CVE search
400,917 resultsCVE-2026-94651HIGHApache Thrift: Java `TSaslNonblockingServer` `Computation.run` orphans a connection on a pre-auth parse errorEPSS —CVE-2026-85483MEDIUMApache Thrift: c_glib TZlibTransport reports a full read after a premature stream endEPSS —CVE-2026-85493HIGHApache Thrift, Apache Thrift: TProtocolUtil.skip follows peer-chosen nesting to any depth the stack allows (Dart, Java ME)EPSS —CVE-2026-85494HIGHApache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: Framed transport and binary protocol size read buffers from a peer-declared length without a limit (multi-language)EPSS —CVE-2026-97876MEDIUMBypass of GRUB lockdown restriction in Secure Boot mode via serial command MMIO base addressEPSS —CVE-2026-104606MEDIUMitsourcecode Online Admission System Project confirm.php sql injectionEPSS —CVE-2026-91135CRITICALApache Thrift: C++ `THeaderTransport::transform()` heap buffer overflow (write direction)EPSS —CVE-2026-86326HIGHAn improper verification of cryptographic signature vulnerability exists in protocol gateways because the device does not properly verify thEPSS —CVE-2026-91137HIGHApache Thrift: PHP `thrift_protocol` accelerator: zero-byte container elementsEPSS —CVE-2026-86325CRITICALA stack-based buffer overflow vulnerability exists in protocol gateways' account management interface. The vulnerability is caused by insuffEPSS —CVE-2026-59668MEDIUMMultiple vulnerabilities in the Repasat applicationEPSS —CVE-2026-93925HIGHApache Thrift: C++ `THeaderTransport::writeVarint32()` stack buffer overflow on a negative protocol idEPSS —CVE-2026-59667MEDIUMMultiple vulnerabilities in the Repasat applicationEPSS —CVE-2026-93926HIGHApache Thrift: C++ `THeaderTransport::untransform()` leaks the zlib stream on the error pathEPSS —CVE-2026-94633HIGHApache Thrift: Dart `TBinaryProtocol.readMessageBegin` allocates from the pre-versioned name lengthEPSS —CVE-2026-59666MEDIUMMultiple vulnerabilities in the Repasat applicationEPSS —CVE-2026-94634HIGHApache Thrift: Python `TJSONProtocol` has a string length limit that is off by defaultEPSS —CVE-2026-59665MEDIUMMultiple vulnerabilities in the Repasat applicationEPSS —CVE-2026-103885—Apache Directory LDAP API: Denial of service via crafted telephone number valuesEPSS —CVE-2026-103877—Apache Directory LDAP API: Unsafe loading of Java code from LDAP schema elementsEPSS —