Total CVEs

150,882

Critical Severity

5,031

High Severity

17,660

Last 7 Days

2,090
Quick preset (or use dates below)
Clear Filters
Showing 2,181 - 2,200 of 150,882 CVEs
CVE-2026-16768 MEDIUM - 5.3

A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper bounds checking against the actual palette size. This vulnerability causes heap bytes to be interpreted as valid palette ...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jul 23, 2026
Source: NVD
CVE-2026-65917 HIGH - 8.8

CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in the IncBackups application's incremental-backup handlers (deleteBackup, fetchRestorePoints, and restorePoint) that allows authenticated panel users to access or manipulate oth...

Vendor: usmannasir
Product: cyberpanel
Published: Jul 23, 2026
Source: NVD
CVE-2026-65916 HIGH - 8.1

CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows authenticated users to kill, delete, and corrupt other tenants' backups. Attackers can send crafted POST requests with arbitrary backupCancellationDo...

Vendor: usmannasir
Product: cyberpanel
Published: Jul 23, 2026
Source: NVD
CVE-2026-48539 MEDIUM - 5.4

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report configuration that allows authenticated attackers to inject arbitrary web script or HTML via the report name parameter to /Archiver/MailInsights.aspx. The injected payload is stored by...

Vendor: GFI Software
Product: GFI Archiver
Published: Jul 23, 2026
Source: NVD
CVE-2026-48538 MEDIUM - 5.4

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configuration that allows authenticated attackers to inject arbitrary web script or HTML via the configured folders parameter to /Archiver/ImportSettingsWizard.ashx. The injected payload is ...

Vendor: GFI Software
Product: GFI Archiver
Published: Jul 23, 2026
Source: NVD
CVE-2026-48537 MEDIUM - 5.4

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configuration that allows authenticated attackers to inject arbitrary web script or HTML via the excluded extensions parameter to /Archiver/FileArchiveAssistantWizard.aspx. The injected paylo...

Vendor: GFI Software
Product: GFI Archiver
Published: Jul 23, 2026
Source: NVD
CVE-2026-48536 MEDIUM - 5.4

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuration that allows authenticated attackers to inject arbitrary web script or HTML via the SMTP server address parameter to /Archiver/GeneralSettingsWizard.aspx. The injected payload is ...

Vendor: GFI Software
Product: GFI Archiver
Published: Jul 23, 2026
Source: NVD
CVE-2026-48535 MEDIUM - 5.4

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configuration that allows authenticated attackers to inject arbitrary web script or HTML via the proxy server address parameter to /Archiver/CallHomeSettingsWizard.aspx. The injected payload ...

Vendor: GFI Software
Product: GFI Archiver
Published: Jul 23, 2026
Source: NVD
CVE-2026-48534 MEDIUM - 5.4

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that allows authenticated attackers to inject arbitrary web script or HTML via the server URL parameter to /Archiver/ImapServerWizard.aspx. The injected payload is stored by ImapServerWiza...

Vendor: GFI Software
Product: GFI Archiver
Published: Jul 23, 2026
Source: NVD

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Published: Jul 23, 2026
Source: NVD
CVE-2026-48532 MEDIUM - 5.4

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File History Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or HTML via the policy name parameter to /Archiver/FAARetentionPolicyWizard.aspx. The injected payload ...

Vendor: GFI Software
Product: GFI Archiver
Published: Jul 23, 2026
Source: NVD
CVE-2026-48531 MEDIUM - 5.4

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or HTML via the policy name parameter to /Archiver/RetentionPolicyWizard.aspx. The injected payload is stored by Ret...

Vendor: GFI Software
Product: GFI Archiver
Published: Jul 23, 2026
Source: NVD
CVE-2026-48530 MEDIUM - 5.4

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Classification Rules configuration that allows authenticated attackers to inject arbitrary web script or HTML via the rule name and email criteria parameters to /Archiver/CategorizationPolicyWizard.aspx. The inject...

Vendor: GFI Software
Product: GFI Archiver
Published: Jul 23, 2026
Source: NVD
CVE-2026-16584 HIGH - 7.0

Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to bypass the user-configured security policy and execute AWS API operations that the policy was set to deny or gate. When initialization of the security policy enforcement data fails...

Vendor: AWS
Product: aws-api-mcp-server
Published: Jul 23, 2026
Source: NVD
CVE-2026-15617 CRITICAL - 9.1

Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via case- or Unicode-different identities.

Vendor: Logto
Product: Logto
Published: Jul 23, 2026
Source: NVD
CVE-2026-15616 CRITICAL - 9.1

Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unauthorized access.

Vendor: Logto
Product: Logto
Published: Jul 23, 2026
Source: NVD
CVE-2026-15615 HIGH - 7.5

Logto omits validation of the SAML <Conditions> element, enabling attackers to strip time and audience restrictions and replay assertions indefinitely.

Vendor: Logto
Product: Logto
Published: Jul 23, 2026
Source: NVD
CVE-2026-15614 HIGH - 7.5

Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s validity window.

Vendor: Logto
Product: Logto
Published: Jul 23, 2026
Source: NVD
CVE-2026-15612 CRITICAL - 9.1

Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication tokens and weakening session-binding.

Vendor: Logto
Product: Logto
Published: Jul 23, 2026
Source: NVD
CVE-2026-15611 CRITICAL - 9.1

Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized access to the victim’s account.

Vendor: Logto
Product: Logto
Published: Jul 23, 2026
Source: NVD