Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6 CVE-2026-8658

OS Command Injection in Rapid7 InsightConnect Tcpdump Plugin_CVE-2026-8658

OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands...

Rapid7 InsightConnect Tcpdump Plugin CVE
MEDIUM 6.5 CVE-2026-2508

Gravity Forms Booking <= 2.7.1 - Authenticated (Subscriber+) Time-Based SQL Injection via 'staff_id'_CVE-2026-2508

The Gravity Forms Booking plugin for WordPress is vulnerable to time-based SQL Injection via the ‘staff_id’ parameter in all versions up to, and in...

GravityMore Gravity Bookings CVE
MEDIUM 6.5 CVE-2026-12079

Dokan Pro <= 5.0.4 - Authenticated (Subscriber+) SQL Injection via 'orderby' Parameter_CVE-2026-12079

The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ’orderby’ parameter in all versions up to, and including, 5.0....

wedevs Dokan Pro CVE
MEDIUM 6.4 CVE-2026-10833

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 6.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'configurablePrefix' Block Attribute_CVE-2026-10833

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...

wpdevteam Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns CVE
MEDIUM 6 CVE-2026-8663

OS Command Injection in Rapid7 InsightConnect RPM Plugin_CVE-2026-8663

OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via...

Rapid7 InsightConnect RPM Plugin CVE
MEDIUM 6 CVE-2026-8659

OS Command Injection in Rapid7 InsightConnect SQLmap Plugin_CVE-2026-8659

OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands ...

Rapid7 InsightConnect SQLmap Plugin CVE
MEDIUM 6.5 CVE-2026-9153

Arbitrary File Read in Rapid7 InsightConnect Sed Plugin_CVE-2026-9153

Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the expre...

Rapid7 InsightConnect Sed Plugin CVE
MEDIUM 6 CVE-2026-8664

OS Command Injection in Rapid7 InsightConnect Finger Plugin_CVE-2026-8664

OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to execute arbitrary OS commands ...

Rapid7 InsightConnect Finger Plugin CVE
MEDIUM 5.1 CVE-2026-49979

Appsmith: SSRF via `POST /api/v1/admin/send-test-email` — JavaMail Bypasses WebClient IP Filter_CVE-2026-49979

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.99, the POST /api/v1/admin/send-test-email endpoint accept...

appsmithorg appsmith < 1.99 CVE
MEDIUM 5.3 CVE-2026-39897

Cacti has a Reflected XSS Vulnerability via html_auth_footer_CVE-2026-39897

Cacti is an open source performance and fault management framework. Versions 1.2.30 and below contain a Reflected XSS vulnerability in the html_aut...

Cacti cacti < 1.2.31 CVE