Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 CVE-2026-9153

Arbitrary File Read in Rapid7 InsightConnect Sed Plugin_CVE-2026-9153

Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the expre...

Rapid7 InsightConnect Sed Plugin CVE
HIGH 7.4 CVE-2026-57589

CVE-2026-57589_CVE-2026-57589

sys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root. This is a context switch use-after-fre...

OpenBSD OpenBSD CVE
HIGH 7.7 CVE-2026-8666

OS Command Injection in Rapid7 InsightConnect Traceroute Plugin_CVE-2026-8666

OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute ...

Rapid7 InsightConnect Traceroute Plugin CVE
HIGH 7.7 CVE-2026-8665

OS Command Injection in Rapid7 InsightConnect Translate Plugin_CVE-2026-8665

OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary...

Rapid7 InsightConnect TR Plugin CVE
MEDIUM 6 CVE-2026-8664

OS Command Injection in Rapid7 InsightConnect Finger Plugin_CVE-2026-8664

OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to execute arbitrary OS commands ...

Rapid7 InsightConnect Finger Plugin CVE
HIGH 7.7 CVE-2026-8660

OS Command Injection in Rapid7 InsightConnect Ping Plugin_CVE-2026-8660

OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS...

Rapid7 InsightConnect Ping Plugin CVE
HIGH 7.7 CVE-2026-8592

OS Command Injection in Rapid7 InsightConnect AWK Plugin_CVE-2026-8592

OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arb...

Rapid7 InsightConnect AWK Plugin CVE
MEDIUM 5.1 CVE-2026-49979

Appsmith: SSRF via `POST /api/v1/admin/send-test-email` — JavaMail Bypasses WebClient IP Filter_CVE-2026-49979

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.99, the POST /api/v1/admin/send-test-email endpoint accept...

appsmithorg appsmith < 1.99 CVE
MEDIUM 5.3 CVE-2026-39897

Cacti has a Reflected XSS Vulnerability via html_auth_footer_CVE-2026-39897

Cacti is an open source performance and fault management framework. Versions 1.2.30 and below contain a Reflected XSS vulnerability in the html_aut...

Cacti cacti < 1.2.31 CVE
LOW 2.9 CVE-2026-39894

Cacti: RRDtool metric shift via LC_NUMERIC locale comma decimal formatting_CVE-2026-39894

Cacti is an open source performance and fault management framework. In versions 1.2.30 and below, the locale-dependent decimal formatting in rrdtoo...

Cacti cacti < 1.2.31 CVE