Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.2 HIGH
CVE-2026-94653 — Apache Thrift: PHP framed/memory/HTTP transports re-slice the buffer on every read (quadr…

Inefficient Algorithmic Complexity vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes …

thrift | Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.3 MEDIUM
CVE-2026-94652 — Apache Thrift: C++ `TEvhttpServer` leaks its `RequestContext` when the processor throws b…

Missing release of memory after effective lifetime vulnerability in Apache Thrift c++ bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25…

thrift | Remote | Memory Corruption
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.2 HIGH
CVE-2026-94648 — Apache Thrift: dart `TJsonProtocol`/`TJSONProtocol` has no string size bound

Allocation of resources without limits or throttling vulnerability in Apache Thrift dart bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0…

thrift | Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.7 HIGH
CVE-2026-94646 — Apache Thrift: Node.js `server.js` ends the process on any per-connection error (+ two tr…

Uncaught exception, Improper validation of specified quantity in input, Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift nodejs…

thrift | Remote | Misconfiguration
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.3 MEDIUM
CVE-2026-94638 — Apache Thrift: PHP `thrift_protocol` C extension ignores the configured `maxStringSize`

Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.…

thrift | Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.2 HIGH
CVE-2026-94637 — Apache Thrift: Go `THeaderTransport` does not bound the inflated size of a ZLIB frame

Improper handling of highly compressed data (data amplification) vulnerability in Apache Thrift Go bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to…

thrift | Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.2 HIGH
CVE-2026-94636 — Apache Thrift: Python `TZlibTransport` stops enforcing its decompressed-size limit once t…

Improper handling of highly compressed data (data amplification), Function call with incorrectly specified arguments, Improper validation of specified quantity in input vulnerability in Apache Thrift…

thrift | Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.3 MEDIUM
CVE-2026-92834 — Apache Thrift: C++ WebSocket server transport does not read a full request length

Use of uninitialized resource, Return of wrong status code vulnerability in Apache Thrift C++ WebSocket server. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade…

thrift | Remote | Memory Corruption
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
0.0 NA
CVE-2026-104609 — onetwothreeneth HospitalManagementSystem edit_accounts.php get sql injection

A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. This affects the function get of the file edit_accounts.php. This manipulati…

| Injection
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.2 HIGH
CVE-2026-90440 — Apache Thrift: An exception escaping a libevent callback stops the D library's non-blocki…

Uncaught exception, improper handling of exceptional conditions, improper resource shutdown vulnerability in Apache Thrift D thrift.server.nonblocking.TNonblockingServer. This issue affects Apache…

thrift | Remote
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.7 HIGH
CVE-2026-87117 — Apache Thrift: PHP `thrift_protocol` accelerator dereferences a missing container-element…

NULL pointer dereference vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

thrift | Remote | Memory Corruption
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.7 HIGH
CVE-2026-86537 — Apache Thrift: A truncated HTTP request stops the D library's server, allowing an unauthe…

Uncaught exception, Loop with unreachable exit condition ('infinite loop'), Integer underflow (wrap or wraparound) vulnerability in Apache Thrift D language bindings. This issue affects Apache Thr…

thrift | Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.3 MEDIUM
CVE-2026-86536 — Apache Thrift, Apache Thrift, Apache Thrift: A map key from the wire can replace a decode…

Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift all JS bindings. This issue affects Apache Thrift: before 0.25.0. Users …

thrift | Remote | Misconfiguration
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.1 MEDIUM
CVE-2026-104473 — YesWiki before 4.5.3 Multiple Reflected XSS via BazaR and listpages

YesWiki before 4.5.3 contains multiple reflected cross-site scripting vulnerabilities that allow remote attackers to inject JavaScript through unsanitized parameters such as incomingurl, id, file, ta…

Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.5 HIGH
CVE-2026-104472 — YesWiki before 4.6.7 Missing Authorization via Attachment Download Handler

YesWiki before 4.6.7 contains a missing authorization vulnerability in the attachment download handler that allows unauthenticated attackers to bypass page read ACLs. Attackers can request the downlo…

Remote | Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.2 HIGH
CVE-2026-104471 — YesWiki before 4.6.7 Unrestricted File Upload via Bazar CSV Import

YesWiki before 4.6.7 contains an unrestricted file upload vulnerability that allows authenticated admins to write remote files into the web-accessible files/ directory via Bazar CSV import preview. A…

Remote | Misconfiguration
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.4 HIGH
CVE-2026-104470 — YesWiki before 4.6.7 SSRF and XSS via Bazar valeur Action

YesWiki before 4.6.7 contains a server-side request forgery vulnerability in the Bazar valeur action that allows page editors to make the server fetch arbitrary URLs. Attackers can supply loopback or…

Remote | Server-Side Request Forgery
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.8 MEDIUM
CVE-2026-104469 — YesWiki before 4.6.7 Session Fixation via Login in AuthController.php

YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated sessions because login does not regenerate the PHP session ID. Attackers who set or learn …

Remote | Authentication
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
4.8 MEDIUM
CVE-2026-104468 — YesWiki before 4.6.7 Non-Expiring Password Reset Tokens via LostPasswordAction

YesWiki before 4.6.7 contains an insufficient session expiration vulnerability that allows attackers to reuse old password reset links because tokens lack expiry timestamps. Attackers who obtain an u…

Remote | Authentication
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.1 HIGH
CVE-2026-104467 — YesWiki before 4.6.7 Authorization Bypass via Public API Mode

YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiService::isAuthorized() that allows unauthenticated attackers to call admin-only API routes when public API mode is enabled. …

Remote | Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
Showing 20 of 15037 Results