CVE Vulnerability Database
Search and browse 384,615 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48539 | MEDIUM | 5.4 | — | Jul 23, 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report conf... |
| CVE-2026-48538 | MEDIUM | 5.4 | — | Jul 23, 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configurat... |
| CVE-2026-48537 | MEDIUM | 5.4 | — | Jul 23, 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configurati... |
| CVE-2026-48536 | MEDIUM | 5.4 | — | Jul 23, 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuratio... |
| CVE-2026-48535 | MEDIUM | 5.4 | 0.1% | Jul 23, 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configurati... |
| CVE-2026-48534 | MEDIUM | 5.4 | — | Jul 23, 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that all... |
| CVE-2026-48533 | — | — | — | Jul 23, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-48532 | MEDIUM | 5.4 | — | Jul 23, 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File History Retention Policy conf... |
| CVE-2026-48531 | MEDIUM | 5.4 | — | Jul 23, 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Policy configuration tha... |
| CVE-2026-48530 | MEDIUM | 5.4 | — | Jul 23, 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Classification Rules configuration... |
| CVE-2026-16584 | HIGH | 7.3 | — | Jul 23, 2026 | Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to ... |
| CVE-2026-15617 | CRITICAL | 9.1 | 0.2% | Jul 23, 2026 | Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unaut... |
| CVE-2026-15616 | CRITICAL | 9.1 | 0.2% | Jul 23, 2026 | Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirem... |
| CVE-2026-15615 | HIGH | 7.5 | 0.1% | Jul 23, 2026 | Logto omits validation of the SAML <Conditions> element, enabling attackers to strip time and audience restrictions and ... |
| CVE-2026-15614 | HIGH | 7.5 | 0.1% | Jul 23, 2026 | Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s valid... |
| CVE-2026-15612 | CRITICAL | 9.1 | 0.1% | Jul 23, 2026 | Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication... |
| CVE-2026-15611 | CRITICAL | 9.1 | 0.2% | Jul 23, 2026 | Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive Id... |
| CVE-2026-11804 | MEDIUM | 5.2 | — | Jul 23, 2026 | Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux... |
| CVE-2026-43823 | HIGH | 7.5 | — | Jul 23, 2026 | When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the c... |
| CVE-2026-43820 | HIGH | 7.7 | 0.1% | Jul 23, 2026 | NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to... |
| CVE-2026-8287 | MEDIUM | 4.3 | — | Jul 23, 2026 | Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade ... |
| CVE-2026-65914 | MEDIUM | 6.1 | 0.3% | Jul 23, 2026 | DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing cont... |
| CVE-2026-65913 | MEDIUM | 6.1 | 0.2% | Jul 23, 2026 | DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass... |
| CVE-2026-65912 | MEDIUM | 6.1 | 0.2% | Jul 23, 2026 | DOMPurify before 3.3.2 contains a URI validation bypass vulnerability when ADD_ATTR is provided as a predicate function ... |
| CVE-2026-65911 | MEDIUM | 6.1 | 0.2% | Jul 23, 2026 | In DOMPurify through 3.3.3, function predicates supplied via ADD_ATTR or ADD_TAGS to DOMPurify.sanitize() persist in int... |
