Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-58389 — Apache Thrift: Rust binary protocol non-strict path missing string size limit

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.…

thrift | Remote | Denial of Service
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
6.9 MEDIUM
CVE-2026-58023 — Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path

Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

thrift | Remote | Memory Corruption
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
4.8 MEDIUM
CVE-2026-57917 — Improper Restriction of XML External Entity Reference in proCertum SmartSign

proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially allowing the reading of local files, depending on the parser's configuration. Th…

| XML External Entity
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
4.6 MEDIUM
CVE-2026-57916 — Arbitrary Path Execution via CPS URI in proCertum SmartSign

proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare arbitrary certificate with CPS URI pointing to a local executable file or any URL…

| Misconfiguration
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
9.3 CRITICAL
CVE-2026-55971 — Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform()

Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

thrift | Remote | Memory Corruption
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
6.9 MEDIUM
CVE-2026-55970 — Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat()

Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

thrift | Remote | Memory Corruption
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
8.7 HIGH
CVE-2026-55969 — Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift:…

Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to…

thrift | Remote | Memory Corruption
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
8.7 HIGH
CVE-2026-55968 — Apache Thrift: Node.js quadratic-time DoS in server receive transports

Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue affects Apache Thrift: before 0.24.0. Users are …

thrift | Remote | Denial of Service
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.5 HIGH
CVE-2026-49158 — Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to v…

thrift | Remote | Denial of Service
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
8.7 HIGH
CVE-2026-48586 — Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift:…

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings. This issue affects Apache Thrift: before 0.24.0. Users are…

thrift | Remote | Denial of Service
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
8.2 HIGH
CVE-2026-48145 — Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.…

thrift | Remote | Misconfiguration
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
9.1 CRITICAL
CVE-2026-48144 — Apache Thrift: c_glib TLS Client Missing Hostname Verification

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.…

thrift | Remote | Misconfiguration
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
6.9 MEDIUM
CVE-2026-45112 — Apache Thrift: Unbounded Read Leading to Denial of Service

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 before 0.24.0. Users are recommended to upgrade to v…

thrift | Remote | Denial of Service
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
8.7 HIGH
CVE-2026-43871 — Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-…

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgr…

thrift | Remote | Denial of Service
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
0.0 NA
CVE-2026-41608 — Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to…

thrift | Denial of Service
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
6.3 MEDIUM
CVE-2026-14856 — Stored Cross-Site Scripting (XSS) in TastyIgniter Media Manager

A stored Cross-Site Scripting (XSS) vulnerability in the file upload functionality of the Media Manager in TastyIgniter v4.3.0, caused by insufficient validation and sanitization of SVG files. An aut…

Remote | Cross-Site Scripting
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
9.2 CRITICAL
CVE-2026-12495 — Stack-Based Buffer Overflow in the Mercusys MB115-4G

Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys MB115-4G device's web interface. An unauthenticated attacker could exploit this …

Remote | Memory Corruption
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
1.8 LOW
CVE-2026-40000 — Path Traversal Vulnerability in ZTE Blade A75 Pro 5G

The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity within ZTE File Manager is designed to preview compressed files. Third-party applications can launch this Activity and supply arbitr…

| Path Traversal
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
5.5 MEDIUM
CVE-2026-17534 — Kimi Code FetchURL SSRF protection bypass via DNS-resolving hostnames and redirects

Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal denylist in assertSafeFetchTarget, without resolving DNS or re-validating hosts…

| Server-Side Request Forgery
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.7 HIGH
CVE-2026-17527 — Virt-cdi-operator: containerized-data-importer: cdi.kubevirt.io:view aggregated clusterro…

In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source…

openshift_virtualization | Remote | Authorization
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Showing 20 of 9087 Results