|
781
|
5.3 |
MEDIUM
Network
|
-
|
-
|
This fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative servers.
New
|
CWE-20
Improper Input Validation
|
CVE-2026-42389
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
782
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Incomplete validation of the SOA record present in a catalog zone might lead to a crash.
New
|
CWE-20
Improper Input Validation
|
CVE-2026-42388
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
783
|
5.9 |
MEDIUM
Network
|
-
|
-
|
A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recursor due to insuffcient input validation.
New
|
CWE-20
Improper Input Validation
|
CVE-2026-42387
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
784
|
5.3 |
MEDIUM
Network
|
-
|
-
|
ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have ECS enabled;
New
|
CWE-524
Use of Cache Containing Sensitive Information
|
CVE-2026-40012
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
785
|
- |
|
-
|
-
|
Malicious HTML content could be injected into the content rendered by the pretix-digital plugin.
New
|
CWE-80
Basic XSS
|
CVE-2026-13314
|
2026-06-26 01:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
786
|
- |
|
-
|
-
|
Malicious HTML content could be injected into the email address of an
order, which pretix showed without sanitization on the confirmation page
for individual tickets in that order.
New
|
CWE-80
Basic XSS
|
CVE-2026-13225
|
2026-06-26 01:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
787
|
- |
|
-
|
-
|
Our payment integration with Computop-based payment methods did not
properly validate payment status responses. An attacker could use a
successful payment status response from one payment and suppl…
New
|
CWE-841
Improper Enforcement of Behavioral Workflow
|
CVE-2026-13223
|
2026-06-26 01:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
788
|
- |
|
-
|
-
|
Our payment integration with Oppwa-based payment methods did not
properly validate payment status responses. An attacker could use a
successful payment status response from one payment and supply i…
New
|
CWE-841
Improper Enforcement of Behavioral Workflow
|
CVE-2026-13222
|
2026-06-26 01:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
789
|
2.7 |
LOW
Network
|
-
|
-
|
Improper input validation in the PAM AD discovery endpoints in
Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated
user with the UserGroupsView permission to coerce server-side…
New
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2026-12755
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
790
|
2.5 |
LOW
Local
|
-
|
-
|
Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi HTML exports render session Markdown into a static HTML file. It did not consistently reject unsafe Markdown link and image URL s…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-54326
|
2026-06-26 01:14 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|