Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-48536 — GFI Archiver < 15.13 Stored XSS via GeneralSettingsWizard.aspx

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuration that allows authenticated attackers to inject arbitrary web script or HTML vi…

archiver | Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.4 MEDIUM
CVE-2026-48535 — GFI Archiver < 15.13 Stored XSS via CallHomeSettingsWizard.aspx

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configuration that allows authenticated attackers to inject arbitrary web script or HTML v…

archiver | Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.4 MEDIUM
CVE-2026-48534 — GFI Archiver < 15.13 Stored XSS via ImapServerWizard.aspx

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that allows authenticated attackers to inject arbitrary web script or HTML via the serv…

archiver | Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.4 MEDIUM
CVE-2026-48532 — GFI Archiver < 15.13 Stored XSS via FAARetentionPolicyWizard.aspx

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File History Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or…

archiver | Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.4 MEDIUM
CVE-2026-48531 — GFI Archiver < 15.13 Stored XSS via RetentionPolicyWizard.aspx

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or HTML via the…

archiver | Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.4 MEDIUM
CVE-2026-48530 — GFI Archiver < 15.13 Stored XSS via CategorizationPolicyWizard.aspx

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Classification Rules configuration that allows authenticated attackers to inject arbitrary web script or HTML via…

archiver | Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.3 HIGH
CVE-2026-16584 — AWS API MCP Server Security Policy Bypass via Startup Failure

Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to bypass the user-configured security policy and execute AWS API operations that …

aws-api-mcp-server | Misconfiguration
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
0.0 NA
CVE-2026-15617 — Principal/domain lookup without case normalization

Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via case- or Unicode-different identities.

| Authentication
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
0.0 NA
CVE-2026-15616 — Local MFA not enforced during SSO sign-in

Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unauthorized access.

| Authentication
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
0.0 NA
CVE-2026-15615 — SAML <Conditions> element not validated

Logto omits validation of the SAML <Conditions> element, enabling attackers to strip time and audience restrictions and replay assertions indefinitely.

| Authentication
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
0.0 NA
CVE-2026-15614 — IdP-initiated SAML sessions not reliably invalidated (replay)

Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s validity window.

| Authentication
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
0.0 NA
CVE-2026-15612 — LOIDC nonce validation bypass

Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication tokens and weakening session-binding.

| Authentication
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
0.0 NA
CVE-2026-15611 — Unverified email-based SSO account linking

Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized access to the victim’s account.

| Authentication
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.2 MEDIUM
CVE-2026-11804 — Program Module Vulnerability

Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Privil…

niagara_enterprise_security | Authorization
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.5 HIGH
CVE-2026-43823 — Swift-Crypto RSA Double Free Vulnerability

When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the catch block, then in the deinit. This can lead to a crash on future memory alloc…

swift-crypto | Remote | Memory Corruption
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
0.0 NA
CVE-2026-43820 — SwiftNIO-SSL Out-of-Bounds Memory Access

NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not all SANs are backed b…

| Memory Corruption
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
4.3 MEDIUM
CVE-2026-8287 — Unrestricted File Upload in BizimHesap Information Systems' Online Pre-Accounting Software

Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade Inc. Online Pre-Accounting Software allows Excessive Allocation. This issue af…

Remote | Denial of Service
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.3 MEDIUM
CVE-2026-65914 — DOMPurify before 3.3.2 Mutation XSS via Re-Contextualization

DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing contexts using innerHTML with wrappers like script, xmp, iframe, noembed, noframes,…

dompurify | Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
6.1 MEDIUM
CVE-2026-65913 — DOMPurify before 3.3.2 Prototype Pollution via USE_PROFILES

DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass attribute filtering by polluting Array.prototype properties. Attackers can set…

dompurify | Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
6.1 MEDIUM
CVE-2026-65912 — DOMPurify before 3.3.2 URI Validation Bypass via ADD_ATTR

DOMPurify before 3.3.2 contains a URI validation bypass vulnerability when ADD_ATTR is provided as a predicate function via EXTRA_ELEMENT_HANDLING.attributeCheck. Attackers can supply a predicate tha…

dompurify | Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Showing 20 of 9724 Results