🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-90440 Uncaught exception, improper handling of exceptional conditions, improper resource shutdown vulnerability in Apache Thrift D thrift.server.nonblocking... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-87117 NULL pointer dereference vulnerability in Apache Thrift PHP bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to ... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-86537 Uncaught exception, Loop with unreachable exit condition ('infinite loop'), Integer underflow (wrap or wraparound) vulnerability in Apache T... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-86536 Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift all JS bindings.
... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104473 YesWiki before 4.5.3 contains multiple reflected cross-site scripting vulnerabilities that allow remote attackers to inject JavaScript through unsanit... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104472 YesWiki before 4.6.7 contains a missing authorization vulnerability in the attachment download handler that allows unauthenticated attackers to bypass... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104471 YesWiki before 4.6.7 contains an unrestricted file upload vulnerability that allows authenticated admins to write remote files into the web-accessible... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104470 YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows page editors to make the server fetch arbitrary URLs via the url... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104469 YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated sessions because login does not regenerat... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104468 YesWiki before 4.6.7 contains an insufficient session expiration vulnerability that allows attackers to reuse old password reset links because tokens ... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104467 YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiService::isAuthorized() that allows unauthenticated attackers to call admin-... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104466 YesWiki before 4.6.7 contains a stored cross-site scripting vulnerability in formatters/wakka.php that allows users who can edit pages or post comment... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104465 YesWiki before 4.6.7 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the field par... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104464 YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make server-side GET requests by su... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104463 YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to trigger server requests by sending ... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104462 YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar nuagetag action, which concatenates the unescaped tags attribute into a raw ... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104461 YesWiki before 4.6.7 contains a stored cross-site scripting vulnerability in the Bazar FileField, which validates only the upload's file extensio... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104460 YesWiki before 4.6.7 contains a blind SQL injection vulnerability in the {{newtextsearch}} action because Bazar list option ids are concatenated into ... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104459 YesWiki before 4.6.7 contains a server-side request forgery vulnerability in WebfingerService that allows unauthenticated attackers to trigger HTTPS r... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104458 YesWiki before 4.6.7 contains a server-side request forgery vulnerability in validateKeyIdUrl() that allows unauthenticated attackers to bypass the SS... | HIGH | ????? | ????? | NVD | 5 days ago |