],{"url":131,"sources":132,"tags":133},"https://www.tenable.com/security/tns-2021-14",[87,92],[103,97,104],[],{"date":136,"score":83,"percentile":137},"2026-06-04",0.84689,[139,143,146,149,152,155,158,161,164,167,170,173,176,179,182,186,189,192,196,199,202,205,208,211,214,217,220,223,226,229,232,235,238,241,244,247,250,253,256,259,262,265,268,271,274,277,280,282,285,288,291,294,297,299,303,306,309,312,315,318,321,324,327,329,332,334,337,340,343,346,348,351,354,356,359,362,365,368,371,374,377,380,383,386,388,391,394,397,400,403],{"date":140,"score":141,"percentile":142},"2025-11-04",0.0137,0.79585,{"date":144,"score":141,"percentile":145},"2025-11-05",0.79586,{"date":147,"score":141,"percentile":148},"2025-11-06",0.79589,{"date":150,"score":141,"percentile":151},"2025-11-07",0.79601,{"date":153,"score":141,"percentile":154},"2025-11-08",0.79608,{"date":156,"score":141,"percentile":157},"2025-11-09",0.79604,{"date":159,"score":141,"percentile":160},"2025-11-10",0.79594,{"date":162,"score":141,"percentile":163},"2025-11-11",0.79597,{"date":165,"score":141,"percentile":166},"2025-11-12",0.79612,{"date":168,"score":141,"percentile":169},"2025-11-13",0.79621,{"date":171,"score":141,"percentile":172},"2025-11-14",0.79627,{"date":174,"score":141,"percentile":175},"2025-11-15",0.79625,{"date":177,"score":141,"percentile":178},"2025-11-16",0.79626,{"date":180,"score":141,"percentile":181},"2025-11-17",0.79624,{"date":183,"score":184,"percentile":185},"2025-11-18",0.02349,0.83562,{"date":187,"score":184,"percentile":188},"2025-11-19",0.83564,{"date":190,"score":184,"percentile":191},"2025-11-20",0.83569,{"date":193,"score":194,"percentile":195},"2025-11-21",0.01533,0.80748,{"date":197,"score":194,"percentile":198},"2025-11-22",0.8075,{"date":200,"score":194,"percentile":201},"2025-11-23",0.8074,{"date":203,"score":194,"percentile":204},"2025-11-24",0.80742,{"date":206,"score":194,"percentile":207},"2025-11-25",0.80746,{"date":209,"score":194,"percentile":210},"2025-11-26",0.80747,{"date":212,"score":194,"percentile":213},"2025-11-27",0.80752,{"date":215,"score":194,"percentile":216},"2025-11-28",0.80744,{"date":218,"score":194,"percentile":219},"2025-11-29",0.80749,{"date":221,"score":194,"percentile":222},"2025-11-30",0.80756,{"date":224,"score":194,"percentile":225},"2025-12-01",0.80842,{"date":227,"score":194,"percentile":228},"2025-12-02",0.80846,{"date":230,"score":194,"percentile":231},"2025-12-03",0.80845,{"date":233,"score":194,"percentile":234},"2025-12-04",0.80758,{"date":236,"score":194,"percentile":237},"2025-12-05",0.80766,{"date":239,"score":194,"percentile":240},"2025-12-06",0.80768,{"date":242,"score":194,"percentile":243},"2025-12-07",0.80769,{"date":245,"score":194,"percentile":246},"2025-12-08",0.80772,{"date":248,"score":194,"percentile":249},"2025-12-09",0.80785,{"date":251,"score":194,"percentile":252},"2025-12-10",0.80811,{"date":254,"score":194,"percentile":255},"2025-12-11",0.80822,{"date":257,"score":194,"percentile":258},"2025-12-12",0.80837,{"date":260,"score":194,"percentile":261},"2025-12-13",0.80836,{"date":263,"score":194,"percentile":264},"2025-12-14",0.80834,{"date":266,"score":194,"percentile":267},"2025-12-15",0.80831,{"date":269,"score":194,"percentile":270},"2025-12-16",0.80841,{"date":272,"score":194,"percentile":273},"2025-12-17",0.8085,{"date":275,"score":194,"percentile":276},"2025-12-18",0.80869,{"date":278,"score":194,"percentile":279},"2025-12-19",0.80875,{"date":281,"score":194,"percentile":276},"2025-12-20",{"date":283,"score":194,"percentile":284},"2025-12-21",0.80864,{"date":286,"score":194,"percentile":287},"2025-12-22",0.80862,{"date":289,"score":194,"percentile":290},"2025-12-23",0.80865,{"date":292,"score":194,"percentile":293},"2025-12-24",0.80879,{"date":295,"score":194,"percentile":296},"2025-12-25",0.80896,{"date":298,"score":194,"percentile":296},"2025-12-26",{"date":300,"score":301,"percentile":302},"2025-12-27",0.01434,0.80294,{"date":304,"score":194,"percentile":305},"2025-12-28",0.80883,{"date":307,"score":194,"percentile":308},"2025-12-29",0.80881,{"date":310,"score":194,"percentile":311},"2025-12-30",0.80888,{"date":313,"score":194,"percentile":314},"2025-12-31",0.80902,{"date":316,"score":194,"percentile":317},"2026-01-01",0.80983,{"date":319,"score":194,"percentile":320},"2026-01-02",0.8098,{"date":322,"score":194,"percentile":323},"2026-01-03",0.80976,{"date":325,"score":194,"percentile":326},"2026-01-04",0.80886,{"date":328,"score":194,"percentile":308},"2026-01-05",{"date":330,"score":194,"percentile":331},"2026-01-06",0.80885,{"date":333,"score":194,"percentile":311},"2026-01-07",{"date":335,"score":194,"percentile":336},"2026-01-08",0.80897,{"date":338,"score":194,"percentile":339},"2026-01-09",0.80899,{"date":341,"score":194,"percentile":342},"2026-01-10",0.809,{"date":344,"score":194,"percentile":345},"2026-01-11",0.80893,{"date":347,"score":194,"percentile":331},"2026-01-12",{"date":349,"score":194,"percentile":350},"2026-01-13",0.80882,{"date":352,"score":194,"percentile":353},"2026-01-14",0.80903,{"date":355,"score":194,"percentile":314},"2026-01-15",{"date":357,"score":194,"percentile":358},"2026-01-16",0.80912,{"date":360,"score":194,"percentile":361},"2026-01-17",0.80919,{"date":363,"score":194,"percentile":364},"2026-01-18",0.8091,{"date":366,"score":194,"percentile":367},"2026-01-19",0.80904,{"date":369,"score":194,"percentile":370},"2026-01-20",0.80906,{"date":372,"score":194,"percentile":373},"2026-01-21",0.80913,{"date":375,"score":194,"percentile":376},"2026-01-22",0.80922,{"date":378,"score":194,"percentile":379},"2026-01-23",0.80947,{"date":381,"score":194,"percentile":382},"2026-01-24",0.80954,{"date":384,"score":194,"percentile":385},"2026-01-25",0.80948,{"date":387,"score":194,"percentile":385},"2026-01-26",{"date":389,"score":194,"percentile":390},"2026-01-27",0.80952,{"date":392,"score":194,"percentile":393},"2026-01-28",0.8095,{"date":395,"score":194,"percentile":396},"2026-01-29",0.80946,{"date":398,"score":194,"percentile":399},"2026-01-30",0.80945,{"date":401,"score":194,"percentile":402},"2026-01-31",0.80951,{"date":404,"score":194,"percentile":405},"2026-02-01",0.81038,[407,412],{"source":87,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":408,"cvss_v4_0":9},{"baseScore":85,"baseSeverity":409,"vectorString":88,"impactScore":410,"exploitabilityScore":411},"MEDIUM",2.3,10,{"source":92,"cvss_v2_0":413,"cvss_v3_0":9,"cvss_v3_1":418,"cvss_v4_0":9},{"baseScore":414,"baseSeverity":9,"vectorString":415,"impactScore":416,"exploitabilityScore":417},4.3,"AV:N/AC:M/Au:N/C:P/I:N/A:N",2.9,8.6,{"baseScore":414,"baseSeverity":409,"vectorString":419,"impactScore":410,"exploitabilityScore":420},"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",7.2,[422,435,441,451,467],{"ecosystem":9,"name":423,"vendor":424,"product":425,"cpe_part":426,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":427},"debian linux","debian","debian_linux","o",[428,431,433],{"version":429,"is_range":35,"range_type":430,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"8.0","cpe",{"version":432,"is_range":35,"range_type":430,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"9.0",{"version":434,"is_range":35,"range_type":430,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"10.0",{"ecosystem":9,"name":436,"vendor":437,"product":436,"cpe_part":426,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":438},"leap","opensuse",[439],{"version":440,"is_range":35,"range_type":430,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"15.1",{"ecosystem":9,"name":442,"vendor":9,"product":442,"cpe_part":9,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":443},"PHP",[444,447,449],{"version":445,"is_range":35,"range_type":87,"version_start":445,"version_start_type":446,"version_end":445,"version_end_type":446,"fixed_in":9},"7.2.x below 7.2.29","including",{"version":448,"is_range":35,"range_type":87,"version_start":448,"version_start_type":446,"version_end":448,"version_end_type":446,"fixed_in":9},"7.3.x below 7.3.16",{"version":450,"is_range":35,"range_type":87,"version_start":450,"version_start_type":446,"version_end":450,"version_end_type":446,"fixed_in":9},"7.4.x below 7.4.4",{"ecosystem":9,"name":442,"vendor":9,"product":442,"cpe_part":9,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":452},[453,459,463],{"version":454,"is_range":455,"range_type":430,"version_start":456,"version_start_type":446,"version_end":457,"version_end_type":458,"fixed_in":9},"gte7.2.0_lt7.2.29",true,"7.2.0","7.2.29","excluding",{"version":460,"is_range":455,"range_type":430,"version_start":461,"version_start_type":446,"version_end":462,"version_end_type":458,"fixed_in":9},"gte7.3.0_lt7.3.16","7.3.0","7.3.16",{"version":464,"is_range":455,"range_type":430,"version_start":465,"version_start_type":446,"version_end":466,"version_end_type":458,"fixed_in":9},"gte7.4.0_lt7.4.4","7.4.0","7.4.4",{"ecosystem":9,"name":468,"vendor":469,"product":468,"cpe_part":470,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":471},"tenable.sc","tenable","a",[472,475],{"version":473,"is_range":455,"range_type":430,"version_start":9,"version_start_type":9,"version_end":474,"version_end_type":458,"fixed_in":9},"lt5.19.0","5.19.0",{"version":474,"is_range":35,"range_type":430,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9}]