Phkp Project maintains a specialized password-hashing utility that, despite a narrow product scope, serves a foundational role in authentication systems across a distributed user base. The observed vulnerability pattern centers on improper neutralization of special elements in OS command construction, reflecting risks inherent to command-line interface design and input-handling requirements. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phkp Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-1010179CRITICAL PHKP including commit 88fd9cfdf14ea4b6ac3e3967feea7bcaabb6f03b is affected by: Improper Neutralization of Special Elements used in a Command ('Command Injection'). The impact is: I | Jul 24, 2019 | 9.8 | 31 | NO | NO |
CVE-2018-1000885CRITICAL PHKP version including commit 88fd9cfdf14ea4b6ac3e3967feea7bcaabb6f03b contains a Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability | Dec 20, 2018 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phkp Project.
Media articles that mention a CVE ID that affects a product developed by Phkp Project — matched by CVE ID, not by vendor name.