Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.4 CVE-2026-56023

WordPress UPI QR Code Payment Gateway for WooCommerce plugin <= 1.6.2 - Broken Access Control vulnerability_CVE-2026-56023

Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce

Knit Pay UPI QR Code Payment Gateway for WooCommerce n/a CVE
MEDIUM 6.5 CVE-2026-56013

WordPress License Manager for WooCommerce plugin <= 3.0.15 - Insecure Direct Object References (IDOR) vulnerability_CVE-2026-56013

Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce

myCred License Manager for WooCommerce n/a CVE
MEDIUM 5.9 CVE-2026-52690

Spoofed answers can mark an authoritative non-EDNS capable_CVE-2026-52690

Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of DNSSEC records served by tha...

PowerDNS Recursor 5.2.0 CVE
MEDIUM 6.7 CVE-2026-46732

CVE-2026-46732_CVE-2026-46732

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain a Concurrent Execution using Shared Resource with Improper Synchroni...

Dell Display and Peripheral Manager CVE
MEDIUM 5.3 CVE-2026-42390

ZONEMD validation can be bypassed_CVE-2026-42390

An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured with ZONEMD validation.

PowerDNS Recursor 5.4.0 CVE
MEDIUM 5.3 CVE-2026-42389

Reject more queries with invalid header values_CVE-2026-42389

This fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative servers.

PowerDNS Recursor 5.4.0 CVE
MEDIUM 5.9 CVE-2026-42388

Missing input validation for catalog zones_CVE-2026-42388

Incomplete validation of the SOA record present in a catalog zone might lead to a crash.

PowerDNS Recursor 5.2.0 CVE
MEDIUM 5.9 CVE-2026-42387

Insufficient input validation in ZoneToCache_CVE-2026-42387

A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recursor due to insuffcient inpu...

PowerDNS Recursor 5.2.0 CVE
MEDIUM 5.3 CVE-2026-40012

Information about ECS zero scoped answers might leak to clients that use a specific ECS_CVE-2026-40012

ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have ECS enabled;

PowerDNS Recursor 5.2.0 CVE
MEDIUM 5.3 CVE-2026-6432

Improper bounds validation in EmberZNet SDK_CVE-2026-6432

Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or dynamic memory leakage.

Silicon Labs SiSDK CVE