Total CVEs

149,971

Critical Severity

4,911

High Severity

17,397

Last 7 Days

1,775
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 621 - 640 of 46,376 CVEs
CVE-2026-58023 CRITICAL - 9.1

Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Jul 27, 2026
Source: NVD

proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially allowing the reading of local files, depending on the parser's configuration. The XML External Entity (XXE) vulnerability is triggered simply by previewing a file in the file s...

Vendor: Asseco
Product: proCertum SmartSign
Published: Jul 27, 2026
Source: NVD

proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare arbitrary certificate with CPS URI pointing to a local executable file or any URL, sign a document with it, and send it to the victim. When the victim opens the document in the appli...

Vendor: Asseco
Product: proCertum SmartSign
Published: Jul 27, 2026
Source: NVD
CVE-2026-55971 CRITICAL - 9.8

Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Jul 27, 2026
Source: NVD
CVE-2026-55970 MEDIUM - 6.5

Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Jul 27, 2026
Source: NVD
CVE-2026-55969 HIGH - 7.5

Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Jul 27, 2026
Source: NVD
CVE-2026-55968 HIGH - 7.5

Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Jul 27, 2026
Source: NVD
CVE-2026-49158 HIGH - 7.5

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Jul 27, 2026
Source: NVD
CVE-2026-48586 HIGH - 7.5

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Jul 27, 2026
Source: NVD
CVE-2026-48145 HIGH - 7.5

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Jul 27, 2026
Source: NVD
CVE-2026-48144 CRITICAL - 9.1

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Jul 27, 2026
Source: NVD
CVE-2026-45112 HIGH - 7.5

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Jul 27, 2026
Source: NVD
CVE-2026-43871 HIGH - 7.5

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Jul 27, 2026
Source: NVD
CVE-2026-41608 HIGH - 7.5

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Jul 27, 2026
Source: NVD

A stored Cross-Site Scripting (XSS) vulnerability in the file upload functionality of the Media Manager in TastyIgniter v4.3.0, caused by insufficient validation and sanitization of SVG files. An authenticated user with low privileges can upload a malicious SVG file containing JavaScript code. When ...

Vendor: Media Manager
Product: TastyIgniter
Published: Jul 27, 2026
Source: NVD

Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys MB115-4G device's web interface. An unauthenticated attacker could exploit this vulnerability by sending a specially crafted request to the /cgi/login endpoint, causing memory ...

Vendor: Mercusys
Product: MB115-4G
Published: Jul 27, 2026
Source: NVD

The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity within ZTE File Manager is designed to preview compressed files. Third-party applications can launch this Activity and supply arbitrary file paths (e.g., content://zte.com.cn.filer.fileprovider/root_path), enabling file access with t...

Vendor: ZTE
Product: A75 Pro 5G
Published: Jul 27, 2026
Source: NVD
CVE-2026-17534 MEDIUM - 5.5

Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal denylist in assertSafeFetchTarget, without resolving DNS or re-validating hosts after HTTP redirects. An attacker who can influence a FetchURL call (for example via prompt injectio...

Vendor: MoonshotAI
Product: Kimi Code
Published: Jul 27, 2026
Source: NVD
CVE-2026-17527 HIGH - 7.7

In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI's DataVolume clone authorization accepts this permission as sufficient to auth...

Vendor: Red Hat
Product: Red Hat OpenShift Virtualization 4
Published: Jul 27, 2026
Source: NVD
CVE-2026-17523 HIGH - 7.8

A flaw was found in the kernel. An unprivileged local user can exploit this vulnerability to execute arbitrary code within the kernel, which leads to a local privilege escalation (LPE). This allows the attacker to gain root privileges and take full control of the affected system.

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jul 27, 2026
Source: NVD