CVE search
400,790 resultsCVE-2026-83632CRITICALApache Thrift: C++ THttpTransport grows its line buffer without boundEPSS —CVE-2026-104733HIGHUser Impersonation/Authorization Bypass in XMPP Server ejabberdEPSS —CVE-2026-83663HIGHApache Thrift: TFramedTransport and THeaderTransport re-enter Read once per frame that carries no payload (Go)EPSS —CVE-2026-83745HIGHApache Thrift, Apache Thrift: WebSocket frame decoders allocate the payload buffer from the declared length, not the bytes received (Node.js, D)EPSS —CVE-2026-104611CRITICALTenda AC9 POST Request fast_setting_internet_set stack-based overflowEPSS —CVE-2026-85476HIGHApache Thrift: c_glib `read_all` spins when the underlying read returns 0EPSS —CVE-2026-96289HIGHApache Thrift: php `--gen php:inlined` struct readers (and `TProtocol::skipBinary`) have no recursion-depth guardEPSS —CVE-2026-96287HIGHApache Thrift: Perl `FramedTransport` reads and TLS socket writes re-slice the remaining buffer on every call (quadratic)EPSS —CVE-2026-96286HIGHApache Thrift: Perl servers end `serve()` when serving one connection failsEPSS —CVE-2026-96277HIGHApache Thrift: Ruby `SimpleServer` ends `serve()` on any non-Transport/Protocol exceptionEPSS —CVE-2026-94658HIGHApache Thrift: Lua `TFramedTransport`/`THttpTransport` re-slice the buffer on every read (quadratic)EPSS —CVE-2026-94657HIGHApache Thrift: javame `TJsonProtocol`/`TJSONProtocol` has no string size boundEPSS —CVE-2026-94656HIGHApache Thrift: rb `TJsonProtocol`/`TJSONProtocol` has no string size boundEPSS —CVE-2026-104610CRITICALTenda HG7/HG9/HG10 Boa Web Server formLoopBack boaGetVar stack-based overflowEPSS —CVE-2026-94655HIGHApache Thrift: Lua `TJsonProtocol` string/number readers have no size bound and are quadraticEPSS —CVE-2026-94654HIGHApache Thrift: Python `TNonblockingServer` busy-loops and stops selecting all fds after an 8192-byte-boundary frameEPSS —CVE-2026-85209MEDIUMIDOR in AVEZ Electronics's LMSEPSS —CVE-2026-94653HIGHApache Thrift: PHP framed/memory/HTTP transports re-slice the buffer on every read (quadratic)EPSS —CVE-2026-94652MEDIUMApache Thrift: C++ `TEvhttpServer` leaks its `RequestContext` when the processor throws before calling backEPSS —CVE-2026-94648HIGHApache Thrift: dart `TJsonProtocol`/`TJSONProtocol` has no string size boundEPSS —