CVE search
400,855 resultsCVE-2026-63772HIGHApache Thrift: Unauthenticated single-packet crash of Go Thrift servers via the THeader transform countEPSS —CVE-2026-66055HIGHApache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TJSONProtocol accepts a single JSON string/number exceeding the configured size limit (multi-language)EPSS —CVE-2026-104612MEDIUMSourceCodester Student Result Management System Announcement new_announcement.php cross site scriptingEPSS —CVE-2026-11795MEDIUMUser Enumeration in Softtr's E-Commerce PackEPSS —CVE-2026-102797MEDIUMWordPress ThemeREX Addons plugin <= 2.46.0 - Server Side Request Forgery (SSRF) vulnerabilityEPSS —CVE-2026-102798MEDIUMWordPress ThemeREX Addons plugin <= 2.46.0 - Cross Site Scripting (XSS) vulnerabilityEPSS —CVE-2026-66081HIGHApache Thrift: c_glib read_message_begin leaves output parameters unset for non-versioned messagesEPSS —CVE-2026-66331MEDIUMApache Thrift: Buffered transport reads are not accounted against MaxMessageSizeEPSS —CVE-2026-66837HIGHApache Thrift: PHP accelerator sizes a stack buffer from a wire-controlled string lengthEPSS —CVE-2026-66858HIGHApache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: skip() does not apply the recursion limit (Python accelerator, PHP, Perl, Lua, Smalltalk, OCaml)EPSS —CVE-2026-66859HIGHApache Thrift: c_glib multiplexed processor crashes on a message it cannot routeEPSS —CVE-2026-83632CRITICALApache Thrift: C++ THttpTransport grows its line buffer without boundEPSS —CVE-2026-104733HIGHUser Impersonation/Authorization Bypass in XMPP Server ejabberdEPSS —CVE-2026-83663HIGHApache Thrift: TFramedTransport and THeaderTransport re-enter Read once per frame that carries no payload (Go)EPSS —CVE-2026-83745HIGHApache Thrift, Apache Thrift: WebSocket frame decoders allocate the payload buffer from the declared length, not the bytes received (Node.js, D)EPSS —CVE-2026-104611CRITICALTenda AC9 POST Request fast_setting_internet_set stack-based overflowEPSS —CVE-2026-85476HIGHApache Thrift: c_glib `read_all` spins when the underlying read returns 0EPSS —CVE-2026-96289HIGHApache Thrift: php `--gen php:inlined` struct readers (and `TProtocol::skipBinary`) have no recursion-depth guardEPSS —CVE-2026-96287HIGHApache Thrift: Perl `FramedTransport` reads and TLS socket writes re-slice the remaining buffer on every call (quadratic)EPSS —CVE-2026-96286HIGHApache Thrift: Perl servers end `serve()` when serving one connection failsEPSS —