Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 CVE-2026-12079

Dokan Pro <= 5.0.4 - Authenticated (Subscriber+) SQL Injection via 'orderby' Parameter_CVE-2026-12079

The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ’orderby’ parameter in all versions up to, and including, 5.0....

wedevs Dokan Pro CVE
HIGH 7.5 CVE-2026-12077

Dokan Pro <= 5.0.4 - Unauthenticated SQL Injection via 'latitude' and 'longitude' Parameters_CVE-2026-12077

The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the via 'latitude' and 'longitude' parameters in all versions up t...

wedevs Dokan Pro CVE
MEDIUM 6.4 CVE-2026-10833

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 6.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'configurablePrefix' Block Attribute_CVE-2026-10833

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...

wpdevteam Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns CVE
MEDIUM 6 CVE-2026-8663

OS Command Injection in Rapid7 InsightConnect RPM Plugin_CVE-2026-8663

OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via...

Rapid7 InsightConnect RPM Plugin CVE
MEDIUM 6 CVE-2026-8659

OS Command Injection in Rapid7 InsightConnect SQLmap Plugin_CVE-2026-8659

OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands ...

Rapid7 InsightConnect SQLmap Plugin CVE
HIGH 8.8 CVE-2026-9155

OS Command Injection in Rapid7 InsightConnect Sed Plugin via expression parameter._CVE-2026-9155

OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via...

Rapid7 InsightConnect Sed Plugin CVE
HIGH 7.1 CVE-2026-9154

Arbitrary File Write in Rapid7 InsightConnect Sed Plugin_CVE-2026-9154

Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content...

Rapid7 InsightConnect Sed Plugin CVE
MEDIUM 6.5 CVE-2026-9153

Arbitrary File Read in Rapid7 InsightConnect Sed Plugin_CVE-2026-9153

Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the expre...

Rapid7 InsightConnect Sed Plugin CVE
HIGH 7.4 CVE-2026-57589

CVE-2026-57589_CVE-2026-57589

sys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root. This is a context switch use-after-fre...

OpenBSD OpenBSD CVE
HIGH 7.7 CVE-2026-8666

OS Command Injection in Rapid7 InsightConnect Traceroute Plugin_CVE-2026-8666

OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute ...

Rapid7 InsightConnect Traceroute Plugin CVE