Financial Security Institute (FSI)

First CVE: Apr 7, 2025Active for: 1 year
13
CVEs Published
More CVEs Published than 31% of tracked CNAs
6.5
Avg CVEs / Year
More Avg CVEs / Year than 40% of tracked CNAs
7.8
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Financial Security Institute (FSI) as a CNA, 0.0% affect products that Financial Security Institute (FSI) develops as a vendor.

100.0%
Self-reported: 0Third-party: 13

Of all the CVEs published that affect products developed by Financial Security Institute (FSI), 0.0% are self-published by Financial Security Institute (FSI) as a CNA.

100.0%
Self-published: 0Published by other CNAs: 4

Trends Over Time

The number and severity of CVEs published by Financial Security Institute (FSI) over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 7, 2025
15 months ago
Most Recent CVE
May 21, 2026
64 days ago

Top CVEs

All CVEs published by Financial Security Institute (FSI) as a CNA, regardless of affected vendor or product.

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Improper input validation, Unrestricted upload of file with dangerous type vulnerability in Gmission Web Fax allows Remote Code Inclusion. This issue affects Web Fax: from 3.0 bef
May 21, 20268.435NONO
Improper Authentication vulnerability in Gmission Web Fax allows Privilege Escalation.This issue affects Web Fax: from 3.0 before 3.0.1
Dec 29, 20259.829NONO
Missing Authorization vulnerability in Gmission Web Fax allows Authentication Abuse, Session Credential Falsification through Manipulation.This issue affects Web Fax: from 3.0 befo
Dec 29, 20259.829NONO
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted Upload of File with Dangerous Type vulnerability in GTONE ChangeFlow allows Path Traver
Oct 2, 20258.829NONO
An attacker can obtain server information using Path Traversal vulnerability to conduct SQL Injection, which possibly exploits Unrestricted Upload of File with Dangerous Type vulne
Oct 2, 20258.828NONO
Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems.  * vulnerabilities: * Improper Neutraliza
Jul 15, 20259.628NONO
Unrestricted Upload of File with Dangerous Type vulnerability in Innorix Innorix WP allows Upload a Web Shell to a Web Server.This issue affects Innorix WP from All versions If the
Dec 29, 20257.725NONO
Permissive Cross-domain Policy with Untrusted Domains vulnerability in local API server of DestinyECM solution(versions described below) which is developed and maintained by Cyberd
Apr 7, 20258.824NONO
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Download of Code Without Integrity Check vulnerability in GTONE ChangeFlow allows Path Traversal.Thi
Oct 2, 20256.523NONO
Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization vulnerability in Gmission Web Fax allows Authentication Abuse. This issue affects Web Fax: from 3
Dec 29, 20256.522NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA13 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local4 (30.8%)
Network5 (38.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network4 (30.8%)
Attack Complexity
Low12 (92.3%)
High1 (7.7%)
Unknown0 (0.0%)
User Interaction
None11 (84.6%)
Unknown0 (0.0%)
Required2 (15.4%)
Privileges Required
Low2 (15.4%)
High0 (0.0%)
None11 (84.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Financial Security Institute (FSI) as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Financial Security Institute (FSI) as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs