Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.7 CVE-2026-12755

CVE-2026-12755_CVE-2026-12755

Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with...

Devolutions Server 2026.2.4.0 CVE
MEDIUM 5.3 CVE-2026-6432

Improper bounds validation in EmberZNet SDK_CVE-2026-6432

Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or dynamic memory leakage.

Silicon Labs SiSDK CVE
LOW 3.3 CVE-2026-57588

SQL Injection in Nessus via Malicious Scan Result File Import_CVE-2026-57588

A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a privileged user, injects ...

tenable Nessus CVE
MEDIUM 5.3 CVE-2026-57587

SQL Injection in Nessus via Reverse DNS Lookup_CVE-2026-57587

A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a scanned host to inject mal...

tenable Nessus CVE
MEDIUM 6.3 CVE-2026-57536

Insufficient validation of payment status in pretix-mollie_CVE-2026-57536

Our payment integration with Mollie did not properly validate payment status responses. An attacker could use a successful payment status respons...

pretix pretix-mollie CVE
LOW 2.1 CVE-2026-57535

CVE-2026-57535_CVE-2026-57535

Content injected to PDF rendering contexts could, in many places, include HTML content including tags. If the src attribute of these images point...

pretix pretix CVE
LOW 2.1 CVE-2026-57534

Stored XSS in pretix-pages_CVE-2026-57534

Malicious HTML content could be injected into the content of a page in the pretix-pages plugin.

pretix pretix-pages CVE
LOW 2.1 CVE-2026-57533

CVE-2026-57533_CVE-2026-57533

Malicious HTML content could be injected into the page pretix shows when redirection to an untrusted page occurs. Since this page has a Content-S...

pretix pretix CVE
HIGH 8.8 CVE-2026-57532

CVE-2026-57532_CVE-2026-57532

Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF editor is opened in the br...

pretix pretix CVE
LOW 1.7 CVE-2026-57437

Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime_CVE-2026-57437

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::XPathContext did not keep its so...

sparklemotion nokogiri < 1.19.4 CVE