Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54227
Total
4299
Critical
16114
High
15798
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-104611 | CRITICAL | 9.1 | A vulnerability was detected in Tenda AC9 15.03.02.13. Affected is an unknown function of the file /goform/fast_setting_internet_set of the component POST Request Handler. Performing a … | Oct 02, 2026 |
| CVE-2026-104610 | CRITICAL | 10.0 | A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_en_xpon. This impacts the function boaGetVar of the file /boaform/formLoopBack of the component … | Oct 02, 2026 |
| CVE-2026-102798 | MEDIUM | 6.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeREX Group ThemeREX Addons trx_addons allows Stored XSS.This issue affects ThemeREX Addons: from … | Oct 02, 2026 |
| CVE-2026-102797 | MEDIUM | 6.4 | Server-Side Request Forgery (SSRF) vulnerability in ThemeREX Group ThemeREX Addons trx_addons allows Server Side Request Forgery.This issue affects ThemeREX Addons: from n/a through 2.46.0. | Oct 02, 2026 |
| CVE-2026-96294 | UNKNOWN | — | Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift NodeJS bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade … | Oct 02, 2026 |
| CVE-2026-96292 | UNKNOWN | — | Inefficient regular expression complexity, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade … | Oct 02, 2026 |
| CVE-2026-96288 | UNKNOWN | — | Uncontrolled Recursion, Allocation of resources without limits or throttling vulnerability in Apache Thrift Erlang bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended … | Oct 02, 2026 |
| CVE-2026-94653 | UNKNOWN | — | Inefficient Algorithmic Complexity vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which … | Oct 02, 2026 |
| CVE-2026-94652 | UNKNOWN | — | Missing release of memory after effective lifetime vulnerability in Apache Thrift c++ bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade … | Oct 02, 2026 |
| CVE-2026-94648 | UNKNOWN | — | Allocation of resources without limits or throttling vulnerability in Apache Thrift dart bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade … | Oct 02, 2026 |
| CVE-2026-94646 | UNKNOWN | — | Uncaught exception, Improper validation of specified quantity in input, Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift nodejs bindings. This … | Oct 02, 2026 |
| CVE-2026-94638 | UNKNOWN | — | Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade … | Oct 02, 2026 |
| CVE-2026-94637 | UNKNOWN | — | Improper handling of highly compressed data (data amplification) vulnerability in Apache Thrift Go bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to … | Oct 02, 2026 |
| CVE-2026-94636 | UNKNOWN | — | Improper handling of highly compressed data (data amplification), Function call with incorrectly specified arguments, Improper validation of specified quantity in input vulnerability in Apache Thrift … | Oct 02, 2026 |
| CVE-2026-92834 | UNKNOWN | — | Use of uninitialized resource, Return of wrong status code vulnerability in Apache Thrift C++ WebSocket server. This issue affects Apache Thrift: before 0.25.0. Users are … | Oct 02, 2026 |
| CVE-2026-90440 | UNKNOWN | — | Uncaught exception, improper handling of exceptional conditions, improper resource shutdown vulnerability in Apache Thrift D thrift.server.nonblocking.TNonblockingServer. This issue affects Apache Thrift: before 0.25.0. Users are … | Oct 02, 2026 |
| CVE-2026-87117 | UNKNOWN | — | NULL pointer dereference vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which … | Oct 02, 2026 |
| CVE-2026-86537 | UNKNOWN | — | Uncaught exception, Loop with unreachable exit condition ('infinite loop'), Integer underflow (wrap or wraparound) vulnerability in Apache Thrift D language bindings. This issue affects Apache … | Oct 02, 2026 |
| CVE-2026-86536 | UNKNOWN | — | Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift all JS bindings. This issue affects Apache Thrift: before 0.25.0. Users are … | Oct 02, 2026 |
| CVE-2026-86535 | UNKNOWN | — | Loop with unreachable exit condition ('infinite loop'), Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift NodeJS bindings with TJSONProtocol. This … | Oct 02, 2026 |
| CVE-2026-85088 | UNKNOWN | — | Improper Validation of Certificate with Host Mismatch in the C++ and D libraries of Apache Thrift. Both libraries install a default access manager for client … | Oct 02, 2026 |
| CVE-2026-85087 | UNKNOWN | — | Improper certificate validation, Return of wrong status code vulnerability in Apache Thrift python bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to … | Oct 02, 2026 |
| CVE-2026-85086 | UNKNOWN | — | Improper certificate validation, Initialization of a resource with an insecure default vulnerability in Apache Thrift perl bindings. This issue affects Apache Thrift: before 0.25.0. Users … | Oct 02, 2026 |
| CVE-2026-82459 | UNKNOWN | — | Integer underflow (wrap or wraparound), Out-of-bounds write vulnerability in Apache Thrift C++ 32 bit THeaderTransport. This issue affects Apache Thrift: before 0.25.0. Users are recommended … | Oct 02, 2026 |
| CVE-2026-82458 | UNKNOWN | — | Memory allocation with excessive size value, Allocation of resources without limits or throttling vulnerability in Apache Thrift Go, netstd, OCaml, Erlang, JavaME, Rust, C++, Java, … | Oct 02, 2026 |