CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-102795 HIGH

Apache Traffic Server: SNI to Host header matching policy is not properly enforced

CVSS 7.0 EPSS n/a Oct 2, 2026
CVE-2026-59265

Apache OpenOffice, Apache OpenOffice: Opening a malicious document can lead to system takeover

CVSS n/a EPSS n/a Oct 2, 2026
CVE-2026-66054 MEDIUM

Apache Thrift: C++ THeaderTransport does not enforce configured maxFrameSize

CVSS 6.9 EPSS n/a Oct 2, 2026
CVE-2026-61374 HIGH

Apache Thrift: Java TSaslTransport post-auth data-frame missing size limit

CVSS 7.1 EPSS n/a Oct 2, 2026
CVE-2026-63772 HIGH

Apache Thrift: Unauthenticated single-packet crash of Go Thrift servers via the THeader transform count

CVSS 8.7 EPSS n/a Oct 2, 2026
CVE-2026-66055 HIGH

Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TJSONProtocol accepts a single JSON string/number exceeding the confi…

CVSS 8.2 EPSS n/a Oct 2, 2026
CVE-2026-66081 HIGH

Apache Thrift: c_glib read_message_begin leaves output parameters unset for non-versioned messages

CVSS 8.7 EPSS n/a Oct 2, 2026
CVE-2026-66331 MEDIUM

Apache Thrift: Buffered transport reads are not accounted against MaxMessageSize

CVSS 6.9 EPSS n/a Oct 2, 2026
CVE-2026-66837 HIGH

Apache Thrift: PHP accelerator sizes a stack buffer from a wire-controlled string length

CVSS 8.7 EPSS n/a Oct 2, 2026
CVE-2026-66858 HIGH

Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: skip() does not apply the recursion limit (Python accelerator, PHP, P…

CVSS 8.7 EPSS n/a Oct 2, 2026
CVE-2026-66859 HIGH

Apache Thrift: c_glib multiplexed processor crashes on a message it cannot route

CVSS 8.7 EPSS n/a Oct 2, 2026
CVE-2026-83632 CRITICAL

Apache Thrift: C++ THttpTransport grows its line buffer without bound

CVSS 9.2 EPSS n/a Oct 2, 2026
CVE-2026-83663 HIGH

Apache Thrift: TFramedTransport and THeaderTransport re-enter Read once per frame that carries no payload (Go)

CVSS 8.7 EPSS n/a Oct 2, 2026
CVE-2026-83745 HIGH

Apache Thrift, Apache Thrift: WebSocket frame decoders allocate the payload buffer from the declared length, not the bytes received (Node.js, D)

CVSS 8.7 EPSS n/a Oct 2, 2026
CVE-2026-85476 HIGH

Apache Thrift: c_glib `read_all` spins when the underlying read returns 0

CVSS 8.2 EPSS n/a Oct 2, 2026
CVE-2026-96289 HIGH

Apache Thrift: php `--gen php:inlined` struct readers (and `TProtocol::skipBinary`) have no recursion-depth guard

CVSS 8.2 EPSS n/a Oct 2, 2026
CVE-2026-96287 HIGH

Apache Thrift: Perl `FramedTransport` reads and TLS socket writes re-slice the remaining buffer on every call (quadratic)

CVSS 8.2 EPSS n/a Oct 2, 2026
CVE-2026-96286 HIGH

Apache Thrift: Perl servers end `serve()` when serving one connection fails

CVSS 8.2 EPSS n/a Oct 2, 2026
CVE-2026-96277 HIGH

Apache Thrift: Ruby `SimpleServer` ends `serve()` on any non-Transport/Protocol exception

CVSS 8.7 EPSS n/a Oct 2, 2026
CVE-2026-94658 HIGH

Apache Thrift: Lua `TFramedTransport`/`THttpTransport` re-slice the buffer on every read (quadratic)

CVSS 8.7 EPSS n/a Oct 2, 2026
CVE-2026-94657 HIGH

Apache Thrift: javame `TJsonProtocol`/`TJSONProtocol` has no string size bound

CVSS 8.2 EPSS n/a Oct 2, 2026
CVE-2026-94656 HIGH

Apache Thrift: rb `TJsonProtocol`/`TJSONProtocol` has no string size bound

CVSS 8.2 EPSS n/a Oct 2, 2026
CVE-2026-94655 HIGH

Apache Thrift: Lua `TJsonProtocol` string/number readers have no size bound and are quadratic

CVSS 8.2 EPSS n/a Oct 2, 2026
CVE-2026-94654 HIGH

Apache Thrift: Python `TNonblockingServer` busy-loops and stops selecting all fds after an 8192-byte-boundary frame

CVSS 8.2 EPSS n/a Oct 2, 2026
CVE-2026-94653 HIGH

Apache Thrift: PHP framed/memory/HTTP transports re-slice the buffer on every read (quadratic)

CVSS 8.2 EPSS n/a Oct 2, 2026

Showing 1 to 25 CVEs · page 1 (more available)