CVE tracker
362 subscribers
4.91K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-43820 - SwiftNIO-SSL Out-of-Bounds Memory Access

CVE ID :CVE-2026-43820
Published : July 23, 2026, 3:17 p.m. | 59 minutes ago
Description :NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not all SANs are backed by ASN1_STRING, so accessing the buffer for such a type can lead to out-of-bounds memory access. This vulnerability is addressed in swift-nio-ssl version 2.37.2.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-43823 - Swift-Crypto RSA Double Free Vulnerability

CVE ID :CVE-2026-43823
Published : July 23, 2026, 3:17 p.m. | 59 minutes ago
Description :When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the catch block, then in the deinit. This can lead to a crash on future memory allocations. This double-free manifests when BoringSSL cannot decode the public key from the bytes provided. This vulnerability is addressed in swift-crypto version 4.5.1.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48530 - GFI Archiver < 15.13 Stored XSS via CategorizationPolicyWizard.aspx

CVE ID :CVE-2026-48530
Published : July 23, 2026, 3:23 p.m. | 53 minutes ago
Description :GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Classification Rules configuration that allows authenticated attackers to inject arbitrary web script or HTML via the rule name and email criteria parameters to /Archiver/CategorizationPolicyWizard.aspx. The injected payload is stored by CategorizationPolicyWizard.SaveAllConfigSettings() without output encoding and is executed in the browsers of users who subsequently view the Classification Rules page.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48531 - GFI Archiver < 15.13 Stored XSS via RetentionPolicyWizard.aspx

CVE ID :CVE-2026-48531
Published : July 23, 2026, 3:25 p.m. | 51 minutes ago
Description :GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or HTML via the policy name parameter to /Archiver/RetentionPolicyWizard.aspx. The injected payload is stored by RetentionPolicyWizard.SaveAllConfigSettings() without output encoding and is executed in the browsers of users who subsequently view the Retention and Spam Policies page.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48532 - GFI Archiver < 15.13 Stored XSS via FAARetentionPolicyWizard.aspx

CVE ID :CVE-2026-48532
Published : July 23, 2026, 3:26 p.m. | 50 minutes ago
Description :GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File History Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or HTML via the policy name parameter to /Archiver/FAARetentionPolicyWizard.aspx. The injected payload is stored by RetentionPolicyWizard.SaveAllConfigSettings() without output encoding and is executed in the browsers of users who subsequently view the File History Retention Policies page.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-48533
Published : July 23, 2026, 3:27 p.m. | 49 minutes ago
Description :None
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48534 - GFI Archiver < 15.13 Stored XSS via ImapServerWizard.aspx

CVE ID :CVE-2026-48534
Published : July 23, 2026, 3:28 p.m. | 48 minutes ago
Description :GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that allows authenticated attackers to inject arbitrary web script or HTML via the server URL parameter to /Archiver/ImapServerWizard.aspx. The injected payload is stored by ImapServerWizard.SaveAllConfigSettings() without output encoding and is executed in the browsers of users who subsequently view the IMAP Server configuration page.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48535 - GFI Archiver < 15.13 Stored XSS via CallHomeSettingsWizard.aspx

CVE ID :CVE-2026-48535
Published : July 23, 2026, 3:29 p.m. | 47 minutes ago
Description :GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configuration that allows authenticated attackers to inject arbitrary web script or HTML via the proxy server address parameter to /Archiver/CallHomeSettingsWizard.aspx. The injected payload is stored by CallHomeSettingsWizard.SaveAllConfigSettings() without output encoding and is executed in the browsers of users who subsequently view the General Settings Additional Settings page.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48536 - GFI Archiver < 15.13 Stored XSS via GeneralSettingsWizard.aspx

CVE ID :CVE-2026-48536
Published : July 23, 2026, 3:30 p.m. | 46 minutes ago
Description :GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuration that allows authenticated attackers to inject arbitrary web script or HTML via the SMTP server address parameter to /Archiver/GeneralSettingsWizard.aspx. The injected payload is stored by GeneralSettingsWizard.SaveAllConfigSettings() without output encoding and is executed in the browsers of users who subsequently view the General Settings page.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48537 - GFI Archiver < 15.13 Stored XSS via FileArchiveAssistantWizard.aspx

CVE ID :CVE-2026-48537
Published : July 23, 2026, 3:31 p.m. | 45 minutes ago
Description :GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configuration that allows authenticated attackers to inject arbitrary web script or HTML via the excluded extensions parameter to /Archiver/FileArchiveAssistantWizard.aspx. The injected payload is stored by FileArchiveAssistantWizard.btnSave_Click() without output encoding and is executed in the browsers of users who subsequently view the File Archive Assistant settings page.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48538 - GFI Archiver < 15.13 Stored XSS via ImportSettingsWizard.ashx

CVE ID :CVE-2026-48538
Published : July 23, 2026, 3:32 p.m. | 44 minutes ago
Description :GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configuration that allows authenticated attackers to inject arbitrary web script or HTML via the configured folders parameter to /Archiver/ImportSettingsWizard.ashx. The injected payload is stored by ImportSettingsWizard.SaveAllConfigSettings() without output encoding and is executed in the browsers of users who subsequently view the Archive Assistant default import settings.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48539 - GFI Archiver < 15.13 Stored XSS via MailInsights.aspx

CVE ID :CVE-2026-48539
Published : July 23, 2026, 3:32 p.m. | 43 minutes ago
Description :GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report configuration that allows authenticated attackers to inject arbitrary web script or HTML via the report name parameter to /Archiver/MailInsights.aspx. The injected payload is stored by ReportScheduling.btnSaveReport_Click() without output encoding and is executed in the browser of the user who created the scheduled report when they subsequently view the MailInsights page.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16584 - AWS API MCP Server Security Policy Bypass via Startup Failure

CVE ID :CVE-2026-16584
Published : July 23, 2026, 3:34 p.m. | 42 minutes ago
Description :Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to bypass the user-configured security policy and execute AWS API operations that the policy was set to deny or gate. When initialization of the security policy enforcement data fails at server startup, the policy check is skipped for the lifetime of the process. IAM permissions on the configured credentials remain in effect and are unaffected. To remediate this issue, users should upgrade to version 1.3.47.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-15617 - Principal/domain lookup without case normalization

CVE ID :CVE-2026-15617
Published : July 23, 2026, 3:41 p.m. | 35 minutes ago
Description :Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via case- or Unicode-different identities.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-15616 - Local MFA not enforced during SSO sign-in

CVE ID :CVE-2026-15616
Published : July 23, 2026, 3:43 p.m. | 33 minutes ago
Description :Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unauthorized access.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-15615 - SAML element not validated

CVE ID :CVE-2026-15615
Published : July 23, 2026, 3:43 p.m. | 33 minutes ago
Description :Logto omits validation of the SAML element, enabling attackers to strip time and audience restrictions and replay assertions indefinitely.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-15614 - IdP-initiated SAML sessions not reliably invalidated (replay)

CVE ID :CVE-2026-15614
Published : July 23, 2026, 3:44 p.m. | 32 minutes ago
Description :Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s validity window.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-15612 - LOIDC nonce validation bypass

CVE ID :CVE-2026-15612
Published : July 23, 2026, 3:45 p.m. | 31 minutes ago
Description :Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication tokens and weakening session-binding.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-15611 - Unverified email-based SSO account linking

CVE ID :CVE-2026-15611
Published : July 23, 2026, 3:45 p.m. | 31 minutes ago
Description :Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized access to the victim’s account.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65916 - CyberPanel Missing Authorization in cancelBackupCreation Handler

CVE ID :CVE-2026-65916
Published : July 23, 2026, 3:53 p.m. | 23 minutes ago
Description :CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows authenticated users to kill, delete, and corrupt other tenants' backups. Attackers can send crafted POST requests with arbitrary backupCancellationDomain and fileName parameters to terminate backup processes, delete backup archives, corrupt backup status files, and remove database records belonging to other tenants.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65917 - CyberPanel IncBackups IDOR via Sequential Backup ID

CVE ID :CVE-2026-65917
Published : July 23, 2026, 3:59 p.m. | 17 minutes ago
Description :CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in the IncBackups application's incremental-backup handlers (deleteBackup, fetchRestorePoints, and restorePoint) that allows authenticated panel users to access or manipulate other tenants' backup resources by supplying an attacker-controlled globally sequential IncJob integer ID that is never re-scoped to the authorized domain. Attackers can enumerate sequential backup IDs to read another tenant's backup metadata, irrecoverably delete another tenant's backup snapshots, or trigger unauthorized restoration of another tenant's backup job with root privileges.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...