Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-9240

The Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the updateShippingMethod() function (registered to the wp_ajax_lpc_order_affect AJAX action) in versions up to, and including, 2.9.0. This is due to the handler performing no current_user_can() capability check and no nonce verification before reading an attacker-supplied order_id and modifying that order's shipping method, p

PUBLISHED
Vendor
iscpcolissimo
Product
Colissimo shipping methods for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9237

The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete, archive, unarchive, and duplicate arbitrary job listings — along with their associated stages, meta, addresses, and applications —

PUBLISHED
Vendor
crewhrm
Product
Employee, Leave and Recruitment Management System – Crew HRM
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9236

The CM Ad Changer – A simple tool to control and optimize your site's banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.7. This is due to missing or incorrect nonce validation on the cmac_campaigns_action function. This makes it possible for unauthenticated attackers to permanently delete arbitrary advertising campaigns, including their associated banner records and uploaded files via a forged request granted they can trick a site

PUBLISHED
Vendor
creativemindssolutions
Product
CM Ad Changer – A simple tool to control and optimize your site's banners
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9235

The DHL eCommerce (Benelux) for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check and missing nonce verification on the create_label() and delete_label() functions in versions up to, and including, 2.2.3. These functions are wired to the wp_ajax_dhlpwc_label_create and wp_ajax_dhlpwc_label_delete hooks and act on an attacker-supplied post_id (WooCommerce order ID). This makes it possible for authenticated attackers, wit

PUBLISHED
Vendor
dhlparcel
Product
DHL eCommerce (Benelux) for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9234

The JTL-Connector for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.4.1. This is due to missing capability checks and nonce verification on the admin_post_settings_save_woo-jtl-connector action (handled by JtlConnectorAdmin::save()) and on the wp_ajax_downloadJTLLogs and wp_ajax_clearJTLLogs AJAX actions (handled by the global downloadJTLLogs() and clearJTLLogs() functions). This makes it possible for authenticated attackers, with Sub

PUBLISHED
Vendor
ntbyk
Product
JTL-Connector for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9233

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to create, modify, and delete quiz output templates stored in the mlw_quiz_output_templates database table, including storing unsanitized HTML

PUBLISHED
Vendor
expresstech
Product
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9230

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to modify quizzes they do not own, overwrite quiz results pages, and reroute quiz-result notification emails to attacker-controlled addresses.

PUBLISHED
Vendor
expresstech
Product
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9228

The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.16 via the action_get_event_data due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to enumerate timeslot IDs and read the full WP_Post object — including post_content, post_excerpt, post_status, and post_author — of draft, pending, and private mp

PUBLISHED
Vendor
jetmonsters
Product
Timetable and Event Schedule by MotoPress
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9227

The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.20.1 via the gutenbee_file_and_ext_json function. This is due to a flawed strpos() substring check that only verifies whether the filename contains the string '.json' rather than confirming the filename ends with a .json extension, allowing double-extension filenames like shell.json.php to bypass validation. This makes it possible for authenticated attackers, with a

PUBLISHED
Vendor
cssigniterteam
Product
GutenBee – Gutenberg Blocks
Provider severity
HIGH
Conflicts
0

CVE-2026-9224

Missing authorization in the user profile update feature in Devolutions Server allows an authenticated Active Directory user to modify their own profile attributes via a crafted API request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier

PUBLISHED
Vendor
Devolutions
Product
Server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9223

Missing authorization in the vault import feature in Devolutions Server  2026.1.16.0 and earlier allows a low-privileged authenticated user to create new vaults via a crafted import request.

PUBLISHED
Vendor
Devolutions
Product
Server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9222

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access.

PUBLISHED
Vendor
Shenzhen i365-Tech Co. Ltd.
Product
Setracker2 Parental Control App (Android) package com.tgelec.setracker
Provider severity
CRITICAL, HIGH
Conflicts
1

CVE-2026-9221

The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier uses MD5 to generate a request signature for authenticating communications between the mobile client and the backend REST API. Attackers could potentially reverse the signature to recover the session ID. With the session ID exposed, an attacker could impersonate the legitimate user and issue authenticated API requests.

PUBLISHED
Vendor
Shenzhen i365-Tech Co. Ltd.
Product
Setracker2 Parental Control App (Android) package com.tgelec.setracker
Provider severity
HIGH
Conflicts
1

CVE-2026-9220

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hardcoded AES keys and initialization vectors. This allows an attacker to decrypt Setracker2 watch traffic.

PUBLISHED
Vendor
Shenzhen i365-Tech Co. Ltd.
Product
Setracker2 Parental Control App (Android) package com.tgelec.setracker
Provider severity
HIGH
Conflicts
1

CVE-2026-9219

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional authentication before assignment. If an attacker is able to obtain the registration ID, they would be able to arbitrarily enroll watches belonging to other users.

PUBLISHED
Vendor
Shenzhen i365-Tech Co. Ltd.
Product
Setracker2 Parental Control App (Android) package com.tgelec.setracker
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-9213

A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execute code on the device.

PUBLISHED
Vendor
NETGEAR, NETGEAR, NETGEAR, NETGEAR
Product
XR1000, MS70, RAXE500, MR70
Provider severity
MEDIUM
Conflicts
1

CVE-2026-9212

Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.

PUBLISHED
Vendor
NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR
Product
RBR10, RBS20, R9000, RAX10, RAX78, RAX120, RBR350, RBS40, RAX120v2, RBS350, RAX120v1, XR450, XR500, RBS50, LBR1020, RAX36S, LBR20, RBS10, R7800, RBR50, RAX70, R6700AX, RBR20, RAX10v2, RBR40
Provider severity
MEDIUM
Conflicts
2

CVE-2026-9211

An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation.

PUBLISHED
Vendor
NETGEAR, NETGEAR, NETGEAR, NETGEAR
Product
RAX30, CAX30, RAXE300, RAX5
Provider severity
MEDIUM
Conflicts
1

CVE-2026-9210

Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.

PUBLISHED
Vendor
NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR, NETGEAR
Product
MR70, EX3700, EX6130, R7000P, R6900P, MR80, RAX35v2, RAX42, R8000P, RAXE450, EX6120, RAX48, RAX50S, RAX41, RAX43, MS60, MS80, R7000, R7960P, R6700v3, RAX45, RAXE500, RAX50, R8500, RAX40v2, RAX20, XR1000, MS70, MR60, EX3800, R6400v2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-9208

Tanium addressed an unauthorized code execution vulnerability in Connect.

PUBLISHED
Vendor
Tanium
Product
Connect
Provider severity
HIGH
Conflicts
0

CVE-2026-9207

Tanium addressed an unauthorized code execution vulnerability in Connect.

PUBLISHED
Vendor
Tanium
Product
Connect
Provider severity
HIGH
Conflicts
0

CVE-2026-9204

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to read arbitrary files from the Gitaly server and access internal network resources during repository import, due to insufficient validation of secondary URLs.

PUBLISHED
Vendor
GitLab
Product
GitLab
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9202

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deployment option), newly created accounts are immediately active and can authenticate to reach RCE endpoints, bypassing the need for AUTO_LOGIN.

PUBLISHED
Vendor
IBM
Product
Langflow OSS
Provider severity
CRITICAL
Conflicts
0

CVE-2026-9200

The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.2.1 via the shortcode function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded an

PUBLISHED
Vendor
shazdeh
Product
Query Shortcode
Provider severity
HIGH
Conflicts
0

CVE-2026-9199

The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.42.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with author-level access and above, to dismiss, ignore, or restore accessibility audit issue records belonging to posts they are not permitted to edit by suppl

PUBLISHED
Vendor
equalizedigital
Product
Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9198

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments

PUBLISHEDCISA KEV
Vendor
IBM
Product
Langflow OSS
Provider severity
CRITICAL
Conflicts
0

CVE-2026-9197

The Smart Slider 3 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.5.1.36 via the replaceHTMLImage function. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

PUBLISHED
Vendor
nextendweb
Product
Smart Slider 3
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9189

The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via Insufficient Verification of Data Authenticity in all versions up to, and including, 2.4.9. Although `cf7pp_paypal_ipn_handler()` correctly validates IPN authenticity by posting back to PayPal with `cmd=_notify-validate`, it fails to compare the IPN payload's `mc_gross` (payment amount), `mc_currency`, or `receiver_email` fields against the corresponding stored order values before passing the att

PUBLISHED
Vendor
scottpaterson
Product
Contact Form 7 – PayPal & Stripe Add-on
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9188

The Appointment Bookings for Zoom GoogleMeet and more – Wappointment plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to and including 2.7.6 via the `appointmentkey` parameter due to the appointment `edit_key` — the sole authorization token consumed by `tryCancel()` — being generated as a predictable, unsalted MD5 hash of only `client_id` (a sequential integer), `start_at` (a publicly observable appointment timestamp), and `staff_id` (a small enumerable i

PUBLISHED
Vendor
wappointment
Product
Appointment Bookings for Zoom GoogleMeet and more – Wappointment
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9187

The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion in versions up to, and including, 2.2. This is due to a missing capability check and missing nonce validation in the action__remove_abandoned() function, which is registered to both the wp_ajax_remove_abandoned and wp_ajax_nopriv_remove_abandoned hooks. The handler takes a user-supplied recover_id parameter from $_POST and passes it directly to wp_delete_post() with the force-delete flag set t

PUBLISHED
Vendor
zealopensource
Product
Abandoned Contact Form 7
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9185

The 6Storage Rentals plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 2.22.0 via the `userId` parameter of the `six_storage_get_user_info` and `six_storage_update_profile` AJAX actions. This is due to the `six_storage_getUserInfo()` and `six_storage_updateProfile()` functions being registered on `wp_ajax_nopriv_*` hooks and accepting a tenant identifier directly from `$_POST['userId']` without performing any ownership veri

PUBLISHED
Vendor
sixstorage
Product
6Storage Rentals
Provider severity
HIGH
Conflicts
0

CVE-2026-9184

The 24liveblog - live blog tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_lb24_token() AJAX function in versions up to, and including, 2.2. The handler only verifies the 'lb24' nonce (which is generated and localized to any user with block editor access via lb24_block_enqueue_scripts()) and does not verify the user's capabilities or that the supplied user_id belongs to the current user. This makes it possible for authe

PUBLISHED
Vendor
24liveblog
Product
24liveblog – live blog tool
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9183

The 24liveblog - live blog tool plugin for WordPress is vulnerable to Exposure of Sensitive Information in versions up to, and including, 2.2. This is due to the lb24_block_enqueue_scripts() function being hooked to enqueue_block_editor_assets and, for any non-administrator user, falling back to loading the administrator-configured site-wide 24liveblog integration secrets (lb24_token, lb24_refresh_token, lb24_uid, lb24_uname) from the options table via get_option() and emitting them through wp_l

PUBLISHED
Vendor
24liveblog
Product
24liveblog – live blog tool
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9182

Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload, potentially allowing for other attacks. This issue impacts all versions of ArcGIS Server on Windows and Linux 12.0 and prior. This issue does not impact ArcGIS Enterprise for Kubernetes.

PUBLISHED
Vendor
Esri
Product
ArcGIS Server
Provider severity
CRITICAL
Conflicts
0

CVE-2026-9181

Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by sending crafted path parameters. Successful exploitation could allow overwriting sensitive files on the system. Abuse of this issue can allow full administrative access to ArcGIS Server, with high impact to confidentiality, integrity, and availability. This issue impacts all versions of ArcGIS Server on Windows and Linux 12.0 an

PUBLISHED
Vendor
Esri
Product
ArcGIS Server
Provider severity
CRITICAL
Conflicts
0

CVE-2026-9180

The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.4.4. This is due to the `POST /motopress/appointment/v1/bookings` REST endpoint being registered with `'permission_callback' => '__return_true'`, allowing unauthenticated access, while the `createBooking` handler in `BookingsRestController.php` accepts an attacker-supplied `payment_details.booking_id` value and loads the referenced booki

PUBLISHED
Vendor
jetmonsters
Product
MotoPress Appointment Booking
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9179

The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/v3/post/list REST endpoint in versions up to and including 1.8. This is due to insufficient escaping on the user-supplied 'order' parameter (read directly from $_GET['order'] into $shorting) and the lack of sufficient preparation on the existing SQL query in the listPost() function, where the value is concatenated unquoted into the ORDER BY clause and executed via $wpdb->get_re

PUBLISHED
Vendor
hancock11
Product
WP Forms Connector
Provider severity
HIGH
Conflicts
0

CVE-2026-9178

The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.8. The plugin registers the REST route wp/v3/user/list/<id> (callback userDetail()) with permission_callback set to '__return_true', and the function's home-grown authentication only verifies that the supplied 'Username' HTTP header maps to an administrator account and that a 'Password' HTTP header is non-empty. It never validates the password with wp_check_password() (unlike

PUBLISHED
Vendor
hancock11
Product
WP Forms Connector
Provider severity
HIGH
Conflicts
0

CVE-2026-9177

A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway SecureTransport product in version 5.5-20260326. This flaw allows an attacker with admin privileges to inject arbitrary Java code expressions, which are executed server-side when the template is rendered (i.e., during email sending). Successful exploitation of this flaw allows an attacker to execute arbitrary code on the server that results in full host compromise. This

PUBLISHED
Vendor
Axway
Product
SecureTransport
Provider severity
CRITICAL
Conflicts
0

CVE-2026-9175

The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.0. This is due to the get_single_account() REST API callback being registered with a permission_callback that unconditionally returns true, providing no authentication or authorization checks on the /devs-accounting/v1/get-account/<id> endpoint. This makes it possible for unauthenticated attackers to read arbitrary private financial

PUBLISHED
Vendor
ajitdas
Product
Devs Accounting – Simple Accounting and Invoicing Solution
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9172

The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to unauthorized modification/deletion of data due to a missing capability check on the delete_single_account() function in versions up to, and including, 1.2.0. The REST route 'devs-accounting/v1/delete-account/(?P<id>\d+)' is registered without any permission_callback, which causes WordPress to expose the endpoint to public, unauthenticated access. This makes it possible for unauthenticated attacke

PUBLISHED
Vendor
ajitdas
Product
Devs Accounting – Simple Accounting and Invoicing Solution
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9171

IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.

PUBLISHED
Vendor
IBM
Product
PowerVM Novalink
Provider severity
HIGH
Conflicts
0

CVE-2026-9170

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improper input validation.

PUBLISHED
Vendor
IBM
Product
HTTP Server
Provider severity
CRITICAL
Conflicts
0

CVE-2026-9165

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a denial of service for the management plane.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat
Product
Red Hat Advanced Cluster Security for Kubernetes 4.11, Red Hat Advanced Cluster Security 4.9, Red Hat Advanced Cluster Security for Kubernetes 4.10
Provider severity
HIGH
Conflicts
1

CVE-2026-9162

Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to invalidate cached authentication state for active WebSocket connections during global session revocation, which allows a user with an existing WebSocket connection to remain authenticated and continue receiving real-time events until the cached session expires or the client reconnects.. Mattermost Advisory ID: MMSA-2026-00664

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9158

In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer. This allows subsequent commands to access freed memory (use-after-free).

PUBLISHED
Vendor
Eclipse Foundation
Product
Eclipse 4diac
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9157

Improper input validation, Unrestricted upload of file with dangerous type vulnerability in Gmission Web Fax allows Remote Code Inclusion. This issue affects Web Fax: from 3.0 before 3.1.

PUBLISHED
Vendor
Gmission
Product
Web Fax
Provider severity
HIGH
Conflicts
2

CVE-2026-9156

Tanium addressed a denial of service vulnerability in Tanium Server.

PUBLISHED
Vendor
Tanium
Product
Tanium Server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9155

OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the expression parameter due to insufficient input validation.

PUBLISHED
Vendor
Rapid7
Product
InsightConnect Sed Plugin
Provider severity
HIGH
Conflicts
0

CVE-2026-9154

Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content to arbitrary file paths via the expression parameter.

PUBLISHED
Vendor
Rapid7
Product
InsightConnect Sed Plugin
Provider severity
HIGH
Conflicts
0