Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51620
Total
4095
Critical
15305
High
14964
Medium
CVE ID Severity Score Description Published
CVE-2026-65695 MEDIUM 6.8 Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attackers who can influence the filename argument to read arbitrary .docx … Jul 23, 2026
CVE-2026-44909 HIGH 7.5 Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETTINGS_INITIAL_WINDOW_SIZE to … Jul 23, 2026
CVE-2026-16768 MEDIUM 5.3 A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read … Jul 23, 2026
CVE-2026-65917 HIGH 8.8 CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in the IncBackups application's incremental-backup handlers (deleteBackup, fetchRestorePoints, and restorePoint) … Jul 23, 2026
CVE-2026-65916 HIGH 8.1 CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows authenticated users to kill, delete, and corrupt … Jul 23, 2026
CVE-2026-48539 MEDIUM 5.4 GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report configuration that allows authenticated attackers to inject arbitrary web script … Jul 23, 2026
CVE-2026-48538 MEDIUM 5.4 GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configuration that allows authenticated attackers to inject arbitrary web script … Jul 23, 2026
CVE-2026-48537 MEDIUM 5.4 GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configuration that allows authenticated attackers to inject arbitrary web script … Jul 23, 2026
CVE-2026-48536 MEDIUM 5.4 GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuration that allows authenticated attackers to inject arbitrary web script … Jul 23, 2026
CVE-2026-48535 MEDIUM 5.4 GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configuration that allows authenticated attackers to inject arbitrary web … Jul 23, 2026
CVE-2026-48534 MEDIUM 5.4 GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that allows authenticated attackers to inject arbitrary web script or … Jul 23, 2026
CVE-2026-48533 UNKNOWN — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Jul 23, 2026
CVE-2026-48532 MEDIUM 5.4 GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File History Retention Policy configuration that allows authenticated attackers to inject arbitrary web … Jul 23, 2026
CVE-2026-48531 MEDIUM 5.4 GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or … Jul 23, 2026
CVE-2026-48530 MEDIUM 5.4 GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Classification Rules configuration that allows authenticated attackers to inject arbitrary web script or … Jul 23, 2026
CVE-2026-16584 HIGH 7.0 Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to bypass the user-configured security policy … Jul 23, 2026
CVE-2026-15617 UNKNOWN — Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via case- or Unicode-different identities. Jul 23, 2026
CVE-2026-15616 UNKNOWN — Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unauthorized access. Jul 23, 2026
CVE-2026-15615 UNKNOWN — Logto omits validation of the SAML <Conditions> element, enabling attackers to strip time and audience restrictions and replay assertions indefinitely. Jul 23, 2026
CVE-2026-15614 UNKNOWN — Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s validity window. Jul 23, 2026
CVE-2026-15612 UNKNOWN — Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication tokens and weakening session-binding. Jul 23, 2026
CVE-2026-15611 UNKNOWN — Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized … Jul 23, 2026
CVE-2026-11804 MEDIUM 5.2 Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows … Jul 23, 2026
CVE-2026-43823 HIGH 7.5 When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the catch block, then in … Jul 23, 2026
CVE-2026-43820 UNKNOWN — NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but … Jul 23, 2026