Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.1 CVE-2026-12862

XLSX formula injection in exports_CVE-2026-12862

Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be used to compromise the env...

pretix Venueless 0.0.0 CVE
MEDIUM 5.1 CVE-2026-12580

Digiwin|EasyFlow .NET – Stored Cross-Site Scripting_CVE-2026-12580

EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent Ja...

Digiwin EasyFlow .NET CVE
MEDIUM 6.3 CVE-2026-54665

Apache NiFi: Missing Validation for Proxy Host Headers_CVE-2026-54665

Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an alternative to the standar...

Apache Software Foundation Apache NiFi 0.0.1 CVE
MEDIUM 5.2 CVE-2026-44913

Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL_CVE-2026-44913

Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQ...

Apache Software Foundation Apache NiFi 1.2.0 CVE
MEDIUM 6.9 CVE-2026-11748

CVE-2026-11748_CVE-2026-11748

A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitut...

LY Corporation Central Dogma 0.84.0 CVE
MEDIUM 4.8 CVE-2026-12823

Browserbase Autobrowse Trace Artifact default permission_CVE-2026-12823

A security flaw has been discovered in Browserbase up to 20260526. This impacts an unknown function of the component Autobrowse Trace Artifact Hand...

n/a Browserbase 20260526 CVE
MEDIUM 4.8 CVE-2026-12822

langflow-ai langflow Bundle URL Loader code injection_CVE-2026-12822

A vulnerability was identified in langflow-ai langflow up to 1.9.3. This affects an unknown function of the component Bundle URL Loader. The manipu...

langflow-ai langflow 1.9.0 CVE
MEDIUM 5.3 CVE-2026-12810

Edimax BR-6478AC V2 POST Request mp command injection_CVE-2026-12810

A security flaw has been discovered in Edimax BR-6478AC V2 1.23. Affected by this vulnerability is the function mp of the file /goform/mp of the co...

Edimax BR-6478AC V2 1.23 CVE
MEDIUM 5.3 CVE-2026-12809

Edimax BR-6478AC V2 POST Request wiz_5in1_redirect command injection_CVE-2026-12809

A vulnerability was identified in Edimax BR-6478AC V2 1.23. Affected is the function wiz_5in1_redirect of the file /goform/wiz_5in1_redirect of the...

Edimax BR-6478AC V2 1.23 CVE
MEDIUM 5.1 CVE-2026-12812

Radware Cyber Controller HTML Report Generation HTML injection_CVE-2026-12812

A security vulnerability has been detected in Radware Cyber Controller up to 10.11.0. This affects an unknown part of the component HTML Report Gen...

Radware Cyber Controller 10.0 CVE