Total CVEs

150,798

Critical Severity

4,991

High Severity

17,614

Last 7 Days

2,022
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,101 - 2,120 of 47,203 CVEs
CVE-2026-48538 MEDIUM - 5.4

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configuration that allows authenticated attackers to inject arbitrary web script or HTML via the configured folders parameter to /Archiver/ImportSettingsWizard.ashx. The injected payload is ...

Vendor: GFI Software
Product: GFI Archiver
Published: Jul 23, 2026
Source: NVD
CVE-2026-48537 MEDIUM - 5.4

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configuration that allows authenticated attackers to inject arbitrary web script or HTML via the excluded extensions parameter to /Archiver/FileArchiveAssistantWizard.aspx. The injected paylo...

Vendor: GFI Software
Product: GFI Archiver
Published: Jul 23, 2026
Source: NVD
CVE-2026-48536 MEDIUM - 5.4

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuration that allows authenticated attackers to inject arbitrary web script or HTML via the SMTP server address parameter to /Archiver/GeneralSettingsWizard.aspx. The injected payload is ...

Vendor: GFI Software
Product: GFI Archiver
Published: Jul 23, 2026
Source: NVD
CVE-2026-48535 MEDIUM - 5.4

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configuration that allows authenticated attackers to inject arbitrary web script or HTML via the proxy server address parameter to /Archiver/CallHomeSettingsWizard.aspx. The injected payload ...

Vendor: GFI Software
Product: GFI Archiver
Published: Jul 23, 2026
Source: NVD
CVE-2026-48534 MEDIUM - 5.4

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that allows authenticated attackers to inject arbitrary web script or HTML via the server URL parameter to /Archiver/ImapServerWizard.aspx. The injected payload is stored by ImapServerWiza...

Vendor: GFI Software
Product: GFI Archiver
Published: Jul 23, 2026
Source: NVD

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Published: Jul 23, 2026
Source: NVD
CVE-2026-48532 MEDIUM - 5.4

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File History Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or HTML via the policy name parameter to /Archiver/FAARetentionPolicyWizard.aspx. The injected payload ...

Vendor: GFI Software
Product: GFI Archiver
Published: Jul 23, 2026
Source: NVD
CVE-2026-48531 MEDIUM - 5.4

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or HTML via the policy name parameter to /Archiver/RetentionPolicyWizard.aspx. The injected payload is stored by Ret...

Vendor: GFI Software
Product: GFI Archiver
Published: Jul 23, 2026
Source: NVD
CVE-2026-48530 MEDIUM - 5.4

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Classification Rules configuration that allows authenticated attackers to inject arbitrary web script or HTML via the rule name and email criteria parameters to /Archiver/CategorizationPolicyWizard.aspx. The inject...

Vendor: GFI Software
Product: GFI Archiver
Published: Jul 23, 2026
Source: NVD
CVE-2026-16584 HIGH - 7.0

Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to bypass the user-configured security policy and execute AWS API operations that the policy was set to deny or gate. When initialization of the security policy enforcement data fails...

Vendor: AWS
Product: aws-api-mcp-server
Published: Jul 23, 2026
Source: NVD
CVE-2026-15617 CRITICAL - 9.1

Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via case- or Unicode-different identities.

Vendor: Logto
Product: Logto
Published: Jul 23, 2026
Source: NVD
CVE-2026-15616 CRITICAL - 9.1

Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unauthorized access.

Vendor: Logto
Product: Logto
Published: Jul 23, 2026
Source: NVD
CVE-2026-15615 HIGH - 7.5

Logto omits validation of the SAML <Conditions> element, enabling attackers to strip time and audience restrictions and replay assertions indefinitely.

Vendor: Logto
Product: Logto
Published: Jul 23, 2026
Source: NVD
CVE-2026-15614 HIGH - 7.5

Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s validity window.

Vendor: Logto
Product: Logto
Published: Jul 23, 2026
Source: NVD
CVE-2026-15612 CRITICAL - 9.1

Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication tokens and weakening session-binding.

Vendor: Logto
Product: Logto
Published: Jul 23, 2026
Source: NVD
CVE-2026-15611 CRITICAL - 9.1

Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized access to the victim’s account.

Vendor: Logto
Product: Logto
Published: Jul 23, 2026
Source: NVD
CVE-2026-11804 MEDIUM - 5.2

Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Privilege Abuse. This issue affects Niagara Framework: before 4.14.6, before 4.15.5; Niagara Enterprise Se...

Vendor: Tridium
Product: Niagara Framework, Niagara Enterprise Security
Published: Jul 23, 2026
Source: NVD
CVE-2026-43823 HIGH - 7.5

When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the catch block, then in the deinit. This can lead to a crash on future memory allocations. This double-free manifests when BoringSSL cannot decode the public key from the bytes provide...

Vendor: Apple
Product: swift-crypto
Published: Jul 23, 2026
Source: NVD
CVE-2026-43820 HIGH - 7.7

NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not all SANs are backed by ASN1_STRING, so accessing the buffer for such a type can lead to out-of-bounds memory access. ...

Vendor: Apple
Product: swift-nio-ssl
Published: Jul 23, 2026
Source: NVD
CVE-2026-45623 HIGH - 7.5

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferences PATH against the...

Vendor: npm
Product: postcss
Published: Jul 23, 2026
Source: GitHub