Search
Search Results (6 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-66145 | 1 Sonicwall | 1 Gms | 2026-08-13 | 9.1 Critical |
| An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip. | ||||
| CVE-2026-66146 | 1 Sonicwall | 1 Gms | 2026-08-13 | 6.1 Medium |
| Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions that allow a remote attacker to execute javascript script in a user's browser. | ||||
| CVE-2026-66147 | 1 Sonicwall | 1 Gms | 2026-08-13 | 9.4 Critical |
| An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests. | ||||
| CVE-2026-66148 | 1 Sonicwall | 1 Gms | 2026-08-13 | 6.3 Medium |
| An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions which allows low-privileged local user to execute system commands with root privileges. | ||||
| CVE-2026-66154 | 1 Sonicwall | 1 Gms | 2026-08-13 | 8.3 High |
| An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlier versions which, under a successful MitM attack and controlled network conditions, could permit unauthorized changes. | ||||
| CVE-2026-18634 | 1 Sonicwall | 1 Gms | 2026-08-13 | 8.4 High |
| An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and earlier versions. A local attacker with the ability to interact with the service could exploit this behavior to perform unauthorized actions through the affected component. | ||||
Page 1 of 1.