|
1461
|
5.3 |
MEDIUM
Network
|
-
|
-
|
This fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative servers.
|
CWE-20
Improper Input Validation
|
CVE-2026-42389
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1462
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Incomplete validation of the SOA record present in a catalog zone might lead to a crash.
|
CWE-20
Improper Input Validation
|
CVE-2026-42388
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1463
|
5.9 |
MEDIUM
Network
|
-
|
-
|
A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recursor due to insuffcient input validation.
|
CWE-20
Improper Input Validation
|
CVE-2026-42387
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1464
|
5.3 |
MEDIUM
Network
|
-
|
-
|
ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have ECS enabled;
|
CWE-524
Use of Cache Containing Sensitive Information
|
CVE-2026-40012
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1465
|
- |
|
-
|
-
|
Malicious HTML content could be injected into the content rendered by the pretix-digital plugin.
|
CWE-80
Basic XSS
|
CVE-2026-13314
|
2026-06-26 01:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1466
|
- |
|
-
|
-
|
Malicious HTML content could be injected into the email address of an
order, which pretix showed without sanitization on the confirmation page
for individual tickets in that order.
|
CWE-80
Basic XSS
|
CVE-2026-13225
|
2026-06-26 01:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1467
|
- |
|
-
|
-
|
Our payment integration with Computop-based payment methods did not
properly validate payment status responses. An attacker could use a
successful payment status response from one payment and suppl…
|
CWE-841
Improper Enforcement of Behavioral Workflow
|
CVE-2026-13223
|
2026-06-26 01:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1468
|
- |
|
-
|
-
|
Our payment integration with Oppwa-based payment methods did not
properly validate payment status responses. An attacker could use a
successful payment status response from one payment and supply i…
|
CWE-841
Improper Enforcement of Behavioral Workflow
|
CVE-2026-13222
|
2026-06-26 01:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1469
|
2.5 |
LOW
Local
|
-
|
-
|
Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi HTML exports render session Markdown into a static HTML file. It did not consistently reject unsafe Markdown link and image URL s…
|
CWE-79
Cross-site Scripting
|
CVE-2026-54326
|
2026-06-26 01:14 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1470
|
7.3 |
HIGH
Local
|
-
|
-
|
Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi versions with temporary npm or git extension package installs used predictable paths under the operating system temporary directo…
|
CWE-379
Creation of Temporary File in Directory with Incorrect Permissions
|
CVE-2026-54328
|
2026-06-26 01:14 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|