Financial Security Institute (FSI)
Self-Reporting Analysis
Of all the CVEs published by Financial Security Institute (FSI) as a CNA, 0.0% affect products that Financial Security Institute (FSI) develops as a vendor.
Of all the CVEs published that affect products developed by Financial Security Institute (FSI), 0.0% are self-published by Financial Security Institute (FSI) as a CNA.
Trends Over Time
The number and severity of CVEs published by Financial Security Institute (FSI) over time
Top CVEs
All CVEs published by Financial Security Institute (FSI) as a CNA, regardless of affected vendor or product.
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-9157HIGH Improper input validation, Unrestricted upload of file with dangerous type vulnerability in Gmission Web Fax allows Remote Code Inclusion.
This issue affects Web Fax: from 3.0 bef | May 21, 2026 | 8.4 | 35 | NO | NO |
CVE-2025-15069CRITICAL Improper Authentication vulnerability in Gmission Web Fax allows Privilege Escalation.This issue affects Web Fax: from 3.0 before 3.0.1 | Dec 29, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-15068CRITICAL Missing Authorization vulnerability in Gmission Web Fax allows Authentication Abuse, Session Credential Falsification through Manipulation.This issue affects Web Fax: from 3.0 befo | Dec 29, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-11221HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted Upload of File with Dangerous Type vulnerability in GTONE ChangeFlow allows Path Traver | Oct 2, 2025 | 8.8 | 29 | NO | NO |
CVE-2025-11020HIGH An attacker can obtain server information using Path Traversal vulnerability to conduct SQL Injection, which possibly exploits Unrestricted Upload of File with Dangerous Type vulne | Oct 2, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-3621CRITICAL Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems.
* vulnerabilities:
*
Improper Neutraliza | Jul 15, 2025 | 9.6 | 28 | NO | NO |
CVE-2025-15067HIGH Unrestricted Upload of File with Dangerous Type vulnerability in Innorix Innorix WP allows Upload a Web Shell to a Web Server.This issue affects Innorix WP from All versions If the | Dec 29, 2025 | 7.7 | 25 | NO | NO |
CVE-2024-11071HIGH Permissive Cross-domain Policy with Untrusted Domains vulnerability in local API server of DestinyECM solution(versions described below) which is developed and maintained by Cyberd | Apr 7, 2025 | 8.8 | 24 | NO | NO |
CVE-2025-11182MEDIUM Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Download of Code Without Integrity Check vulnerability in GTONE ChangeFlow allows Path Traversal.Thi | Oct 2, 2025 | 6.5 | 23 | NO | NO |
CVE-2025-15070MEDIUM Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization vulnerability in Gmission Web Fax allows Authentication Abuse.
This issue affects Web Fax: from 3 | Dec 29, 2025 | 6.5 | 22 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (13 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Financial Security Institute (FSI) as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Financial Security Institute (FSI) as a CNA — matched by CVE ID, not by organization name.