Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54227
Total
4299
Critical
16114
High
15798
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-93926 | UNKNOWN | — | Missing release of memory after effective lifetime, Missing release of resource after effective lifetime vulnerability in Apache Thrift THeaderTransport. This issue affects Apache Thrift: before … | Oct 02, 2026 |
| CVE-2026-93925 | UNKNOWN | — | Stack-based buffer overflow, Incorrect bitwise shift of integer vulnerability in Apache Thrift C++ THeaderProtocol. This issue affects Apache Thrift: before 0.25.0. Users are recommended to … | Oct 02, 2026 |
| CVE-2026-91137 | UNKNOWN | — | Improper validation of specified quantity in input, Allocation of resources without limits or throttling, Excessive Iteration vulnerability in Apache Thrift PHP bindings. This issue affects … | Oct 02, 2026 |
| CVE-2026-91135 | UNKNOWN | — | Heap-based buffer overflow vulnerability in Apache Thrift C++ THeaderTransport. When an application enables the ZLIB transform for the frames it sends, THeaderTransport::transform() copies the compressed … | Oct 02, 2026 |
| CVE-2026-86326 | UNKNOWN | — | An improper verification of cryptographic signature vulnerability exists in protocol gateways because the device does not properly verify the cryptographic authenticity of firmware images before … | Oct 02, 2026 |
| CVE-2026-86325 | UNKNOWN | — | A stack-based buffer overflow vulnerability exists in protocol gateways' account management interface. The vulnerability is caused by insufficient length validation of the `account_name` parameter when … | Oct 02, 2026 |
| CVE-2026-85494 | UNKNOWN | — | Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size value, Initialization of a resource with an insecure default … | Oct 02, 2026 |
| CVE-2026-85493 | UNKNOWN | — | Uncontrolled Recursion vulnerability in Apache Thrift Dart and Java ME bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version … | Oct 02, 2026 |
| CVE-2026-85483 | UNKNOWN | — | Use of uninitialized resource, Return of wrong status code vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended … | Oct 02, 2026 |
| CVE-2026-59668 | UNKNOWN | — | Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in … | Oct 02, 2026 |
| CVE-2026-59667 | UNKNOWN | — | Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in … | Oct 02, 2026 |
| CVE-2026-59666 | UNKNOWN | — | Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in … | Oct 02, 2026 |
| CVE-2026-104606 | MEDIUM | 6.3 | A security flaw has been discovered in itsourcecode Online Admission System Project 1.0. The impacted element is an unknown function of the file confirm.php. The … | Oct 02, 2026 |
| CVE-2026-97652 | MEDIUM | 6.1 | The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Query-Parameter Key in all versions … | Oct 02, 2026 |
| CVE-2026-95662 | UNKNOWN | — | Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in … | Oct 02, 2026 |
| CVE-2026-94639 | UNKNOWN | — | improper handling of exceptional conditions, Allocation of resources without limits or throttling, Uncaught exception vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: … | Oct 02, 2026 |
| CVE-2026-94635 | UNKNOWN | — | Allocation of resources without limits or throttling, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before … | Oct 02, 2026 |
| CVE-2026-94634 | UNKNOWN | — | Allocation of resources without limits or throttling, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python bindings. This issue affects Apache … | Oct 02, 2026 |
| CVE-2026-94541 | CRITICAL | 9.8 | The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This … | Oct 02, 2026 |
| CVE-2026-94405 | MEDIUM | 5.3 | Authorization Bypass Through User-Controlled Key vulnerability in Shahjada Download Manager allows Retrieve Embedded Sensitive Data. This issue affects Download Manager: from n/a through 3.3.71. | Oct 02, 2026 |
| CVE-2026-94180 | MEDIUM | 4.3 | Authorization Bypass Through User-Controlled Key vulnerability in Monetizemore Advanced Ads allows Retrieve Embedded Sensitive Data. This issue affects Advanced Ads: from n/a through 2.0.26. | Oct 02, 2026 |
| CVE-2026-87920 | HIGH | 7.2 | The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Output-Buffer Regex Rewrite in all versions up to, … | Oct 02, 2026 |
| CVE-2026-85492 | MEDIUM | 6.1 | The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress … | Oct 02, 2026 |
| CVE-2026-80298 | HIGH | 8.8 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows SQL Injection. This … | Oct 02, 2026 |
| CVE-2026-59673 | UNKNOWN | — | Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in … | Oct 02, 2026 |