CVE-2026-43869 Apache Thrift: TSSLTransportFactory.java hostname verification

Information published.


CVE-2026-8328 FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address

Information published.


CVE-2026-7246 Pallets Click contains a command injection via Unsanitized Filename "click.edit()"

Information published.


CVE-2026-43443 ASoC: amd: acp-mach-common: Add missing error check for clock acquisition

Information published.


CVE-2026-44662 rust-openssl: Heap buffer overflow when encrypting with AES key-wrap-with-padding

Information published.


CVE-2026-42154 Prometheus: remote read endpoint allows denial of service via crafted snappy payload

Information published.


CVE-2026-6210 Type confusion and heap-buffer-overflow in Qt SVG marker handling causing application crash

Information published.


CVE-2026-41602 Apache Thrift: Go TFramedTransport uint32 overflow

Information published.


CVE-2025-48431 Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid pointer error.

Information published.


CVE-2026-42151 Prometheus Azure AD remote write OAuth client secret exposed via config API

Information published.


This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

AbuseIPDB Contributor Badge