Vulnerabilities
Summary — last 7 days
New vulnerabilities2,546▼ 402 vs. last week
Critical / high1,312▲ 29 vs. last week
New active exploitation (KEV)6▼ 5 vs. last week
Unscored (no CVSS)59▼ 467 vs. last week
401,252 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (8.2) | 0.43% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Uncontrolled Recursion, Allocation of resources without limits or throttling vulnerability in Apache Thrift Erlang bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Deferred | High (8.2) | 0.43% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Inefficient Algorithmic Complexity vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Deferred | Medium (6.3) | 0.43% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Missing release of memory after effective lifetime vulnerability in Apache Thrift c++ bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Deferred | High (8.2) | 0.43% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Allocation of resources without limits or throttling vulnerability in Apache Thrift dart bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Deferred | High (8.7) | 0.46% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Uncaught exception, Improper validation of specified quantity in input, Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift nodejs bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which… | |
| Deferred | Medium (6.3) | 0.43% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Deferred | High (8.2) | 0.43% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Improper handling of highly compressed data (data amplification) vulnerability in Apache Thrift Go bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Deferred | High (8.2) | 0.43% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Improper handling of highly compressed data (data amplification), Function call with incorrectly specified arguments, Improper validation of specified quantity in input vulnerability in Apache Thrift py bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which… | |
| Deferred | Medium (6.3) | 0.43% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Use of uninitialized resource, Return of wrong status code vulnerability in Apache Thrift C++ WebSocket server. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Deferred | High (8.2) | 0.43% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Uncaught exception, improper handling of exceptional conditions, improper resource shutdown vulnerability in Apache Thrift D thrift.server.nonblocking.TNonblockingServer. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Deferred | High (8.7) | 0.43% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | NULL pointer dereference vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Deferred | High (8.7) | 0.55% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Uncaught exception, Loop with unreachable exit condition ('infinite loop'), Integer underflow (wrap or wraparound) vulnerability in Apache Thrift D language bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Deferred | Medium (6.3) | 0.46% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift all JS bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0 and re-generate JS code, which fixes the issue. | |
| Deferred | High (8.7) | 0.34% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Loop with unreachable exit condition ('infinite loop'), Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift NodeJS bindings with TJSONProtocol. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which… | |
| Deferred | Medium (6.9) | 0.21% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Improper Validation of Certificate with Host Mismatch in the C++ and D libraries of Apache Thrift. Both libraries install a default access manager for client sockets — TSSLSocketFactory does so in C++, and the accessManager property does so in D — which compares the peer certificate against the host name that was… | |
| Deferred | Medium (6.9) | 0.21% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Improper certificate validation, Return of wrong status code vulnerability in Apache Thrift python bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Deferred | Medium (6.9) | 0.26% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Improper certificate validation, Initialization of a resource with an insecure default vulnerability in Apache Thrift perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Deferred | High (8.2) | 0.43% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Integer underflow (wrap or wraparound), Out-of-bounds write vulnerability in Apache Thrift C++ 32 bit THeaderTransport. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Deferred | High (8.7) | 0.43% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Memory allocation with excessive size value, Allocation of resources without limits or throttling vulnerability in Apache Thrift Go, netstd, OCaml, Erlang, JavaME, Rust, C++, Java, Kotlin and D language bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which… | |
| Deferred | High (8.7) | 0.43% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java TSaslNonblockingServer. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Deferred | Medium (5.5) | 0.26% | — | Onetwothreeneth HospitalmanagmentsystemAI | 10/2/2026 | 10/2/2026 | A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. This affects the function get of the file edit_accounts.php. This manipulation of the argument user_id/patient_id/physician_id/discounts_id/services_id causes sql injection. Remote exploitation of… | |
| Deferred | Medium (5.1) | 0.20% | — | YeswikiAI | 10/2/2026 | 10/2/2026 | YesWiki before 4.5.3 contains multiple reflected cross-site scripting vulnerabilities that allow remote attackers to inject JavaScript through unsanitized parameters such as incomingurl, id, file, tags, and template. Attackers can lure authenticated or unauthenticated users into opening crafted links to hijack… | |
| Deferred | High (8.7) | 0.34% | — | YeswikiAI | 10/2/2026 | 10/2/2026 | YesWiki before 4.6.7 contains a missing authorization vulnerability in the attachment download handler that allows unauthenticated attackers to bypass page read ACLs. Attackers can request the download handler with a known page tag and file parameter to retrieve confidential attachments from read-restricted pages. | |
| Deferred | High (8.6) | 0.37% | — | YeswikiAI | 10/2/2026 | 10/2/2026 | YesWiki before 4.6.7 contains an unrestricted file upload vulnerability that allows authenticated admins to write remote files into the web-accessible files/ directory via Bazar CSV import preview. Attackers can import a CSV whose file or image field references a remote .php URL, which is saved without extension… | |
| Deferred | Medium (5.3) | 0.24% | — | YeswikiAI | 10/2/2026 | 10/4/2026 | YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows page editors to make the server fetch arbitrary URLs via the url parameter of the Bazar valeur action. Attackers can embed the action with a champ parameter in wiki markup to reach loopback or internal services and partially read… |