Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54227
Total
4299
Critical
16114
High
15798
Medium
CVE ID Severity Score Description Published
CVE-2026-93926 UNKNOWN — Missing release of memory after effective lifetime, Missing release of resource after effective lifetime vulnerability in Apache Thrift THeaderTransport. This issue affects Apache Thrift: before … Oct 02, 2026
CVE-2026-93925 UNKNOWN — Stack-based buffer overflow, Incorrect bitwise shift of integer vulnerability in Apache Thrift C++ THeaderProtocol. This issue affects Apache Thrift: before 0.25.0. Users are recommended to … Oct 02, 2026
CVE-2026-91137 UNKNOWN — Improper validation of specified quantity in input, Allocation of resources without limits or throttling, Excessive Iteration vulnerability in Apache Thrift PHP bindings. This issue affects … Oct 02, 2026
CVE-2026-91135 UNKNOWN — Heap-based buffer overflow vulnerability in Apache Thrift C++ THeaderTransport. When an application enables the ZLIB transform for the frames it sends, THeaderTransport::transform() copies the compressed … Oct 02, 2026
CVE-2026-86326 UNKNOWN — An improper verification of cryptographic signature vulnerability exists in protocol gateways because the device does not properly verify the cryptographic authenticity of firmware images before … Oct 02, 2026
CVE-2026-86325 UNKNOWN — A stack-based buffer overflow vulnerability exists in protocol gateways' account management interface. The vulnerability is caused by insufficient length validation of the `account_name` parameter when … Oct 02, 2026
CVE-2026-85494 UNKNOWN — Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size value, Initialization of a resource with an insecure default … Oct 02, 2026
CVE-2026-85493 UNKNOWN — Uncontrolled Recursion vulnerability in Apache Thrift Dart and Java ME bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version … Oct 02, 2026
CVE-2026-85483 UNKNOWN — Use of uninitialized resource, Return of wrong status code vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended … Oct 02, 2026
CVE-2026-59668 UNKNOWN — Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in … Oct 02, 2026
CVE-2026-59667 UNKNOWN — Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in … Oct 02, 2026
CVE-2026-59666 UNKNOWN — Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in … Oct 02, 2026
CVE-2026-104606 MEDIUM 6.3 A security flaw has been discovered in itsourcecode Online Admission System Project 1.0. The impacted element is an unknown function of the file confirm.php. The … Oct 02, 2026
CVE-2026-97652 MEDIUM 6.1 The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Query-Parameter Key in all versions … Oct 02, 2026
CVE-2026-95662 UNKNOWN — Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in … Oct 02, 2026
CVE-2026-94639 UNKNOWN — improper handling of exceptional conditions, Allocation of resources without limits or throttling, Uncaught exception vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: … Oct 02, 2026
CVE-2026-94635 UNKNOWN — Allocation of resources without limits or throttling, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before … Oct 02, 2026
CVE-2026-94634 UNKNOWN — Allocation of resources without limits or throttling, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python bindings. This issue affects Apache … Oct 02, 2026
CVE-2026-94541 CRITICAL 9.8 The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This … Oct 02, 2026
CVE-2026-94405 MEDIUM 5.3 Authorization Bypass Through User-Controlled Key vulnerability in Shahjada Download Manager allows Retrieve Embedded Sensitive Data. This issue affects Download Manager: from n/a through 3.3.71. Oct 02, 2026
CVE-2026-94180 MEDIUM 4.3 Authorization Bypass Through User-Controlled Key vulnerability in Monetizemore Advanced Ads allows Retrieve Embedded Sensitive Data. This issue affects Advanced Ads: from n/a through 2.0.26. Oct 02, 2026
CVE-2026-87920 HIGH 7.2 The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Output-Buffer Regex Rewrite in all versions up to, … Oct 02, 2026
CVE-2026-85492 MEDIUM 6.1 The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress … Oct 02, 2026
CVE-2026-80298 HIGH 8.8 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows SQL Injection. This … Oct 02, 2026
CVE-2026-59673 UNKNOWN — Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in … Oct 02, 2026