Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.1 CVE-2026-12862

XLSX formula injection in exports_CVE-2026-12862

Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be used to compromise the env...

pretix Venueless 0.0.0 CVE
HIGH 7.7 CVE-2026-12581

Digiwin|EasyFlow .NET – Session Fixation_CVE-2026-12581

EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a us...

Digiwin EasyFlow .NET CVE
MEDIUM 5.1 CVE-2026-12580

Digiwin|EasyFlow .NET – Stored Cross-Site Scripting_CVE-2026-12580

EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent Ja...

Digiwin EasyFlow .NET CVE
HIGH 8.7 CVE-2025-4994

Authentication Bypass for SafeLine SL6 and SL6+_CVE-2025-4994

The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authentication bypass. This vulnerabilit...

SafeLine SafeLine SL6/SL6+ 4.82 CVE
MEDIUM 6.3 CVE-2026-54665

Apache NiFi: Missing Validation for Proxy Host Headers_CVE-2026-54665

Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an alternative to the standar...

Apache Software Foundation Apache NiFi 0.0.1 CVE
HIGH 7.5 CVE-2026-44914

Apache NiFi: Missing Authorization of Restricted Permissions when Replacing Flow Contents_CVE-2026-44914

Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required P...

Apache Software Foundation Apache NiFi 1.12.0 CVE
MEDIUM 5.2 CVE-2026-44913

Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL_CVE-2026-44913

Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQ...

Apache Software Foundation Apache NiFi 1.2.0 CVE
LOW 2.3 CVE-2026-44911

Apache NiFi: Incorrect Authorization for Configuration Verification Requests_CVE-2026-44911

Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to sub...

Apache Software Foundation Apache NiFi 1.15.0 CVE
HIGH 7.3 CVE-2026-6645

Insecure Search Path Vulnerability in PaperCut Print Deploy Client for Windows_CVE-2026-6645

An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows. The app...

PaperCut Print Deploy CVE
HIGH 7.1 CVE-2026-8918

CVE-2026-8918_CVE-2026-8918

A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or cause a...

ASUS Armoury Crate CVE