CVE search

400,866 results
CVE-2026-94648HIGHApache Thrift: dart `TJsonProtocol`/`TJSONProtocol` has no string size boundEPSS —CVE-2026-94646HIGHApache Thrift: Node.js `server.js` ends the process on any per-connection error (+ two triggers)EPSS —CVE-2026-94638MEDIUMApache Thrift: PHP `thrift_protocol` C extension ignores the configured `maxStringSize`EPSS —CVE-2026-94637HIGHApache Thrift: Go `THeaderTransport` does not bound the inflated size of a ZLIB frameEPSS —CVE-2026-94636HIGHApache Thrift: Python `TZlibTransport` stops enforcing its decompressed-size limit once the limit is exactly used upEPSS —CVE-2026-92834MEDIUMApache Thrift: C++ WebSocket server transport does not read a full request lengthEPSS —CVE-2026-104609MEDIUMonetwothreeneth HospitalManagementSystem edit_accounts.php get sql injectionEPSS —CVE-2026-90440HIGHApache Thrift: An exception escaping a libevent callback stops the D library's non-blocking server, allowing an unauthenticated remote attacker to deny serviceEPSS —CVE-2026-87117HIGHApache Thrift: PHP `thrift_protocol` accelerator dereferences a missing container-element specEPSS —CVE-2026-86537HIGHApache Thrift: A truncated HTTP request stops the D library's server, allowing an unauthenticated remote attacker to deny serviceEPSS —CVE-2026-86536MEDIUMApache Thrift, Apache Thrift, Apache Thrift: A map key from the wire can replace a decoded object's prototype in generated JavaScriptEPSS —CVE-2026-104473MEDIUMYesWiki before 4.5.3 Multiple Reflected XSS via BazaR and listpagesEPSS —CVE-2026-104472HIGHYesWiki before 4.6.7 Missing Authorization via Attachment Download HandlerEPSS —CVE-2026-104471HIGHYesWiki before 4.6.7 Unrestricted File Upload via Bazar CSV ImportEPSS —CVE-2026-104470MEDIUMYesWiki before 4.6.7 SSRF and XSS via Bazar valeur ActionEPSS —CVE-2026-104469HIGHYesWiki before 4.6.7 Session Fixation via Login in AuthController.phpEPSS —CVE-2026-104468MEDIUMYesWiki before 4.6.7 Non-Expiring Password Reset Tokens via LostPasswordActionEPSS —CVE-2026-104467CRITICALYesWiki before 4.6.7 Authorization Bypass via Public API ModeEPSS —CVE-2026-104466MEDIUMYesWiki before 4.6.7 Stored XSS via Wakka Markdown Image src AttributeEPSS —CVE-2026-104465MEDIUMYesWiki before 4.6.7 Reflected XSS via field Parameter in mail HandlerEPSS —