CVE Vulnerability Database

Search and browse 384,615 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-48539MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report conf...
CVE-2026-48538MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configurat...
CVE-2026-48537MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configurati...
CVE-2026-48536MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuratio...
CVE-2026-48535MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configurati...
CVE-2026-48534MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that all...
CVE-2026-48533Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-48532MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File History Retention Policy conf...
CVE-2026-48531MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Policy configuration tha...
CVE-2026-48530MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Classification Rules configuration...
CVE-2026-16584HIGH7.3Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to ...
CVE-2026-15617CRITICAL9.1Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unaut...
CVE-2026-15616CRITICAL9.1Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirem...
CVE-2026-15615HIGH7.5Logto omits validation of the SAML <Conditions> element, enabling attackers to strip time and audience restrictions and ...
CVE-2026-15614HIGH7.5Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s valid...
CVE-2026-15612CRITICAL9.1Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication...
CVE-2026-15611CRITICAL9.1Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive Id...
CVE-2026-11804MEDIUM5.2Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux...
CVE-2026-43823HIGH7.5When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the c...
CVE-2026-43820HIGH7.7NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to...
CVE-2026-8287MEDIUM4.3Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade ...
CVE-2026-65914MEDIUM6.1DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing cont...
CVE-2026-65913MEDIUM6.1DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass...
CVE-2026-65912MEDIUM6.1DOMPurify before 3.3.2 contains a URI validation bypass vulnerability when ADD_ATTR is provided as a predicate function ...
CVE-2026-65911MEDIUM6.1In DOMPurify through 3.3.3, function predicates supplied via ADD_ATTR or ADD_TAGS to DOMPurify.sanitize() persist in int...