<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Arbitrary File Read (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/arb-read.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/arb-read-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Arbitrary File Read (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:33 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-0611 – Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0611</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0611</guid>
    <pubDate>Tue, 02 Jun 2026 17:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-0611</strong></p>
  <p>Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability through a deprecated .NET Remoting HTTP channel exposed on port 8989 that allows attackers to perform arbitrary file read and write operations by supplying valid .NET URI endpoints. Attackers can write ASPX webshells to the IIS wwwroot directory to achie…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0611">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49136 – Banana Slides through 0.4.0, patched in commit e8bc490, contains a path traversa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49136</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49136</guid>
    <pubDate>Mon, 01 Jun 2026 21:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49136</strong></p>
  <p>Banana Slides through 0.4.0, patched in commit e8bc490, contains a path traversal vulnerability in the generate_image() function within the AI service backend that allows unauthenticated attackers to read arbitrary image-format files outside the intended uploads directory by exploiting an incomplete path prefix check using os.path.startswith() without a trailing separator. Attackers can supply cr…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49136">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10073 – DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10073</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10073</guid>
    <pubDate>Fri, 29 May 2026 14:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10073</strong></p>
  <p>DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing unauthenticated local attackers to exploit Relative Path Traversal to download arbitrary system files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10073">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10044 – Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10044</guid>
    <pubDate>Thu, 28 May 2026 22:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10044</strong></p>
  <p>Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vulnerability in the GET /api/prompts/{filename} endpoint on Windows deployments that allows unauthenticated remote attackers to read arbitrary files by supplying absolute Windows paths or backslash-based traversal sequences. Attackers can bypass the incomplete path traversal guard, which only blocks forward slashes and…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48126 – Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when alg...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48126</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48126</guid>
    <pubDate>Tue, 26 May 2026 17:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48126</strong></p>
  <p>Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when algernon is started with --domain (or --letsencrypt, which silently turns on --domain at engine/flags.go:372), the request handler resolves the served directory by joining the configured --dir with the value of the client-supplied Host header. The join is performed by filepath.Join with no validation, so a Host: .. heade…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48126">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39352 – Frappe is a full-stack web application framework. Versions prior to 15.105.0 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39352</guid>
    <pubDate>Wed, 20 May 2026 20:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39352</strong></p>
  <p>Frappe is a full-stack web application framework. Versions prior to 15.105.0 and 16.15.0 contain a possible Arbitrary File Read vulnerability via Path Traversal. The issue is resolved in versions 16.15.0, 15.105.0 and above.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22599 – Strapi is an open source headless content management system. In versions on the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22599</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22599</guid>
    <pubDate>Thu, 14 May 2026 19:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22599</strong></p>
  <p>Strapi is an open source headless content management system. In versions on the 4.x branch prior to 4.26.1 and on the 5.x branch prior to 5.33.2, a database-query injection vulnerability existed in the Strapi Content-Type Builder write API. An authenticated administrator could inject arbitrary database statements through the `column.defaultTo` attribute when creating or modifying a content type.…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22599">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4030 – The Database Backup for WordPress plugin for WordPress is vulnerable to unauthor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4030</guid>
    <pubDate>Thu, 14 May 2026 13:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4030</strong></p>
  <p>The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check combined with a user-controlled backup directory parameter. This makes it possible for unauthenticated attackers to read and delete arbitrary f…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6514 – The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6514</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6514</guid>
    <pubDate>Thu, 14 May 2026 09:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6514</strong></p>
  <p>The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.1.2 via the popup_submit. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6514">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29205 – Incorrect privileges management and insufficient path filtering allow to read ar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29205</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29205</guid>
    <pubDate>Wed, 13 May 2026 22:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29205</strong></p>
  <p>Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29205">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29201 – Insufficient input validation of the feature file name in `feature::LOADFEATUREF...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29201</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29201</guid>
    <pubDate>Fri, 08 May 2026 19:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29201</strong></p>
  <p>Insufficient input validation of the feature file name in `feature::LOADFEATUREFILE` adminbin call can cause arbitrary file read when a relative file path is passed.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29201">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43533 – OpenClaw before 2026.4.10 contains an arbitrary file read vulnerability in QQBot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43533</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43533</guid>
    <pubDate>Tue, 05 May 2026 12:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43533</strong></p>
  <p>OpenClaw before 2026.4.10 contains an arbitrary file read vulnerability in QQBot media tags that allows attackers to reference host-local paths outside the intended media storage boundary. Attackers can craft malicious reply text containing media tags to disclose arbitrary local files through outbound media handling.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43533">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6320 – The Salon Booking System – Free Version plugin for WordPress is vulnerable to Ar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6320</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6320</guid>
    <pubDate>Sat, 02 May 2026 12:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6320</strong></p>
  <p>The Salon Booking System – Free Version plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 10.30.25. This is due to the public booking flow accepting attacker-controlled file-field values and later using those stored values as trusted paths for email attachments. This makes it possible for unauthenticated attackers to read arbitrary local files and exfiltr…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6320">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-50992 – Weaver (Fanwei) E-cology 9.5 versions prior to 10.52 contain an arbitrary file r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-50992</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-50992</guid>
    <pubDate>Thu, 30 Apr 2026 17:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-50992</strong></p>
  <p>Weaver (Fanwei) E-cology 9.5 versions prior to 10.52 contain an arbitrary file read vulnerability in the XmlRpcServlet interface at the XML-RPC endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying file paths to the WorkflowService.getAttachment and WorkflowService.LoadTemplateProp methods. Attackers can exploit these methods without authentication to retrieve…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-50992">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33077 – Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33077</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33077</guid>
    <pubDate>Fri, 24 Apr 2026 03:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33077</strong></p>
  <p>Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the oldconfig parameter in the haproxy_section_save interface has an arbitrary file read vulnerability. Version 8.2.6.4 fixes the issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33077">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34413 – Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34413</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34413</guid>
    <pubDate>Wed, 22 Apr 2026 19:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34413</strong></p>
  <p>Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.php where an HTTP redirect to unauthenticated callers does not call exit() or die(), allowing PHP execution to continue and process the full request server-side. Unauthenticated attackers can perform file operations on project media di…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-497</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34413">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5478 – The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5478</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5478</guid>
    <pubDate>Mon, 20 Apr 2026 20:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5478</strong></p>
  <p>The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and including, 3.4.4. This is due to the plugin trusting attacker-controlled old_files data from public form submissions as legitimate server-side upload state, and converting attacker-supplied URLs into local filesystem paths using regex-based string replacement without canonicalizatio…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5478">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5710 – The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5710</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5710</guid>
    <pubDate>Fri, 17 Apr 2026 18:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5710</strong></p>
  <p>The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary File Read in versions up to and including 1.3.9.6. This is due to the plugin using client-supplied mfile[] POST values as the source of truth for email attachment selection without performing any server-side upload provenance check, path canonicalization, or director…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5710">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3464 – The WP Customer Area plugin for WordPress is vulnerable to arbitrary file read a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3464</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3464</guid>
    <pubDate>Fri, 17 Apr 2026 17:17:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3464</strong></p>
  <p>The WP Customer Area plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation in the 'ajax_attach_file' function in all versions up to, and including, 8.3.4. This makes it possible for authenticated attackers with a role that an administrator grants access to (e.g., Subscriber) to to read the contents of arbitrary files on the server, which c…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3464">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4659 – The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4659</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4659</guid>
    <pubDate>Fri, 17 Apr 2026 07:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4659</strong></p>
  <p>The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV URL parameter in versions up to, and including, 2.0.6. This is due to insufficient path traversal sanitization in the URLtoRelative() and urlToPath() functions, combined with the ability to enable debug output in widget settings. The URLtoRelative() function only performs a sim…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4659">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-39842 – OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39842</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39842</guid>
    <pubDate>Wed, 15 Apr 2026 04:17:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-39842</strong></p>
  <p>OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulnerabilities in the rules engine that allow arbitrary code execution on the server. The JavaScript rules engine executes user-supplied scripts via Nashorn's ScriptEngine.eval() without sandboxing, class filtering, or access restrictions, and the authorization check in RulesResourc…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39842">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-35033 – Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35033</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35033</guid>
    <pubDate>Tue, 14 Apr 2026 23:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-35033</strong></p>
  <p>Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpeg argument injection through the StreamOptions query parameter parsing mechanism. The ParseStreamOptions method in StreamingHelpers.cs adds any lowercase query parameter to a dictionary without validation, bypassing the RegularExpression attribute on…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35033">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-35031 – Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35031</guid>
    <pubDate>Tue, 14 Apr 2026 23:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-35031</strong></p>
  <p>Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /Videos/{itemId}/Subtitles), where the Format field is not validated, allowing path traversal via the file extension and enabling arbitrary file write. This arbitrary file write can be chained into arbitrary file read via .strm files, database extracti…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35031">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23780 – An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL inject...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23780</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23780</guid>
    <pubDate>Fri, 10 Apr 2026 15:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23780</strong></p>
  <p>An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug interface allows an authenticated attacker to inject malicious queries due to improper input validation and unsafe dynamic SQL handling. Successful exploitation can enable arbitrary file read/write operations and potentially lead to remote code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23780">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34070 – LangChain is a framework for building agents and LLM-powered applications. Prior...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34070</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34070</guid>
    <pubDate>Tue, 31 Mar 2026 03:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34070</strong></p>
  <p>LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without validating against directory traversal or absolute path injection. When an application passes user-influenced prompt configurations to load_prompt() or load_prompt_from_config(),…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34070">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33725 – Metabase is an open source business intelligence and embedded analytics tool. In...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33725</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33725</guid>
    <pubDate>Fri, 27 Mar 2026 01:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33725</strong></p>
  <p>Metabase is an open source business intelligence and embedded analytics tool. In Metabase Enterprise prior to versions 1.54.22, 1.55.22, 1.56.22, 1.57.16, 1.58.10, and 1.59.4, authenticated admins on Metabase Enterprise Edition can achieve Remote Code Execution (RCE) and Arbitrary File Read via the `POST /api/ee/serialization/import` endpoint. A crafted serialization archive injects an `INIT` pro…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33725">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4373 – The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4373</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4373</guid>
    <pubDate>Sat, 21 Mar 2026 07:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4373</strong></p>
  <p>The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 3.5.6.2. This is due to the 'Uploaded_File::set_from_array' method accepting user-supplied file paths from the Media Field preset JSON payload without validating that the path belongs to the WordPress uploads directory. Combined with an insufficient same-file check…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4373">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33166 – Allure 2 is the version 2.x branch of Allure Report, a multi-language test repor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33166</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33166</guid>
    <pubDate>Fri, 20 Mar 2026 22:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33166</strong></p>
  <p>Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. The Allure report generator prior to version 2.38.0 is vulnerable to an arbitrary file read via path traversal when processing test results. An attacker can craft a malicious result file (-result.json, -container.json, or .plist) that points an attachment source to a sensitive file on the host system. Durin…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33166">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32711 – pydicom is a pure Python package for working with DICOM files. Versions 2.0.0-rc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32711</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32711</guid>
    <pubDate>Fri, 20 Mar 2026 02:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32711</strong></p>
  <p>pydicom is a pure Python package for working with DICOM files. Versions 2.0.0-rc.1 through 3.0.1 are vulnerable to Path Traversal through a maliciously crafted DICOMDIR ReferencedFileID when it is set to a path outside the File-set root. pydicom resolves the path only to confirm that it exists, but does not verify that the resolved path remains under the File-set root. Subsequent public FileSet o…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32711">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33301 – OpenEMR is a free and open source electronic health records and medical practice...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33301</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33301</guid>
    <pubDate>Thu, 19 Mar 2026 21:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33301</strong></p>
  <p>OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2,  users with the `Notes - my encounters` role can fill Eye Exam forms in patient encounters. The answers to the form can be printed out in PDF form. An arbitrary file read vulnerability was identified in the PDF creation function where the form answers are parsed as unescaped…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33301">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30403 – There is an arbitrary file read vulnerability in the test connection function of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30403</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30403</guid>
    <pubDate>Thu, 19 Mar 2026 17:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30403</strong></p>
  <p>There is an arbitrary file read vulnerability in the test connection function of backend database management in wgcloud v3.6.3 and before, which can be used to read any file on the victim's server.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30403">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25472 – IntelBras Telefone IP TIP200 and 200 LITE contain an unauthenticated arbitrary f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25472</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25472</guid>
    <pubDate>Wed, 11 Mar 2026 19:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25472</strong></p>
  <p>IntelBras Telefone IP TIP200 and 200 LITE contain an unauthenticated arbitrary file read vulnerability in the dumpConfigFile function accessible via the cgiServer.exx endpoint. Attackers can send GET requests to /cgi-bin/cgiServer.exx with the command parameter containing dumpConfigFile() to read sensitive files including /etc/shadow and configuration files without proper authorization.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25472">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28807 – Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28807</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28807</guid>
    <pubDate>Tue, 10 Mar 2026 22:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28807</strong></p>
  <p>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in gleam-wisp wisp allows arbitrary file read via percent-encoded path traversal.  The wisp.serve_static function is vulnerable to path traversal because sanitization runs before percent-decoding. The encoded sequence %2e%2e passes through string.replace unchanged, then uri.percent_decode converts it to .…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28807">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0846 – A vulnerability in the `filestring()` function of the `nltk.util` module in nltk...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0846</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0846</guid>
    <pubDate>Mon, 09 Mar 2026 20:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0846</strong></p>
  <p>A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without sanitization, enabling attackers to access sensitive system files by providing absolute paths or traversal paths. This vulnerability can be exploited locally or remotel…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0846">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29064 – Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29064</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29064</guid>
    <pubDate>Fri, 06 Mar 2026 17:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29064</strong></p>
  <p>Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal vulnerability in archive extraction allows a specifically crafted Zarf package to create symlinks pointing outside the destination directory, enabling arbitrary file read or write on the system processing the package. This issue has been patched in version 0.73.1.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29064">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28463 – OpenClaw versions prior to 2026.2.14 contain an arbitrary file read vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28463</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28463</guid>
    <pubDate>Thu, 05 Mar 2026 22:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28463</strong></p>
  <p>OpenClaw versions prior to 2026.2.14 contain an arbitrary file read vulnerability in the exec-approvals allowlist validation that checks pre-expansion argv tokens but executes using real shell expansion. Attackers with authorization or through prompt-injection attacks can exploit safe binaries like head, tail, or grep with glob patterns or environment variables to disclose files readable by the g…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28463">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-45691 – An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-45691</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-45691</guid>
    <pubDate>Thu, 05 Mar 2026 19:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-45691</strong></p>
  <p>An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in Exploding Gradients RAGAS v0.2.3 to v0.2.14. The vulnerability stems from improper validation and sanitization of URLs supplied in the retrieved_contexts parameter when handling multimodal inputs.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-45691">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0847 – A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0847</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0847</guid>
    <pubDate>Wed, 04 Mar 2026 19:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0847</strong></p>
  <p>A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCorpusReader, TaggedCorpusReader, and BracketParseCorpusReader. These classes fail to properly sanitize or validate file paths, enabling attackers to traverse directories and access sensitive files on the server. This issue is particularly cr…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0847">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26960 – node-tar is a full-featured Tar for Node.js. When using default options in versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26960</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26960</guid>
    <pubDate>Fri, 20 Feb 2026 02:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26960</strong></p>
  <p>node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outside the extraction root, enabling arbitrary file read and write as the extracting user. Severity is high because the primitive bypasses path protections and turns archive extraction into…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26960">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26202 – Penpot is an open-source design tool for design and code collaboration. Prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26202</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26202</guid>
    <pubDate>Thu, 19 Feb 2026 20:25:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26202</strong></p>
  <p>Penpot is an open-source design tool for design and code collaboration. Prior to version 2.13.2, an authenticated user can read arbitrary files from the server by supplying a local file path (e.g. `/etc/passwd`) as a font data chunk in the `create-font-variant` RPC endpoint, resulting in the file contents being stored and retrievable as a "font" asset. This is an arbitrary file read vulnerability…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26202">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26337 – Hyland Alfresco Transformation Service allows unauthenticated attackers to achie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26337</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26337</guid>
    <pubDate>Thu, 19 Feb 2026 18:24:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26337</strong></p>
  <p>Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve both arbitrary file read and server-side request forgery through the absolute path traversal.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26337">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2274 – A SSRF and Arbitrary File Read vulnerability in AppSheet Core in Google AppSheet...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2274</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2274</guid>
    <pubDate>Thu, 19 Feb 2026 16:27:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2274</strong></p>
  <p>A SSRF and Arbitrary File Read vulnerability in AppSheet Core in Google AppSheet prior to 2025-11-23 allows an authenticated remote attacker to read sensitive local files and access internal network resources via crafted requests to the production cluster.      This vulnerability was patched and no customer action is needed.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2274">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13603 – The WP AUDIO GALLERY plugin for WordPress is vulnerable to Unauthorized Arbitrar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13603</guid>
    <pubDate>Thu, 19 Feb 2026 07:17:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13603</strong></p>
  <p>The WP AUDIO GALLERY plugin for WordPress is vulnerable to Unauthorized Arbitrary File Read in all versions up to, and including, 2.0. This is due to insufficient capability checks and lack of nonce verification on the "wpag_htaccess_callback" function This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the site's .htaccess file with arbitrary…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-26333 – Calero VeraSMART versions prior to 2022 R1 expose an unauthenticated .NET Remoti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26333</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26333</guid>
    <pubDate>Fri, 13 Feb 2026 21:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-26333</strong></p>
  <p>Calero VeraSMART versions prior to 2022 R1 expose an unauthenticated .NET Remoting HTTP service on TCP port 8001. The service publishes default ObjectURIs (including EndeavorServer.rem and RemoteFileReceiver.rem) and permits the use of SOAP and binary formatters with TypeFilterLevel set to Full. An unauthenticated remote attacker can invoke the exposed remoting endpoints to perform arbitrary file…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26333">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-26221 – Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase W...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26221</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26221</guid>
    <pubDate>Fri, 13 Feb 2026 16:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-26221</strong></p>
  <p>Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service (Hyland.Core.Workflow.NTService.exe). An attacker who can reach the service can send crafted .NET Remoting requests to default HTTP channel endpoints on TCP/8900 (e.g., TimerServiceAPI.rem and TimerServiceEvents.rem for Workflow) to trigger unsafe object unmarshalling, enabling arbitrary file rea…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26221">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-15577 – An unauthenticated attacker can exploit this vulnerability by manipulating URL t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15577</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15577</guid>
    <pubDate>Thu, 12 Feb 2026 07:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-15577</strong></p>
  <p>An unauthenticated attacker can exploit this vulnerability by manipulating URL to achieve arbitrary file read access.This issue affects Valmet DNA Web Tools: C2022 and older.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15577">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1669 – Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1669</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1669</guid>
    <pubDate>Wed, 11 Feb 2026 23:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1669</strong></p>
  <p>Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensitive information via a crafted .keras model file utilizing HDF5 external dataset references.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1669">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23954 – Incus is a system container and virtual machine manager. Versions 6.21.0 and bel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23954</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23954</guid>
    <pubDate>Thu, 22 Jan 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23954</strong></p>
  <p>Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) to use directory traversal or symbolic links in the templating functionality to achieve host arbitrary file read, and host arbitrary file write. This ultimately results in arbitrary command execution on the h…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23954">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-7335 – EduSoho versions prior to 22.4.7 contain an arbitrary file read vulnerability in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-7335</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-7335</guid>
    <pubDate>Thu, 22 Jan 2026 17:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-7335</strong></p>
  <p>EduSoho versions prior to 22.4.7 contain an arbitrary file read vulnerability in the classroom-course-statistics export functionality. A remote, unauthenticated attacker can supply crafted path traversal sequences in the fileNames[] parameter to read arbitrary files from the server filesystem, including application configuration files such as config/parameters.yml that may contain secrets and dat…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-7335">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1330 – MeetingHub developed by HAMASTAR Technology has an Arbitrary File Read vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1330</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1330</guid>
    <pubDate>Thu, 22 Jan 2026 09:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1330</strong></p>
  <p>MeetingHub developed by HAMASTAR Technology has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1330">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-55130 – A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-rea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55130</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55130</guid>
    <pubDate>Tue, 20 Jan 2026 21:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-55130</strong></p>
  <p>A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-289</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55130">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-53912 – An arbitrary file read vulnerability exists in the encapsulatedDoc functionality...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53912</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53912</guid>
    <pubDate>Tue, 20 Jan 2026 15:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-53912</strong></p>
  <p>An arbitrary file read vulnerability exists in the encapsulatedDoc functionality of MedDream PACS Premium 7.3.6.870. A specially crafted HTTP request can lead to an arbitrary file read. An attacker can send http request to trigger this vulnerability.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53912">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23850 – SiYuan is a personal knowledge management system. In versions prior to 3.5.4, th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23850</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23850</guid>
    <pubDate>Mon, 19 Jan 2026 20:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23850</strong></p>
  <p>SiYuan is a personal knowledge management system. In versions prior to 3.5.4, the markdown feature allows unrestricted server side html-rendering which allows arbitrary file read (LFD). Version 3.5.4 fixes the issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23850">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23529 – Kafka Connect BigQuery Connector is an implementation of a sink connector from A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23529</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23529</guid>
    <pubDate>Fri, 16 Jan 2026 17:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23529</strong></p>
  <p>Kafka Connect BigQuery Connector is an implementation of a sink connector from Apache Kafka to Google BigQuery. Prior to 2.11.0, there is an arbitrary file read in Google BigQuery Sink connector. Aiven's Google BigQuery Kafka Connect Sink connector requires Google Cloud credential configurations for authentication to BigQuery services. During connector configuration, users can supply credential J…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23529">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1022 – Statistics Database System developed by Gotac has an Arbitrary File Read vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1022</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1022</guid>
    <pubDate>Fri, 16 Jan 2026 04:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1022</strong></p>
  <p>Statistics Database System developed by Gotac has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1022">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1018 – Police Statistics Database System developed by Gotac has an Arbitrary File Read ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1018</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1018</guid>
    <pubDate>Fri, 16 Jan 2026 03:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1018</strong></p>
  <p>Police Statistics Database System developed by Gotac has an Arbitrary File Read vulnerability, allowing Unauthenticated remote attacker to exploit Absolute Path Traversal to download arbitrary system files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1018">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22200 – Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22200</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22200</guid>
    <pubDate>Mon, 12 Jan 2026 19:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22200</strong></p>
  <p>Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export functionality. A remote attacker can submit a ticket containing crafted rich-text HTML that includes PHP filter expressions which are insufficiently sanitized before being processed by the mPDF PDF generator during export. When the attacker exports…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22200">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-15227 – BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Read vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15227</guid>
    <pubDate>Mon, 29 Dec 2025 08:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-15227</strong></p>
  <p>BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-15225 – WMPro developed by Sunnet has an Arbitrary File Read vulnerability, allowing una...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15225</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15225</guid>
    <pubDate>Mon, 29 Dec 2025 07:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-15225</strong></p>
  <p>WMPro developed by Sunnet has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to read arbitrary system files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15225">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-14388 – The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14388</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14388</guid>
    <pubDate>Tue, 23 Dec 2025 10:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-14388</strong></p>
  <p>The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read via null byte injection in all versions up to, and including, 3.7. This is due to a discrepancy between the extension validation in `getExtensionForURL()` which operates on URL-decoded paths, and `appendNormalized()` which strips everything after a null byte before constructing the filesystem path. This makes…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-158</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14388">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68476 – KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to versions...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68476</guid>
    <pubDate>Mon, 22 Dec 2025 22:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68476</strong></p>
  <p>KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to versions 2.17.3 and 2.18.3, an Arbitrary File Read vulnerability has been identified in KEDA, potentially affecting any KEDA resource that uses TriggerAuthentication to configure HashiCorp Vault authentication. The vulnerability stems from an incorrect or insufficient path validation when loading the Service Account Token spe…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-15015 – Enterprise Cloud Database developed by Ragic has a Arbitrary File Read vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15015</guid>
    <pubDate>Mon, 22 Dec 2025 04:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-15015</strong></p>
  <p>Enterprise Cloud Database developed by Ragic has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68155 – @vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68155</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68155</guid>
    <pubDate>Tue, 16 Dec 2025 19:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68155</strong></p>
  <p>@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_findSourceMapURL` endpoint in `@vitejs/plugin-rsc` allows unauthenticated arbitrary file read during development mode. An attacker can read any file accessible to the Node.js process by sending a crafted HTTP request with a `file://` URL in the `filename` query parameter. Version 0.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68155">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-65878 – The warehouse management system version 1.2 contains an arbitrary file read vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65878</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65878</guid>
    <pubDate>Fri, 05 Dec 2025 17:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-65878</strong></p>
  <p>The warehouse management system version 1.2 contains an arbitrary file read vulnerability. The endpoint `/file/showImageByPath` does not sanitize user-controlled path parameters. An attacker could exploit directory traversal to read arbitrary files on the server's file system. This could lead to the leakage of sensitive system information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65878">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-66263 – Unauthenticated Arbitrary File Read via Null Byte Injection in DB Electronica Te...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66263</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66263</guid>
    <pubDate>Wed, 26 Nov 2025 01:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-66263</strong></p>
  <p>Unauthenticated Arbitrary File Read via Null Byte Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Null byte injection in download_setting.php allows reading arbitrary files. The `/var/tdf/download_setting.php` endpoint constructs file paths by concatenating user-controlled `…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-158</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66263">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-34350 – UnForm Server versions &lt; 10.1.15 contain an unauthenticated arbitrary file read ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34350</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34350</guid>
    <pubDate>Tue, 25 Nov 2025 19:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-34350</strong></p>
  <p>UnForm Server versions < 10.1.15 contain an unauthenticated arbitrary file read and SMB coercion vulnerability in the Doc Flow feature’s 'arc' endpoint. The Doc Flow module uses the 'arc' handler to retrieve and render pages or resources specified by the user-supplied 'pp' parameter, but it does so without enforcing authentication or restricting path inputs. As a result, an unauthenticated remote…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34350">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13161 – IQ-Support developed by IQ Service International has an Arbitrary File Read vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13161</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13161</guid>
    <pubDate>Fri, 14 Nov 2025 04:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13161</strong></p>
  <p>IQ-Support developed by IQ Service International has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13161">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-55108 – The Control-M/Agent is vulnerable to unauthenticated remote code execution, arbi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55108</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55108</guid>
    <pubDate>Wed, 05 Nov 2025 09:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-55108</strong></p>
  <p>The Control-M/Agent is vulnerable to unauthenticated remote code execution, arbitrary file read and write and similar unauthorized actions when mutual SSL/TLS authentication is not enabled (i.e. in the default configuration).   NOTE:     *  The vendor believes that this vulnerability only occurs when documented security best practices are not followed. BMC has always strongly recommended to use s…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55108">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10897 – The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10897</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10897</guid>
    <pubDate>Fri, 31 Oct 2025 08:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10897</strong></p>
  <p>The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.9.28. This makes it possible for unauthenticated attackers to read arbitrary files on the server, which can expose DB credentials when the wp-config.php file is read.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10897">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-8422 – The Propovoice: All-in-One Client Management System plugin for WordPress is vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8422</guid>
    <pubDate>Thu, 11 Sep 2025 08:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8422</strong></p>
  <p>The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.7.6.7 via the send_email() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8422">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13982 – SPON IP Network Broadcast System, a digital audio transmission platform develope...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13982</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13982</guid>
    <pubDate>Wed, 27 Aug 2025 22:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13982</strong></p>
  <p>SPON IP Network Broadcast System, a digital audio transmission platform developed by SPON Communications, contains an arbitrary file read vulnerability in the rj_get_token.php endpoint. The flaw arises from insufficient input validation on the jsondata[url] parameter, which allows attackers to perform directory traversal and access sensitive files on the server. An unauthenticated remote attacker…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13982">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-29421 – PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFile...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-29421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-29421</guid>
    <pubDate>Mon, 25 Aug 2025 17:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-29421</strong></p>
  <p>PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFileContent function.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6253 – The UiCore Elements – Free Elementor widgets and templates plugin for WordPress ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6253</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6253</guid>
    <pubDate>Tue, 12 Aug 2025 06:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6253</strong></p>
  <p>The UiCore Elements – Free Elementor widgets and templates plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.3.0 via the prepare_template() function due to a missing capability check and insufficient controls on the filename specified. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which c…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6253">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-34130 – An unauthenticated arbitrary file read exists in LILIN Digital Video Recorder (D...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34130</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34130</guid>
    <pubDate>Wed, 16 Jul 2025 22:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-34130</strong></p>
  <p>An unauthenticated arbitrary file read exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the /z/zbin/net_html.cgi endpoint. This vulnerability allows attackers to read sensitive configuration files, such as /zconf/service.xml, which can then be used to facilitate further attacks including command injection. The vulnerability has been exploited in t…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34130">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-26291 – An Unauthenticated Arbitrary File Read vulnerability affects the
Agent when inst...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-26291</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-26291</guid>
    <pubDate>Mon, 14 Jul 2025 09:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-26291</strong></p>
  <p>An Unauthenticated Arbitrary File Read vulnerability affects the Agent when installed on a system. The parameter filename does not validate the path thus allowing users to read arbitrary files. As the application runs with the highest privileges (root/NT_AUTHORITY SYSTEM) by default attackers are able to obtain sensitive information.  This issue affects Avid NEXIS E-series: before 2025.5.1; Avid…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26291">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-7401 – The Premium Age Verification / Restriction for WordPress plugin for WordPress is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7401</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7401</guid>
    <pubDate>Fri, 11 Jul 2025 05:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-7401</strong></p>
  <p>The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and write due to the existence of an insufficiently protected remote support functionality in remote_tunnel.php in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to read from or write to arbitrary files on the affected site's server whi…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7401">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3046 – A vulnerability in the `ObsidianReader` class of the run-llama/llama_index repos...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3046</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3046</guid>
    <pubDate>Mon, 07 Jul 2025 10:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3046</strong></p>
  <p>A vulnerability in the `ObsidianReader` class of the run-llama/llama_index repository, versions 0.12.23 to 0.12.28, allows for arbitrary file read through symbolic links. The `ObsidianReader` fails to resolve symlinks to their real paths and does not validate whether the resolved paths lie within the intended directory. This flaw enables attackers to place symlinks pointing to files outside the v…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3046">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-34058 – Hikvision Streaming Media Management Server v2.3.5 uses default credentials that...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34058</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34058</guid>
    <pubDate>Tue, 01 Jul 2025 15:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-34058</strong></p>
  <p>Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate and access restricted functionality. After authenticating with these credentials, an attacker can exploit an arbitrary file read vulnerability in the /systemLog/downFile.php endpoint via directory traversal in the fileName parameter. This exploit chain can enable unauthorized ac…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34058">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-34048 – A path traversal vulnerability exists in the web management interface of D-Link ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34048</guid>
    <pubDate>Thu, 26 Jun 2025 16:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-34048</strong></p>
  <p>A path traversal vulnerability exists in the web management interface of D-Link DSL-2730U, DSL-2750U, and DSL-2750E ADSL routers with firmware versions IN_1.02, SEA_1.04, and SEA_1.07. The vulnerability is due to insufficient input validation on the getpage parameter within the /cgi-bin/webproc CGI script. This flaw allows an unauthenticated remote attacker to perform path traversal attacks by su…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-34045 – A path traversal vulnerability exists in WeiPHP 5.0, an open source WeChat publi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34045</guid>
    <pubDate>Thu, 26 Jun 2025 16:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-34045</strong></p>
  <p>A path traversal vulnerability exists in WeiPHP 5.0, an open source WeChat public account platform development framework by Shenzhen Yuanmengyun Technology Co., Ltd. The flaw occurs in the picUrl parameter of the /public/index.php/material/Material/_download_imgage endpoint, where insufficient input validation allows unauthenticated remote attackers to perform directory traversal via crafted POST…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48026 – A vulnerability in the WebApl component of Mitel OpenScape Xpressions through V7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48026</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48026</guid>
    <pubDate>Mon, 23 Jun 2025 20:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48026</strong></p>
  <p>A vulnerability in the WebApl component of Mitel OpenScape Xpressions through V7R1 FR5 HF43 P913 could allow an unauthenticated attacker to conduct a path traversal attack due to insufficient input validation. A successful exploit could allow an attacker to read files from the underlying OS and obtain sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48026">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4365 – Arbitrary file read in NetScaler Console and NetScaler SDX (SVM)</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4365</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4365</guid>
    <pubDate>Tue, 17 Jun 2025 13:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4365</strong></p>
  <p>Arbitrary file read in NetScaler Console and NetScaler SDX (SVM)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4365">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27817 – A possible arbitrary file read and SSRF vulnerability has been identified in Apa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27817</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27817</guid>
    <pubDate>Tue, 10 Jun 2025 08:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27817</strong></p>
  <p>A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients accept configuration data for setting the SASL/OAUTHBEARER connection with the brokers, including "sasl.oauthbearer.token.endpoint.url" and "sasl.oauthbearer.jwks.endpoint.url". Apache Kafka allows clients to read an arbitrary file and return the content in the error log, or send…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27817">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-45529 – An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSC...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-45529</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-45529</guid>
    <pubDate>Tue, 27 May 2025 19:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-45529</strong></p>
  <p>An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET request to /cms/templates/templatesAssetsEditor.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-552</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-45529">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-28055 – upset-gal-web v7.1.0 /api/music/v1/cover.ts contains an arbitrary file read vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-28055</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-28055</guid>
    <pubDate>Tue, 13 May 2025 16:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-28055</strong></p>
  <p>upset-gal-web v7.1.0 /api/music/v1/cover.ts contains an arbitrary file read vulnerabilit</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-28055">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3419 – The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3419</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3419</guid>
    <pubDate>Thu, 08 May 2025 06:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3419</strong></p>
  <p>The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 4.0.26 via the proxy_image() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. CVE-2025-47445 is a duplicate of this vulnerab…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3419">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46568 – Stirling-PDF is a locally hosted web application that allows you to perform vari...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46568</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46568</guid>
    <pubDate>Thu, 01 May 2025 18:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46568</strong></p>
  <p>Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. Prior to version 0.45.0, Stirling-PDF is vulnerable to SSRF-induced arbitrary file read. WeasyPrint redefines a set of HTML tags, including img, embed, object, and others. The references to several files inside, allow the attachment of content from any webpage or local file to a PDF. This…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46568">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-1565 – The Mayosis Core plugin for WordPress is vulnerable to Arbitrary File Read in al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1565</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1565</guid>
    <pubDate>Fri, 25 Apr 2025 10:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-1565</strong></p>
  <p>The Mayosis Core plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.4.1 via the library/wave-audio/peaks/remote_dl.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1565">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3103 – The CLEVER - HTML5 Radio Player With History - Shoutcast and Icecast - Elementor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3103</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3103</guid>
    <pubDate>Sat, 19 Apr 2025 05:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3103</strong></p>
  <p>The CLEVER - HTML5 Radio Player With History - Shoutcast and Icecast - Elementor Widget Addon plugin for WordPress is vulnerable to arbitrary file read due to insufficient file path validation in the 'history.php' file in all versions up to, and including, 2.4. This makes it possible for unauthenticated attackers to read arbitrary files on the affected site's server, which may contain sensitive i…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3103">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3431 – The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3431</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3431</guid>
    <pubDate>Tue, 08 Apr 2025 08:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3431</strong></p>
  <p>The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.91 via the 'dzsap_download' action. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3431">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30014 – SAP Capital Yield Tax Management has directory traversal vulnerability due to in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30014</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30014</guid>
    <pubDate>Tue, 08 Apr 2025 08:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30014</strong></p>
  <p>SAP Capital Yield Tax Management has directory traversal vulnerability due to insufficient path validation. This could allow an attacker with low privileges to read files from directory which they don�t have access to, hence causing a high impact on confidentiality. Integrity and Availability are not affected.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-35</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30014">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27428 – Due to directory traversal vulnerability, an authorized attacker could gain acce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27428</guid>
    <pubDate>Tue, 08 Apr 2025 08:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27428</strong></p>
  <p>Due to directory traversal vulnerability, an authorized attacker could gain access to some critical information by using RFC enabled function module. Upon successful exploitation, they could read files from any managed system connected to SAP Solution Manager, leading to high impact on confidentiality. There is no impact on integrity or availability.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-45480 – An improper control of generation of code ('Code Injection') vulnerability in th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45480</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45480</guid>
    <pubDate>Tue, 25 Mar 2025 05:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-45480</strong></p>
  <p>An improper control of generation of code ('Code Injection') vulnerability in the AprolCreateReport component of B&R APROL <4.4-00P5 may allow an unauthenticated network-based attacker to read files from the local system.</p>
  <p><strong>CVSS:</strong> 9.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45480">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-8859 – A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When user...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8859</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8859</guid>
    <pubDate>Thu, 20 Mar 2025 10:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-8859</strong></p>
  <p>A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, concatenating the URL directly into the file protocol results in an arbitrary file read vulnerability. This issue occurs because only the path part of the URL is checked, while parts such as query and parameters are not handled. The vulnerability is triggered if the user has confi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-29</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8859">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-8248 – A vulnerability in the normalizePath function in mintplex-labs/anything-llm vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8248</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8248</guid>
    <pubDate>Thu, 20 Mar 2025 10:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-8248</strong></p>
  <p>A vulnerability in the normalizePath function in mintplex-labs/anything-llm version git 296f041 allows for path traversal, leading to arbitrary file read and write in the storage directory. This can result in privilege escalation from manager to admin. The issue is fixed in version 1.2.2.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-29</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8248">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-7760 – aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7760</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7760</guid>
    <pubDate>Thu, 20 Mar 2025 10:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-7760</strong></p>
  <p>aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulnerability is due to overly permissive CORS settings, allowing cross-origin requests from all origins. This enables CSRF attacks on all endpoints of the tracking server, which can be chained with other existing vulnerabilities such as remote code execution, denial of service, and…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7760">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-12450 – In infiniflow/ragflow versions 0.12.0, the `web_crawl` function in `document_app...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-12450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-12450</guid>
    <pubDate>Thu, 20 Mar 2025 10:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-12450</strong></p>
  <p>In infiniflow/ragflow versions 0.12.0, the `web_crawl` function in `document_app.py` contains multiple vulnerabilities. The function does not filter URL parameters, allowing attackers to exploit Full Read SSRF by accessing internal network addresses and viewing their content through the generated PDF files. Additionally, the lack of restrictions on the file protocol enables Arbitrary File Read, a…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-12450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27785 – Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerabl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27785</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27785</guid>
    <pubDate>Wed, 19 Mar 2025 21:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27785</strong></p>
  <p>Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's `export_index` function. This issue may lead to reading arbitrary files on the Applio server. It can also be used in conjunction with blind server-side request forgery to read files from servers on the internal network that the Applio server has access to. As of time of publicati…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27785">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27784 – Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerabl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27784</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27784</guid>
    <pubDate>Wed, 19 Mar 2025 21:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27784</strong></p>
  <p>Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's `export_pth` function. This issue may lead to reading arbitrary files on the Applio server. It can also be used in conjunction with blind server-side request forgery to read files from servers on the internal network that the Applio server has access to. As of time of publication…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27784">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27777 – Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27777</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27777</guid>
    <pubDate>Wed, 19 Mar 2025 21:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27777</strong></p>
  <p>Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) in `model_download.py` (line 195 in 3.2.7). The blind SSRF allows for sending requests on behalf of Applio server and can be leveraged to probe for other vulnerabilities on the server itself or on other back-end systems on the internal network, that the Applio server can reach. The bli…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27777">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
