Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.2 CVE-2026-57959

Hi.Events 1.9.0 – Promo Code Max-Usage Bypass via Asynchronous Job Race Condition_CVE-2026-57959

Hi.Events through 1.9.0 contains a promo code validation vulnerability where reservation validates usage count before asynchronous UpdateEventStati...

HiEventsDev Hi.Events CVE
HIGH 8.3 CVE-2026-57955

SigNoz 0.130.1 – SQL Injection in Alert History Endpoints via Rule ID Parameter_CVE-2026-57955

SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary ClickHouse queries by inject...

SigNoz signoz CVE
HIGH 7.1 CVE-2026-57951

Mythic < 3.4.0.60 - Broken Permission Filter in payload_build_step Table_CVE-2026-57951

Mythic before 3.4.0.60 contains a broken hasura permission filter on the payload_build_step table with an always-satisfied _or condition that bypas...

its-a-feature Mythic CVE
HIGH 8.6 CVE-2026-57950

ruoyi-vue-pro – Incorrect Permission Namespace in ErpSaleOrderController_CVE-2026-57950

ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control vulnerability in ErpSaleOrderController that allows attacke...

Yunai ruoyi-vue-pro CVE
HIGH 7.1 CVE-2026-57949

ruoyi-vue-pro – Missing Authorization in CRM Follow-up Record GET Endpoint_CVE-2026-57949

ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module's GET /admin-api/crm/follo...

Yunai ruoyi-vue-pro CVE
HIGH 7.6 CVE-2026-57948

Pinpoint – Insecure Session Cookie Attributes in pinpointJwt_CVE-2026-57948

Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie...

pinpoint-apm pinpoint CVE
HIGH 7.1 CVE-2026-56783

Parseable < 2.9.2 - Cleartext Credential Exposure in Notification Target API_CVE-2026-56783

Parseable before 2.9.2 contains an information disclosure vulnerability in the notification-target API endpoints that returns webhook tokens and ba...

parseablehq parseable CVE
HIGH 7.7 CVE-2026-56780

Modoboa < 2.9.0 - Insecure Direct Object Reference in Account Password Change API_CVE-2026-56780

Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api/v1/accounts/{pk}/password/ endpoint that allows dom...

modoboa modoboa CVE
HIGH 7.7 CVE-2026-56285

Nitter – Server-Side Request Forgery in /video Media Proxy Endpoint_CVE-2026-56285

Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded default HMAC key, allowing unauth...

zedeus nitter CVE
HIGH 7.5 CVE-2026-49049

Joomla Extension – joomshaper.com – Unauthenticated access to Helix3 template ajax handler_CVE-2026-49049

The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON fi...

joomshaper.com Helix3 extension for Joomla 1.0-3.1.1 CVE