<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Arbitrary File Read</title>
  <link>https://cvedaily.com/pages/tags/arb-read.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/arb-read.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Arbitrary File Read</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:33 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-0611 – Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0611</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0611</guid>
    <pubDate>Tue, 02 Jun 2026 17:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-0611</strong></p>
  <p>Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability through a deprecated .NET Remoting HTTP channel exposed on port 8989 that allows attackers to perform arbitrary file read and write operations by supplying valid .NET URI endpoints. Attackers can write ASPX webshells to the IIS wwwroot directory to achie…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0611">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-32685 – Path traversal vulnerability in Gleam's handling of custom documentation pages a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32685</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32685</guid>
    <pubDate>Tue, 02 Jun 2026 14:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-32685</strong></p>
  <p>Path traversal vulnerability in Gleam's handling of custom documentation pages allows arbitrary file read and file write outside the intended documentation output directory.  The documentation.pages entries from gleam.toml are incorporated into filesystem paths without sufficient validation or confinement to the intended project and documentation output directories. The documentation.pages[].path…</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32685">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49136 – Banana Slides through 0.4.0, patched in commit e8bc490, contains a path traversa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49136</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49136</guid>
    <pubDate>Mon, 01 Jun 2026 21:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49136</strong></p>
  <p>Banana Slides through 0.4.0, patched in commit e8bc490, contains a path traversal vulnerability in the generate_image() function within the AI service backend that allows unauthenticated attackers to read arbitrary image-format files outside the intended uploads directory by exploiting an incomplete path prefix check using os.path.startswith() without a trailing separator. Attackers can supply cr…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49136">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10074 – DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10074</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10074</guid>
    <pubDate>Fri, 29 May 2026 14:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10074</strong></p>
  <p>DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing privileged local attackers to exploit Relative Path Traversal to download arbitrary system files.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10074">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10073 – DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10073</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10073</guid>
    <pubDate>Fri, 29 May 2026 14:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10073</strong></p>
  <p>DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing unauthenticated local attackers to exploit Relative Path Traversal to download arbitrary system files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10073">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10044 – Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10044</guid>
    <pubDate>Thu, 28 May 2026 22:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10044</strong></p>
  <p>Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vulnerability in the GET /api/prompts/{filename} endpoint on Windows deployments that allows unauthenticated remote attackers to read arbitrary files by supplying absolute Windows paths or backslash-based traversal sequences. Attackers can bypass the incomplete path traversal guard, which only blocks forward slashes and…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9035 – IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9035</guid>
    <pubDate>Wed, 27 May 2026 14:17:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9035</strong></p>
  <p>IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential arbitrary file read in the asperahttpd component. An authenticated user may be able to take advantage of this vulnerability to access files in the server’s local storage that they sho…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48126 – Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when alg...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48126</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48126</guid>
    <pubDate>Tue, 26 May 2026 17:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48126</strong></p>
  <p>Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when algernon is started with --domain (or --letsencrypt, which silently turns on --domain at engine/flags.go:372), the request handler resolves the served directory by joining the configured --dir with the value of the client-supplied Host header. The join is performed by filepath.Join with no validation, so a Host: .. heade…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48126">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40564 – Files or Directories Accessible to External Parties, Server-Side Request Forgery...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40564</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40564</guid>
    <pubDate>Tue, 26 May 2026 16:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40564</strong></p>
  <p>Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator.  The FlinkSessionJob jarURI is currently not validated so that it points to user-owned files or addresses.  This lets a user with CR create permissions read files from the operator pod's filesystem and pull content from any backing store reachable through Flin…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-552</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40564">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39352 – Frappe is a full-stack web application framework. Versions prior to 15.105.0 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39352</guid>
    <pubDate>Wed, 20 May 2026 20:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39352</strong></p>
  <p>Frappe is a full-stack web application framework. Versions prior to 15.105.0 and 16.15.0 contain a possible Arbitrary File Read vulnerability via Path Traversal. The issue is resolved in versions 16.15.0, 15.105.0 and above.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22599 – Strapi is an open source headless content management system. In versions on the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22599</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22599</guid>
    <pubDate>Thu, 14 May 2026 19:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22599</strong></p>
  <p>Strapi is an open source headless content management system. In versions on the 4.x branch prior to 4.26.1 and on the 5.x branch prior to 5.33.2, a database-query injection vulnerability existed in the Strapi Content-Type Builder write API. An authenticated administrator could inject arbitrary database statements through the `column.defaultTo` attribute when creating or modifying a content type.…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22599">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4030 – The Database Backup for WordPress plugin for WordPress is vulnerable to unauthor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4030</guid>
    <pubDate>Thu, 14 May 2026 13:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4030</strong></p>
  <p>The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check combined with a user-controlled backup directory parameter. This makes it possible for unauthenticated attackers to read and delete arbitrary f…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6514 – The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6514</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6514</guid>
    <pubDate>Thu, 14 May 2026 09:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6514</strong></p>
  <p>The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.1.2 via the popup_submit. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6514">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44445 – ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44445</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44445</guid>
    <pubDate>Wed, 13 May 2026 22:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44445</strong></p>
  <p>ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.12.0, an improper restriction of XML external entity (XXE) reference vulnerability in the EDI Module enables an authenticated attacker to read files from the local file system, including sensitive configuration files. This vulnerability is fixed in 15.104.3 and 16.12.0.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44445">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29205 – Incorrect privileges management and insufficient path filtering allow to read ar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29205</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29205</guid>
    <pubDate>Wed, 13 May 2026 22:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29205</strong></p>
  <p>Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29205">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0259 – An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0259</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0259</guid>
    <pubDate>Wed, 13 May 2026 19:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0259</strong></p>
  <p>An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables users to read sensitive information and delete arbitrary files. This vulnerability affects WF-500 and WF-500-B appliances running in the default non-FIPS configuration mode.    The WildFire Appliance (WF-500, WF-500-B) software update is now available to customers that use the Wi…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0259">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4782 – The Avada Builder plugin for WordPress is vulnerable to Arbitrary File Read in a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4782</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4782</guid>
    <pubDate>Wed, 13 May 2026 13:01:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4782</strong></p>
  <p>The Avada Builder plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.15.2 via the 'fusion_get_svg_from_file' function with the 'custom_svg' parameter of the 'fusion_section_separator' shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4782">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8052 – HashiCorp Nomad’s exec2 task driver prior to 0.1.2 is vulnerable to arbitrary fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8052</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8052</guid>
    <pubDate>Tue, 12 May 2026 20:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8052</strong></p>
  <p>HashiCorp Nomad’s exec2 task driver prior to 0.1.2 is vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-8052) is fixed in version 0.1.2 of the exec2 task driver.</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8052">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6959 – HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6959</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6959</guid>
    <pubDate>Tue, 12 May 2026 20:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6959</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-6959) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6959">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42600 – MinIO is a high-performance object storage system. From RELEASE.2022-07-24T01-54...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42600</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42600</guid>
    <pubDate>Mon, 11 May 2026 22:22:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42600</strong></p>
  <p>MinIO is a high-performance object storage system. From RELEASE.2022-07-24T01-54-52Z to before RELEASE.2026-04-14T21-32-45Z, A path traversal vulnerability in MinIO's ReadMultiple internode storage-REST endpoint allows a caller holding the cluster root JWT to read files from outside the configured drive roots, bounded only by the MinIO process UID. The attacker sends POST minio/storage/{drivePath…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42600">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29201 – Insufficient input validation of the feature file name in `feature::LOADFEATUREF...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29201</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29201</guid>
    <pubDate>Fri, 08 May 2026 19:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29201</strong></p>
  <p>Insufficient input validation of the feature file name in `feature::LOADFEATUREFILE` adminbin call can cause arbitrary file read when a relative file path is passed.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29201">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44111 – OpenClaw before 2026.4.15 contains an arbitrary file read vulnerability in the Q...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44111</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44111</guid>
    <pubDate>Wed, 06 May 2026 20:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44111</strong></p>
  <p>OpenClaw before 2026.4.15 contains an arbitrary file read vulnerability in the QMD backend memory_get function that allows callers to read any Markdown files within the workspace root. Attackers with access to the memory tool can bypass path restrictions by providing arbitrary workspace Markdown paths to read files outside canonical memory locations or indexed QMD result sets.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-183</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44111">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-43975 – FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uplo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43975</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43975</guid>
    <pubDate>Wed, 06 May 2026 10:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-43975</strong></p>
  <p>FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileName  before constructing file paths, allowing an unauthenticated attacker to  write arbitrary files outside the intended upload directory or read  files from arbitrary locations on the server.  This issue affects Apache Wicket: from 8.0.0 through 8.17.0, from 9.0.0 through 9.22.0,…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43975">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6344 – The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6344</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6344</guid>
    <pubDate>Wed, 06 May 2026 08:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6344</strong></p>
  <p>The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This is due to insufficient path validation in the getAttachments() method of EmailNotificationActions, which resolves attacker-supplied file-upload URLs into filesystem paths without verifying that the resolved path stays inside the WordPress uploads directory: a strpos() prefix chec…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6344">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43533 – OpenClaw before 2026.4.10 contains an arbitrary file read vulnerability in QQBot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43533</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43533</guid>
    <pubDate>Tue, 05 May 2026 12:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43533</strong></p>
  <p>OpenClaw before 2026.4.10 contains an arbitrary file read vulnerability in QQBot media tags that allows attackers to reference host-local paths outside the intended media storage boundary. Attackers can craft malicious reply text containing media tags to disclose arbitrary local files through outbound media handling.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43533">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-5957 – The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read in all ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5957</guid>
    <pubDate>Tue, 05 May 2026 04:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-5957</strong></p>
  <p>The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to and including 1.6.5. This is due to a flawed path traversal validation in the create_template() method of the CheckForm class, where realpath() is called on the allowed base directory (wp-content/uploads/emailkit/templates/) which may not exist, causing it to return false. In PHP 8.x, strpos($real_path, f…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6320 – The Salon Booking System – Free Version plugin for WordPress is vulnerable to Ar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6320</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6320</guid>
    <pubDate>Sat, 02 May 2026 12:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6320</strong></p>
  <p>The Salon Booking System – Free Version plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 10.30.25. This is due to the public booking flow accepting attacker-controlled file-field values and later using those stored values as trusted paths for email attachments. This makes it possible for unauthenticated attackers to read arbitrary local files and exfiltr…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6320">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-50992 – Weaver (Fanwei) E-cology 9.5 versions prior to 10.52 contain an arbitrary file r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-50992</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-50992</guid>
    <pubDate>Thu, 30 Apr 2026 17:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-50992</strong></p>
  <p>Weaver (Fanwei) E-cology 9.5 versions prior to 10.52 contain an arbitrary file read vulnerability in the XmlRpcServlet interface at the XML-RPC endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying file paths to the WorkflowService.getAttachment and WorkflowService.LoadTemplateProp methods. Attackers can exploit these methods without authentication to retrieve…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-50992">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33077 – Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33077</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33077</guid>
    <pubDate>Fri, 24 Apr 2026 03:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33077</strong></p>
  <p>Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the oldconfig parameter in the haproxy_section_save interface has an arbitrary file read vulnerability. Version 8.2.6.4 fixes the issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33077">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34413 – Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34413</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34413</guid>
    <pubDate>Wed, 22 Apr 2026 19:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34413</strong></p>
  <p>Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.php where an HTTP redirect to unauthenticated callers does not call exit() or die(), allowing PHP execution to continue and process the full request server-side. Unauthenticated attackers can perform file operations on project media di…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-497</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34413">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39378 – The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various oth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39378</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39378</guid>
    <pubDate>Tue, 21 Apr 2026 01:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39378</strong></p>
  <p>The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. In versions 6.5 through 7.17.0, when `HTMLExporter.embed_images=True`, nbconvert's markdown renderer allows arbitrary file read via path traversal in image references. A malicious notebook can exfiltrate sensitive files from the conversion host by embedding them as base64 data URIs in t…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39378">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5478 – The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5478</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5478</guid>
    <pubDate>Mon, 20 Apr 2026 20:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5478</strong></p>
  <p>The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and including, 3.4.4. This is due to the plugin trusting attacker-controlled old_files data from public form submissions as legitimate server-side upload state, and converting attacker-supplied URLs into local filesystem paths using regex-based string replacement without canonicalizatio…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5478">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5710 – The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5710</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5710</guid>
    <pubDate>Fri, 17 Apr 2026 18:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5710</strong></p>
  <p>The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary File Read in versions up to and including 1.3.9.6. This is due to the plugin using client-supplied mfile[] POST values as the source of truth for email attachment selection without performing any server-side upload provenance check, path canonicalization, or director…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5710">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3464 – The WP Customer Area plugin for WordPress is vulnerable to arbitrary file read a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3464</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3464</guid>
    <pubDate>Fri, 17 Apr 2026 17:17:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3464</strong></p>
  <p>The WP Customer Area plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation in the 'ajax_attach_file' function in all versions up to, and including, 8.3.4. This makes it possible for authenticated attackers with a role that an administrator grants access to (e.g., Subscriber) to to read the contents of arbitrary files on the server, which c…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3464">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4659 – The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4659</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4659</guid>
    <pubDate>Fri, 17 Apr 2026 07:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4659</strong></p>
  <p>The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV URL parameter in versions up to, and including, 2.0.6. This is due to insufficient path traversal sanitization in the URLtoRelative() and urlToPath() functions, combined with the ability to enable debug output in widget settings. The URLtoRelative() function only performs a sim…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4659">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-39842 – OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39842</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39842</guid>
    <pubDate>Wed, 15 Apr 2026 04:17:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-39842</strong></p>
  <p>OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulnerabilities in the rules engine that allow arbitrary code execution on the server. The JavaScript rules engine executes user-supplied scripts via Nashorn's ScriptEngine.eval() without sandboxing, class filtering, or access restrictions, and the authorization check in RulesResourc…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39842">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-35033 – Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35033</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35033</guid>
    <pubDate>Tue, 14 Apr 2026 23:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-35033</strong></p>
  <p>Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpeg argument injection through the StreamOptions query parameter parsing mechanism. The ParseStreamOptions method in StreamingHelpers.cs adds any lowercase query parameter to a dictionary without validation, bypassing the RegularExpression attribute on…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35033">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-35031 – Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35031</guid>
    <pubDate>Tue, 14 Apr 2026 23:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-35031</strong></p>
  <p>Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /Videos/{itemId}/Subtitles), where the Format field is not validated, allowing path traversal via the file extension and enabling arbitrary file write. This arbitrary file write can be chained into arbitrary file read via .strm files, database extracti…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35031">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23780 – An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL inject...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23780</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23780</guid>
    <pubDate>Fri, 10 Apr 2026 15:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23780</strong></p>
  <p>An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug interface allows an authenticated attacker to inject malicious queries due to improper input validation and unsafe dynamic SQL handling. Successful exploitation can enable arbitrary file read/write operations and potentially lead to remote code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23780">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-30816 – An external control of configuration vulnerability in the OpenVPN module of TP-L...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30816</guid>
    <pubDate>Wed, 08 Apr 2026 19:25:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-30816</strong></p>
  <p>An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary file when a malicious configuration file is processed.  Successful exploitation may allow unauthorized access to arbitrary files on the device, potentially exposing sensitive information.This issue affects AX53 v1.0: before 1.7.1 Build 20260213.</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-15</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34070 – LangChain is a framework for building agents and LLM-powered applications. Prior...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34070</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34070</guid>
    <pubDate>Tue, 31 Mar 2026 03:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34070</strong></p>
  <p>LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without validating against directory traversal or absolute path injection. When an application passes user-influenced prompt configurations to load_prompt() or load_prompt_from_config(),…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34070">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3098 – The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3098</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3098</guid>
    <pubDate>Fri, 27 Mar 2026 04:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3098</strong></p>
  <p>The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3098">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33725 – Metabase is an open source business intelligence and embedded analytics tool. In...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33725</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33725</guid>
    <pubDate>Fri, 27 Mar 2026 01:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33725</strong></p>
  <p>Metabase is an open source business intelligence and embedded analytics tool. In Metabase Enterprise prior to versions 1.54.22, 1.55.22, 1.56.22, 1.57.16, 1.58.10, and 1.59.4, authenticated admins on Metabase Enterprise Edition can achieve Remote Code Execution (RCE) and Arbitrary File Read via the `POST /api/ee/serialization/import` endpoint. A crafted serialization archive injects an `INIT` pro…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33725">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-4474 – Ruckus Access Point products contain an arbitrary file read vulnerability in the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-4474</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-4474</guid>
    <pubDate>Thu, 26 Mar 2026 20:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-4474</strong></p>
  <p>Ruckus Access Point products contain an arbitrary file read vulnerability in the command-line interface that allows authenticated remote attackers with administrative privileges to read arbitrary files from the underlying filesystem. Attackers can exploit this vulnerability to access sensitive information including configuration files, credentials, and system data stored on the device.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-552</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4474">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4373 – The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4373</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4373</guid>
    <pubDate>Sat, 21 Mar 2026 07:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4373</strong></p>
  <p>The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 3.5.6.2. This is due to the 'Uploaded_File::set_from_array' method accepting user-supplied file paths from the Media Field preset JSON payload without validating that the path belongs to the WordPress uploads directory. Combined with an insufficient same-file check…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4373">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2351 – The Task Manager plugin for WordPress is vulnerable to Arbitrary File Read in al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2351</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2351</guid>
    <pubDate>Sat, 21 Mar 2026 04:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2351</strong></p>
  <p>The Task Manager plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.0.2 via the callback_get_text_from_url() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2351">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3474 – The EmailKit – Email Customizer for WooCommerce &amp; WP plugin for WordPress is vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3474</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3474</guid>
    <pubDate>Sat, 21 Mar 2026 00:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3474</strong></p>
  <p>The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 1.6.3. This is due to the action() function in the TemplateData class passing user-supplied input from the 'emailkit-editor-template' REST API parameter directly to file_get_contents() without any path validation, sanitization, or…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3474">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33166 – Allure 2 is the version 2.x branch of Allure Report, a multi-language test repor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33166</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33166</guid>
    <pubDate>Fri, 20 Mar 2026 22:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33166</strong></p>
  <p>Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. The Allure report generator prior to version 2.38.0 is vulnerable to an arbitrary file read via path traversal when processing test results. An attacker can craft a malicious result file (-result.json, -container.json, or .plist) that points an attachment source to a sensitive file on the host system. Durin…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33166">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32711 – pydicom is a pure Python package for working with DICOM files. Versions 2.0.0-rc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32711</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32711</guid>
    <pubDate>Fri, 20 Mar 2026 02:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32711</strong></p>
  <p>pydicom is a pure Python package for working with DICOM files. Versions 2.0.0-rc.1 through 3.0.1 are vulnerable to Path Traversal through a maliciously crafted DICOMDIR ReferencedFileID when it is set to a path outside the File-set root. pydicom resolves the path only to confirm that it exists, but does not verify that the resolved path remains under the File-set root. Subsequent public FileSet o…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32711">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33301 – OpenEMR is a free and open source electronic health records and medical practice...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33301</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33301</guid>
    <pubDate>Thu, 19 Mar 2026 21:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33301</strong></p>
  <p>OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2,  users with the `Notes - my encounters` role can fill Eye Exam forms in patient encounters. The answers to the form can be printed out in PDF form. An arbitrary file read vulnerability was identified in the PDF creation function where the form answers are parsed as unescaped…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33301">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30403 – There is an arbitrary file read vulnerability in the test connection function of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30403</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30403</guid>
    <pubDate>Thu, 19 Mar 2026 17:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30403</strong></p>
  <p>There is an arbitrary file read vulnerability in the test connection function of backend database management in wgcloud v3.6.3 and before, which can be used to read any file on the victim's server.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30403">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2808 – HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2808</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2808</guid>
    <pubDate>Thu, 12 Mar 2026 00:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2808</strong></p>
  <p>HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2808">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25472 – IntelBras Telefone IP TIP200 and 200 LITE contain an unauthenticated arbitrary f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25472</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25472</guid>
    <pubDate>Wed, 11 Mar 2026 19:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25472</strong></p>
  <p>IntelBras Telefone IP TIP200 and 200 LITE contain an unauthenticated arbitrary file read vulnerability in the dumpConfigFile function accessible via the cgiServer.exx endpoint. Attackers can send GET requests to /cgi-bin/cgiServer.exx with the command parameter containing dumpConfigFile() to read sensitive files including /etc/shadow and configuration files without proper authorization.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25472">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-30234 – OpenProject is an open-source, web-based project management software. Prior to 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30234</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30234</guid>
    <pubDate>Wed, 11 Mar 2026 16:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-30234</strong></p>
  <p>OpenProject is an open-source, web-based project management software. Prior to 17.2.0, an authenticated project member with BCF import permissions can upload a crafted .bcf archive where the <Snapshot> value in markup.bcf is manipulated to contain an absolute or traversal local path (for example: /etc/passwd or ../../../../etc/passwd). During import, this untrusted <Snapshot> value is used as fil…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30234">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28807 – Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28807</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28807</guid>
    <pubDate>Tue, 10 Mar 2026 22:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28807</strong></p>
  <p>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in gleam-wisp wisp allows arbitrary file read via percent-encoded path traversal.  The wisp.serve_static function is vulnerable to path traversal because sanitization runs before percent-decoding. The encoded sequence %2e%2e passes through string.replace unchanged, then uri.percent_decode converts it to .…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28807">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0846 – A vulnerability in the `filestring()` function of the `nltk.util` module in nltk...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0846</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0846</guid>
    <pubDate>Mon, 09 Mar 2026 20:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0846</strong></p>
  <p>A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without sanitization, enabling attackers to access sensitive system files by providing absolute paths or traversal paths. This vulnerability can be exploited locally or remotel…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0846">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-29190 – Karapace is an open-source implementation of Kafka REST and Schema Registry. Pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29190</guid>
    <pubDate>Sat, 07 Mar 2026 16:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-29190</strong></p>
  <p>Karapace is an open-source implementation of Kafka REST and Schema Registry. Prior to version 6.0.0, there is a Path Traversal vulnerability in the backup reader (backup/backends/v3/backend.py). If a malicious backup file is provided to Karapace, an attacker may exploit insufficient path validation to perform arbitrary file read on the system where Karapace is running. The issue affects deploymen…</p>
  <p><strong>CVSS:</strong> 4.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29190">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29064 – Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29064</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29064</guid>
    <pubDate>Fri, 06 Mar 2026 17:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29064</strong></p>
  <p>Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal vulnerability in archive extraction allows a specifically crafted Zarf package to create symlinks pointing outside the destination directory, enabling arbitrary file read or write on the system processing the package. This issue has been patched in version 0.73.1.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29064">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28463 – OpenClaw versions prior to 2026.2.14 contain an arbitrary file read vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28463</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28463</guid>
    <pubDate>Thu, 05 Mar 2026 22:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28463</strong></p>
  <p>OpenClaw versions prior to 2026.2.14 contain an arbitrary file read vulnerability in the exec-approvals allowlist validation that checks pre-expansion argv tokens but executes using real shell expansion. Attackers with authorization or through prompt-injection attacks can exploit safe binaries like head, tail, or grep with glob patterns or environment variables to disclose files readable by the g…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28463">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-45691 – An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-45691</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-45691</guid>
    <pubDate>Thu, 05 Mar 2026 19:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-45691</strong></p>
  <p>An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in Exploding Gradients RAGAS v0.2.3 to v0.2.14. The vulnerability stems from improper validation and sanitization of URLs supplied in the retrieved_contexts parameter when handling multimodal inputs.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-45691">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0847 – A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0847</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0847</guid>
    <pubDate>Wed, 04 Mar 2026 19:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0847</strong></p>
  <p>A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCorpusReader, TaggedCorpusReader, and BracketParseCorpusReader. These classes fail to properly sanitize or validate file paths, enabling attackers to traverse directories and access sensitive files on the server. This issue is particularly cr…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0847">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2606 – IBM webMethods API Gateway (on-prem) 10.11 through 10.11_Fix3210.15 to 10.15_Fix...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2606</guid>
    <pubDate>Tue, 03 Mar 2026 20:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2606</strong></p>
  <p>IBM webMethods API Gateway (on-prem) 10.11 through 10.11_Fix3210.15 to 10.15_Fix2711.1 to 11.1_Fix7 IBM webMethods API Management (on-prem) fails to properly validate user-supplied input passed to the url parameter on the /createapi endpoint. An attacker can modify this parameter to use a file:// URI schema instead of the expected https:// schema, enabling unauthorized arbitrary file read access…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26960 – node-tar is a full-featured Tar for Node.js. When using default options in versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26960</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26960</guid>
    <pubDate>Fri, 20 Feb 2026 02:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26960</strong></p>
  <p>node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outside the extraction root, enabling arbitrary file read and write as the extracting user. Severity is high because the primitive bypasses path protections and turns archive extraction into…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26960">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26202 – Penpot is an open-source design tool for design and code collaboration. Prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26202</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26202</guid>
    <pubDate>Thu, 19 Feb 2026 20:25:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26202</strong></p>
  <p>Penpot is an open-source design tool for design and code collaboration. Prior to version 2.13.2, an authenticated user can read arbitrary files from the server by supplying a local file path (e.g. `/etc/passwd`) as a font data chunk in the `create-font-variant` RPC endpoint, resulting in the file contents being stored and retrievable as a "font" asset. This is an arbitrary file read vulnerability…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26202">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26337 – Hyland Alfresco Transformation Service allows unauthenticated attackers to achie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26337</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26337</guid>
    <pubDate>Thu, 19 Feb 2026 18:24:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26337</strong></p>
  <p>Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve both arbitrary file read and server-side request forgery through the absolute path traversal.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26337">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2274 – A SSRF and Arbitrary File Read vulnerability in AppSheet Core in Google AppSheet...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2274</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2274</guid>
    <pubDate>Thu, 19 Feb 2026 16:27:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2274</strong></p>
  <p>A SSRF and Arbitrary File Read vulnerability in AppSheet Core in Google AppSheet prior to 2025-11-23 allows an authenticated remote attacker to read sensitive local files and access internal network resources via crafted requests to the production cluster.      This vulnerability was patched and no customer action is needed.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2274">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13603 – The WP AUDIO GALLERY plugin for WordPress is vulnerable to Unauthorized Arbitrar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13603</guid>
    <pubDate>Thu, 19 Feb 2026 07:17:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13603</strong></p>
  <p>The WP AUDIO GALLERY plugin for WordPress is vulnerable to Unauthorized Arbitrary File Read in all versions up to, and including, 2.0. This is due to insufficient capability checks and lack of nonce verification on the "wpag_htaccess_callback" function This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the site's .htaccess file with arbitrary…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-26333 – Calero VeraSMART versions prior to 2022 R1 expose an unauthenticated .NET Remoti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26333</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26333</guid>
    <pubDate>Fri, 13 Feb 2026 21:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-26333</strong></p>
  <p>Calero VeraSMART versions prior to 2022 R1 expose an unauthenticated .NET Remoting HTTP service on TCP port 8001. The service publishes default ObjectURIs (including EndeavorServer.rem and RemoteFileReceiver.rem) and permits the use of SOAP and binary formatters with TypeFilterLevel set to Full. An unauthenticated remote attacker can invoke the exposed remoting endpoints to perform arbitrary file…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26333">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-26221 – Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase W...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26221</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26221</guid>
    <pubDate>Fri, 13 Feb 2026 16:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-26221</strong></p>
  <p>Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service (Hyland.Core.Workflow.NTService.exe). An attacker who can reach the service can send crafted .NET Remoting requests to default HTTP channel endpoints on TCP/8900 (e.g., TimerServiceAPI.rem and TimerServiceEvents.rem for Workflow) to trigger unsafe object unmarshalling, enabling arbitrary file rea…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26221">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-15577 – An unauthenticated attacker can exploit this vulnerability by manipulating URL t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15577</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15577</guid>
    <pubDate>Thu, 12 Feb 2026 07:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-15577</strong></p>
  <p>An unauthenticated attacker can exploit this vulnerability by manipulating URL to achieve arbitrary file read access.This issue affects Valmet DNA Web Tools: C2022 and older.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15577">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1669 – Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1669</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1669</guid>
    <pubDate>Wed, 11 Feb 2026 23:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1669</strong></p>
  <p>Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensitive information via a crafted .keras model file utilizing HDF5 external dataset references.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1669">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25760 – Sliver is a command and control framework that uses a custom Wireguard netstack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25760</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25760</guid>
    <pubDate>Fri, 06 Feb 2026 22:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25760</strong></p>
  <p>Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.6.11, a path traversal in the website content subsystem lets an authenticated operator read arbitrary files on the Sliver server host. This is an authenticated path traversal / arbitrary file read issue, and it can expose credentials, configs, and keys. This vulnerability is fixed in 1.6.11.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25760">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-23633 – Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23633</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23633</guid>
    <pubDate>Fri, 06 Feb 2026 18:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-23633</strong></p>
  <p>Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, there is an arbitrary file read/write via path traversal in Git hook editing. This issue has been patched in versions 0.13.4 and 0.14.0+dev.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23633">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1246 – The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Arbitrary F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1246</guid>
    <pubDate>Thu, 05 Feb 2026 07:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1246</strong></p>
  <p>The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Arbitrary File Read via path traversal in the 'loadFile' parameter in all versions up to, and including, 6.4.2 due to insufficient path validation and sanitization in the 'loadLogFile' AJAX action. This makes it possible for authenticated attackers, with Editor-level access and above, to read the contents of arbitrary files on t…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24738 – gmrtd is a Go library for reading Machine Readable Travel Documents (MRTDs). Pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24738</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24738</guid>
    <pubDate>Tue, 27 Jan 2026 21:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24738</strong></p>
  <p>gmrtd is a Go library for reading Machine Readable Travel Documents (MRTDs). Prior to version 0.17.2, ReadFile accepts TLVs with lengths that can range up to 4GB, which can cause unconstrained resource consumption in both memory and cpu cycles. ReadFile can consume an extended TLV with lengths well outside what would be available in ICs. It can accept something all the way up to 4GB which would t…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24738">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23954 – Incus is a system container and virtual machine manager. Versions 6.21.0 and bel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23954</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23954</guid>
    <pubDate>Thu, 22 Jan 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23954</strong></p>
  <p>Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) to use directory traversal or symbolic links in the templating functionality to achieve host arbitrary file read, and host arbitrary file write. This ultimately results in arbitrary command execution on the h…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23954">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-7335 – EduSoho versions prior to 22.4.7 contain an arbitrary file read vulnerability in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-7335</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-7335</guid>
    <pubDate>Thu, 22 Jan 2026 17:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-7335</strong></p>
  <p>EduSoho versions prior to 22.4.7 contain an arbitrary file read vulnerability in the classroom-course-statistics export functionality. A remote, unauthenticated attacker can supply crafted path traversal sequences in the fileNames[] parameter to read arbitrary files from the server filesystem, including application configuration files such as config/parameters.yml that may contain secrets and dat…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-7335">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1330 – MeetingHub developed by HAMASTAR Technology has an Arbitrary File Read vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1330</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1330</guid>
    <pubDate>Thu, 22 Jan 2026 09:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1330</strong></p>
  <p>MeetingHub developed by HAMASTAR Technology has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1330">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-55130 – A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-rea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55130</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55130</guid>
    <pubDate>Tue, 20 Jan 2026 21:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-55130</strong></p>
  <p>A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-289</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55130">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-53912 – An arbitrary file read vulnerability exists in the encapsulatedDoc functionality...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53912</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53912</guid>
    <pubDate>Tue, 20 Jan 2026 15:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-53912</strong></p>
  <p>An arbitrary file read vulnerability exists in the encapsulatedDoc functionality of MedDream PACS Premium 7.3.6.870. A specially crafted HTTP request can lead to an arbitrary file read. An attacker can send http request to trigger this vulnerability.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53912">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-22218 – Chainlit versions prior to 2.9.4 contain an arbitrary file read vulnerability in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22218</guid>
    <pubDate>Tue, 20 Jan 2026 00:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-22218</strong></p>
  <p>Chainlit versions prior to 2.9.4 contain an arbitrary file read vulnerability in the /project/element update flow. An authenticated client can send a custom Element with a user-controlled path value, causing the server to copy the referenced file into the attacker’s session. The resulting element identifier (chainlitKey) can then be used to retrieve the file contents via /project/file/<chainlitKe…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23850 – SiYuan is a personal knowledge management system. In versions prior to 3.5.4, th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23850</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23850</guid>
    <pubDate>Mon, 19 Jan 2026 20:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23850</strong></p>
  <p>SiYuan is a personal knowledge management system. In versions prior to 3.5.4, the markdown feature allows unrestricted server side html-rendering which allows arbitrary file read (LFD). Version 3.5.4 fixes the issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23850">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-12002 – The Feeds for YouTube Pro plugin for WordPress is vulnerable to arbitrary file r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12002</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12002</guid>
    <pubDate>Sat, 17 Jan 2026 03:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-12002</strong></p>
  <p>The Feeds for YouTube Pro plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 2.6.0 via the 'sby_check_wp_submit' AJAX action. This is due to insufficient sanitization of user-supplied data and the use of that data in a file operation. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can c…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12002">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23529 – Kafka Connect BigQuery Connector is an implementation of a sink connector from A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23529</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23529</guid>
    <pubDate>Fri, 16 Jan 2026 17:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23529</strong></p>
  <p>Kafka Connect BigQuery Connector is an implementation of a sink connector from Apache Kafka to Google BigQuery. Prior to 2.11.0, there is an arbitrary file read in Google BigQuery Sink connector. Aiven's Google BigQuery Kafka Connect Sink connector requires Google Cloud credential configurations for authentication to BigQuery services. During connector configuration, users can supply credential J…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23529">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1022 – Statistics Database System developed by Gotac has an Arbitrary File Read vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1022</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1022</guid>
    <pubDate>Fri, 16 Jan 2026 04:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1022</strong></p>
  <p>Statistics Database System developed by Gotac has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1022">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1018 – Police Statistics Database System developed by Gotac has an Arbitrary File Read ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1018</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1018</guid>
    <pubDate>Fri, 16 Jan 2026 03:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1018</strong></p>
  <p>Police Statistics Database System developed by Gotac has an Arbitrary File Read vulnerability, allowing Unauthenticated remote attacker to exploit Absolute Path Traversal to download arbitrary system files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1018">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-67083 – Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67083</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67083</guid>
    <pubDate>Thu, 15 Jan 2026 15:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-67083</strong></p>
  <p>Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the server. The ability to read files and the file type depends on the web server and its configuration.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67083">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-22915 – An attacker with low privileges may be able to read files from specific director...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22915</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22915</guid>
    <pubDate>Thu, 15 Jan 2026 13:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-22915</strong></p>
  <p>An attacker with low privileges may be able to read files from specific directories on the device, potentially exposing sensitive information.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-497</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22915">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-15020 – The Gotham Block Extra Light plugin for WordPress is vulnerable to Arbitrary Fil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15020</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15020</guid>
    <pubDate>Wed, 14 Jan 2026 06:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-15020</strong></p>
  <p>The Gotham Block Extra Light plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.5.0 via the  'ghostban' shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15020">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22200 – Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22200</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22200</guid>
    <pubDate>Mon, 12 Jan 2026 19:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22200</strong></p>
  <p>Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export functionality. A remote attacker can submit a ticket containing crafted rich-text HTML that includes PHP filter expressions which are insufficiently sanitized before being processed by the mPDF PDF generator during export. When the attacker exports…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22200">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-14059 – The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read via Path ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14059</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14059</guid>
    <pubDate>Wed, 07 Jan 2026 12:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-14059</strong></p>
  <p>The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and including, 1.6.1. This is due to missing path validation in the create_template REST API endpoint where user-controlled input from the emailkit-editor-template parameter is passed directly to file_get_contents() without sanitization. This makes it possible for authenticated attacke…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14059">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-15227 – BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Read vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15227</guid>
    <pubDate>Mon, 29 Dec 2025 08:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-15227</strong></p>
  <p>BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-15225 – WMPro developed by Sunnet has an Arbitrary File Read vulnerability, allowing una...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15225</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15225</guid>
    <pubDate>Mon, 29 Dec 2025 07:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-15225</strong></p>
  <p>WMPro developed by Sunnet has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to read arbitrary system files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15225">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-14388 – The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14388</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14388</guid>
    <pubDate>Tue, 23 Dec 2025 10:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-14388</strong></p>
  <p>The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read via null byte injection in all versions up to, and including, 3.7. This is due to a discrepancy between the extension validation in `getExtensionForURL()` which operates on URL-decoded paths, and `appendNormalized()` which strips everything after a null byte before constructing the filesystem path. This makes…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-158</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14388">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68476 – KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to versions...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68476</guid>
    <pubDate>Mon, 22 Dec 2025 22:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68476</strong></p>
  <p>KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to versions 2.17.3 and 2.18.3, an Arbitrary File Read vulnerability has been identified in KEDA, potentially affecting any KEDA resource that uses TriggerAuthentication to configure HashiCorp Vault authentication. The vulnerability stems from an incorrect or insufficient path validation when loading the Service Account Token spe…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-15015 – Enterprise Cloud Database developed by Ragic has a Arbitrary File Read vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15015</guid>
    <pubDate>Mon, 22 Dec 2025 04:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-15015</strong></p>
  <p>Enterprise Cloud Database developed by Ragic has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68155 – @vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68155</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68155</guid>
    <pubDate>Tue, 16 Dec 2025 19:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68155</strong></p>
  <p>@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_findSourceMapURL` endpoint in `@vitejs/plugin-rsc` allows unauthenticated arbitrary file read during development mode. An attacker can read any file accessible to the Node.js process by sending a crafted HTTP request with a `file://` URL in the `filename` query parameter. Version 0.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68155">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13972 – The WatchTowerHQ plugin for WordPress is vulnerable to arbitrary file read via t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13972</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13972</guid>
    <pubDate>Fri, 12 Dec 2025 04:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13972</strong></p>
  <p>The WatchTowerHQ plugin for WordPress is vulnerable to arbitrary file read via the 'wht_download_big_object_origin' parameter in all versions up to, and including, 3.16.0. This is due to insufficient path validation in the handle_big_object_download_request function. This makes it possible for authenticated attackers, with administrator-level access and a valid access token, to read arbitrary fil…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13972">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-14293 – The WP Job Portal plugin for WordPress is vulnerable to Arbitrary File Read in a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14293</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14293</guid>
    <pubDate>Thu, 11 Dec 2025 21:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-14293</strong></p>
  <p>The WP Job Portal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.4.0 via the 'downloadCustomUploadedFile' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14293">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-48604 – In multiple locations, there is a possible way to read files from another user d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48604</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48604</guid>
    <pubDate>Mon, 08 Dec 2025 17:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-48604</strong></p>
  <p>In multiple locations, there is a possible way to read files from another user due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48604">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
