On this page
Atomicorp WAF Rule 344360
Rule Summary
- Rule ID: 344360
- Status: Active
- Alert message: Atomicorp.com WAF Rules: Unauthorized Operating System File Access Attempt
- Observed CWEs: CWE-20 (27), CWE-22 (559), CWE-23 (5), CWE-24 (1), CWE-29 (3), CWE-35 (1), CWE-36 (3), CWE-59 (2), CWE-73 (30), CWE-74 (28), CWE-77 (102), CWE-78 (244), CWE-79 (9), CWE-88 (3), CWE-89 (17), CWE-91 (1), CWE-93 (3), CWE-94 (92), CWE-95 (6), CWE-98 (12), CWE-120 (1), CWE-121 (3), CWE-180 (2), CWE-183 (1), CWE-184 (4), CWE-187 (1), CWE-200 (28), CWE-203 (1), CWE-206 (1), CWE-253 (1), CWE-269 (5), CWE-284 (13), CWE-285 (5), CWE-287 (9), CWE-288 (1), CWE-306 (22), CWE-327 (1), CWE-345 (2), CWE-346 (1), CWE-352 (10), CWE-367 (6), CWE-384 (1), CWE-400 (1), CWE-425 (1), CWE-434 (20), CWE-441 (5), CWE-444 (1), CWE-470 (5), CWE-472 (1), CWE-473 (1), CWE-489 (1), CWE-494 (1), CWE-501 (1), CWE-502 (2), CWE-522 (1), CWE-552 (7), CWE-601 (1), CWE-611 (4), CWE-625 (1), CWE-639 (3), CWE-641 (1), CWE-644 (2), CWE-668 (3), CWE-669 (1), CWE-674 (1), CWE-698 (1), CWE-704 (1), CWE-705 (1), CWE-706 (1), CWE-732 (2), CWE-770 (1), CWE-791 (1), CWE-798 (2), CWE-824 (1), CWE-829 (11), CWE-835 (1), CWE-862 (12), CWE-863 (7), CWE-913 (2), CWE-915 (2), CWE-917 (1), CWE-918 (280), CWE-942 (2), CWE-1188 (3), CWE-1220 (1), CWE-1336 (6), CWE-1392 (1)
- Revision: 5
- Rule severity: Critical (2)
- Phase: 2 (request body)
- Request surfaces: Request cookies, Request argument names, Request arguments, JSON request data, SOAP request data, XML request data
- Rule action: deny
- HTTP status: 403
- Public tags: attack-lfi
- Logging: log, auditlog
Description
This rule detects behavior identified by its current alert as “Unauthorized Operating System File Access Attempt” in the request cookies, request argument names, request arguments, JSON request data, SOAP request data, XML request data. It evaluates during the request body phase and denies matching traffic with HTTP status 403.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2009-0545 | ZeroShell <= 1.0beta11 Remote Code Execution | zeroshell | 10.0 (v2.0) | High |
| CVE-2010-5286 | Joomla! Component Jstore - 'Controller' Local File Inclusion | com jstore | 10.0 (v2.0) | High |
| CVE-2022-24816 | GeoServer <1.2.2 - Remote Code Execution | jai-ext | 10.0 (v3.1) | Critical |
| CVE-2025-34037 | Linksys Routers E/WAG/WAP/WES/WET/WRT-Series | E4200 | 10.0 (v4.0) | Critical |
| CVE-2025-55169 | WeGIA - Directory Traversal | wegia | 10.0 (v4.0) | Critical |
| CVE-2026-19188 | Haiwell IoT Cloud HMI Gateway OS Command Injection | Haiwell IoT Cloud HMI Gateway | 10.0 (v4.0) | Critical |
| CVE-2026-33712 | TypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint bypasses SSRF controls | typebot.io | 10.0 (v3.1) | Critical |
| CVE-2026-34234 | CtrlPanel: Unauthenticated RCE using installer script | panel | 10.0 (v3.1) | Critical |
| CVE-2026-44181 | Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Execution | enterprise gateway | 10.0 (v4.0) | Critical |
| CVE-2026-47668 | DbGate - Remote Code Execution via Anonymous JWT | dbgate | 10.0 (v3.1) | Critical |
| CVE-2026-49869 | Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in AuthenticationFilter | kestra | 10.0 (v3.1) | Critical |
| CVE-2026-54745 | Kubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENAB | pipelines | 10.0 (v3.1) | Critical |
| CVE-2026-58192 | Appium: Unauthenticated arbitrary file/directory deletion in @appium/storage-plugin | appium/storage-plugin | 10.0 (v3.1) | Critical |
| CVE-2026-81735 | UI-TARS-desktop @agent-infra MCP Servers Bind Every Interface Without Authentication, Exposing Arbitrary Command Executi | UI-TARS-desktop | 10.0 (v4.0) | Critical |
| CVE-2026-8984 | Unauthenticated RCE | maxicharger single charger firmware | 10.0 (v4.0) | Critical |
| CVE-2026-8985 | Unauthenticated Command Injection | maxicharger single charger firmware | 10.0 (v4.0) | Critical |
| CVE-2026-31818 | Budibase: Server-Side Request Forgery via REST Connector with Empty Default Blacklist | budibase | 9.9 (v3.1) | Critical |
| CVE-2026-42454 | Termix: OS Command Injection in Docker Container Management Endpoints | Termix | 9.9 (v3.1) | Critical |
| CVE-2026-43986 | Tautulli vulnerable to unauthenticated SSRF in /image/<hash> via attacker-seeded image hash replay | Tautulli | 9.9 (v3.1) | Critical |
| CVE-2026-44450 | Lumiverse: RCE via MCP stdio argument injection | Lumiverse | 9.9 (v3.1) | Critical |
| CVE-2026-45629 | Dokploy: Authenticated Remote Code Execution via Command Injection in /listen-deployment WebSocket Endpoint | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-45632 | Dokploy: Schedule Authorization Bypass Enables Host/Server Command Execution | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-48030 | Pheditor 2.0.1-2.0.3 - OS Command Injection | pheditor | 9.9 (v3.1) | Critical |
| CVE-2026-51027 | FileThingie v.2.5.7 Information Disclosure Vulnerability | - | 9.9 (v3.1) | Critical |
| CVE-2026-55166 | Lemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and cr | lemur | 9.9 (v3.1) | Critical |
| CVE-2026-55565 | Yamcs: Authenticated remote code execution via unescaped StreamSQL LIKE pattern compiled by Janino (LikeExpression) | yamcs | 9.9 (v3.1) | Critical |
| CVE-2026-55634 | Pimcore: Remote Code Execution via DataObject Class-Definition Field Name | pimcore | 9.9 (v3.1) | Critical |
| CVE-2026-63298 | LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration | lxd | 9.9 (v3.1) | Critical |
| CVE-2026-72738 | Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search Parameter | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-72740 | Dokploy: OS Command Injection via SSH-form customGitUrl domain in ssh-keyscan | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-72865 | Dokploy: OS Command Injection via compose composePath | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-72868 | Dokploy: Member-role RCE as host root via destination.testConnection rclone shell injection | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-72869 | Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCE | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-72872 | Dokploy: OS Command Injection via Bitbucket owner/repository in git clone | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-72876 | Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.* | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-72882 | Dokploy: Authenticated blind command injection via file mounts leads to direct remote host RCE on managed servers | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-72902 | Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryById | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-73294 | Semaphore U: OS Command Injection | semaphore | 9.9 (v3.1) | Critical |
| CVE-2026-8481 | Remote Code Execution via Code Validation Endpoint | langflow | 9.9 (v3.1) | Critical |
| CVE-2009-1151 | PhpMyAdmin Scripts - Remote Code Execution | phpmyadmin | 9.8 (v3.1) | Critical |
| CVE-2010-2861 | Adobe ColdFusion - Directory Traversal | coldfusion | 9.8 (v3.1) | Critical |
| CVE-2013-4864 | MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities | veralite firmware | 9.8 (v3.1) | Critical |
| CVE-2014-1203 | Eyou E-Mail <3.6 - Remote Code Execution | eyou | 9.8 (v3.1) | Critical |
| CVE-2014-6271 | ShellShock - Remote Code Execution | bash | 9.8 (v3.1) | Critical |
| CVE-2014-9148 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | 9.8 (v3.0) | Critical |
| CVE-2015-1427 | ElasticSearch - Remote Code Execution | elasticsearch | 9.8 (v3.1) | Critical |
| CVE-2015-4664 | Xceedium Xsuite - Multiple Vulnerabilities | privileged access manager | 9.8 (v3.0) | Critical |
| CVE-2015-4667 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 9.8 (v3.0) | Critical |
| CVE-2017-12611 | Apache Struts2 S2-053 - Remote Code Execution | struts | 9.8 (v3.0) | Critical |
| CVE-2017-7462 | Intellinet NFC-30IR Camera - Multiple Vulnerabilities | nfc-30ir firmware | 9.8 (v3.0) | Critical |
| CVE-2018-12031 | Eaton Intelligent Power Manager 1.6 - Directory Traversal | intelligent power manager | 9.8 (v3.0) | Critical |
| CVE-2018-1273 | Spring Data Commons - Remote Code Execution | spring data commons | 9.8 (v3.1) | Critical |
| CVE-2018-16283 | WordPress Plugin Wechat Broadcast 1.2.0 - Local File Inclusion | wechat brodcast | 9.8 (v3.0) | Critical |
| CVE-2018-16763 | FUEL CMS 1.4.1 - Remote Code Execution | fuel cms | 9.8 (v3.1) | Critical |
| CVE-2018-17246 | Kibana - Local File Inclusion | kibana | 9.8 (v3.0) | Critical |
| CVE-2018-18925 | Gogs (Go Git Service) 0.11.66 - Remote Code Execution | gogs | 9.8 (v3.0) | Critical |
| CVE-2019-12725 | Zeroshell 3.9.0 - Remote Command Execution | zeroshell | 9.8 (v3.0) | Critical |
| CVE-2019-15107 | Webmin <= 1.920 - Unauthenticated Remote Command Execution | webmin | 9.8 (v3.1) | Critical |
| CVE-2019-16662 | rConfig 3.9.2 - Remote Code Execution | rconfig | 9.8 (v3.1) | Critical |
| CVE-2019-16920 | D-Link Routers - Remote Code Execution | dir-655 firmware | 9.8 (v3.1) | Critical |
| CVE-2019-17270 | Yachtcontrol Webapplication 1.0 - Remote Command Injection | yachtcontrol | 9.8 (v3.1) | Critical |
| CVE-2019-7238 | Sonatype Nexus Repository Manager <3.15.0 - Remote Code Execution | nexus | 9.8 (v3.1) | Critical |
| CVE-2019-7256 | eMerge E3 1.00-06 - Remote Code Execution | linear emerge essential firmware | 9.8 (v3.1) | Critical |
| CVE-2019-9618 | WordPress GraceMedia Media Player 1.0 - Local File Inclusion | gracemedia media player | 9.8 (v3.0) | Critical |
| CVE-2020-11455 | LimeSurvey 4.1.11 - Local File Inclusion | limesurvey | 9.8 (v3.1) | Critical |
| CVE-2020-15568 | TerraMaster TOS <.1.29 - Remote Code Execution | tos | 9.8 (v3.1) | Critical |
| CVE-2020-15920 | Mida eFramework <=2.9.0 - Remote Command Execution | eframework | 9.8 (v3.1) | Critical |
| CVE-2020-17496 | vBulletin 5.5.4 - 5.6.2- Remote Command Execution | vbulletin | 9.8 (v3.1) | Critical |
| CVE-2020-17530 | Apache Struts 2.0.0-2.5.25 - Remote Code Execution | struts | 9.8 (v3.1) | Critical |
| CVE-2020-21224 | Inspur ClusterEngine 4.0 - Remote Code Execution | clusterengine | 9.8 (v3.1) | Critical |
| CVE-2020-29227 | Car Rental Management System 1.0 - Local File Inclusion | car rental management system | 9.8 (v3.1) | Critical |
| CVE-2020-29390 | Zeroshell 3.9.3 - Command Injection | zeroshell | 9.8 (v3.1) | Critical |
| CVE-2020-5902 | F5 BIG-IP TMUI - Remote Code Execution | big-ip access policy manager | 9.8 (v3.1) | Critical |
| CVE-2020-7209 | LinuxKI Toolset <= 6.01 - Remote Command Execution | linuxki | 9.8 (v3.1) | Critical |
| CVE-2020-7980 | Satellian Intellian Aptus Web <= 1.24 - Remote Command Execution | aptus web | 9.8 (v3.1) | Critical |
| CVE-2020-9054 | Zyxel NAS Firmware 5.21- Remote Code Execution | nas326 firmware | 9.8 (v3.1) | Critical |
| CVE-2021-28799 | QNAP HBS 3 - Broken Access Control | hybrid backup sync | 9.8 (v3.1) | Critical |
| CVE-2022-0679 | WordPress Narnoo Distributor <=2.5.1 - Local File Inclusion | narnoo distributor | 9.8 (v3.1) | Critical |
| CVE-2022-1390 | WordPress Admin Word Count Column 2.2 - Local File Inclusion | admin word count column | 9.8 (v3.1) | Critical |
| CVE-2022-1391 | WordPress Cab fare calculator < 1.0.4 - Local File Inclusion | cab fare calculator | 9.8 (v3.1) | Critical |
| CVE-2022-22954 | VMware Workspace ONE Access - Server-Side Template Injection | identity manager | 9.8 (v3.1) | Critical |
| CVE-2022-24086 | Adobe Commerce (Magento) - Remote Code Execution | commerce | 9.8 (v3.1) | Critical |
| CVE-2022-29303 | SolarView Compact 6.0 - OS Command Injection | sv-cpt-mc310 firmware | 9.8 (v3.1) | Critical |
| CVE-2022-31137 | Roxy-WI < 6.1.1.0 - Remote Code Execution | roxy-wi | 9.8 (v3.1) | Critical |
| CVE-2022-32409 | Portal do Software Publico Brasileiro i3geo 7.0.5 - Local File Inclusion | i3geo | 9.8 (v3.1) | Critical |
| CVE-2022-35914 | GLPI <=10.0.2 - Remote Command Execution | glpi | 9.8 (v3.1) | Critical |
| CVE-2022-36553 | Hytec Inter HWL-2511-SS - Remote Command Execution | hwl-2511-ss firmware | 9.8 (v3.1) | Critical |
| CVE-2022-36642 | Omnia MPX 1.5.0+r1 - Local File Inclusion | omnia mpx node firmware | 9.8 (v3.1) | Critical |
| CVE-2022-4060 | WordPress User Post Gallery <=2.19 - Remote Code Execution | user post gallery | 9.8 (v3.1) | Critical |
| CVE-2022-40881 | SolarView 6.00 - Remote Command Execution | solarview compact | 9.8 (v3.1) | Critical |
| CVE-2022-41840 | Welcart eCommerce <=2.7.7 - Local File Inclusion | welcart e-commerce | 9.8 (v3.1) | Critical |
| CVE-2022-47615 | LearnPress Plugin < 4.2.0 - Local File Inclusion | learnpress | 9.8 (v3.1) | Critical |
| CVE-2023-34960 | Chamilo Command Injection | chamilo | 9.8 (v3.1) | Critical |
| CVE-2023-3643 | CAREL Boss Mini <= 1.4.0 - Local File Inclusion | boss-mini | 9.8 (v3.1) | Critical |
| CVE-2023-36845 | Juniper J-Web - Remote Code Execution | junos | 9.8 (v3.1) | Critical |
| CVE-2023-45852 | Viessmann Vitogate 300 - Remote Code Execution | vitogate 300 firmware | 9.8 (v3.1) | Critical |
| CVE-2023-5991 | Hotel Booking Lite < 4.8.5 - Arbitrary File Download & Deletion | hotel booking lite | 9.8 (v3.1) | Critical |
| CVE-2023-6623 | Essential Blocks < 4.4.3 - Local File Inclusion | essential blocks | 9.8 (v3.1) | Critical |
| CVE-2024-12209 | WP Umbrella Update Backup Restore & Monitoring <= 2.17.0 - Local File Inclusion | wp-umbrella | 9.8 (v3.1) | Critical |
| CVE-2024-31823 | ecommerce-codeigniter-bootstrap Arbitrary Code Execution Vulnerability | ecommerce-codeigniter-bootstrap | 9.8 (v3.1) | Critical |
| CVE-2024-50603 | Aviatrix Controller - Remote Code Execution | controller | 9.8 (v3.1) | Critical |
| CVE-2024-53584 | OpenPanel 0.3.4 - OS Command Injection | openpanel | 9.8 (v3.1) | Critical |
| CVE-2024-5827 | Vanna - SQL injection | vanna-ai/vanna | 9.8 (v3.0) | Critical |
| CVE-2024-6460 | WordPress Grow by Tradedoubler Plugin < 2.0.22 - Unauthenticated Local File Inclusion | tradedoubler-affiliate-tracker | 9.8 (v3.1) | Critical |
| CVE-2024-9047 | WordPress File Upload <= 4.24.11 - Arbitrary File Read | wordpress file upload | 9.8 (v3.1) | Critical |
| CVE-2025-2294 | Kubio AI Page Builder <= 2.5.1 - Local File Inclusion | Kubio AI Page Builder | 9.8 (v3.1) | Critical |
| CVE-2025-29306 | FoxCMS v.1.2.5 - Remote Code Execution | foxcms | 9.8 (v3.1) | Critical |
| CVE-2025-3248 | Langflow AI - Unauthenticated Remote Code Execution | langflow | 9.8 (v3.1) | Critical |
| CVE-2025-4524 | WordPress Madara - Local File Inclusion | Madara – Responsive and modern WordPress theme for manga sites | 9.8 (v3.1) | Critical |
| CVE-2025-47445 | WordPress Eventin (Themewinter) ≤ 4.0.26 - Arbitrary File Download | eventin | 9.8 (v3.1) | Critical |
| CVE-2025-54123 | Hoverfly <= 1.11.3 - Remote Code Execution | hoverfly | 9.8 (v3.1) | Critical |
| CVE-2026-0770 | Langflow < 1.3.0 - Remote Code Execution via validate_code() exec() | langflow | 9.8 (v3.0) | Critical |
| CVE-2026-0926 | Prodigy Commerce <= 3.3.0 - Local File Inclusion | Prodigy Commerce | 9.8 (v3.1) | Critical |
| CVE-2026-12940 | Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoint | langflow | 9.8 (v3.1) | Critical |
| CVE-2026-15732 | WGDashboard Server-Side Request Forgery Vulnerability | WGDashboard | 9.8 (v3.1) | Critical |
| CVE-2026-15733 | WGDashboard <= 4.3.2 - Authenticated OS Command Injection /etc/passwd Read | WGDashboard | 9.8 (v3.1) | Critical |
| CVE-2026-18482 | neo-mjs Command Injection Vulnerability | neo-mjs | 9.8 (v3.1) | Critical |
| CVE-2026-30118 | scalar/astro v0.1.13 was discovered to Server-Side Request Forgery Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2026-31040 | stata-mcp Code Injection Vulnerability | stata-mcp | 9.8 (v3.1) | Critical |
| CVE-2026-3296 | Everest Forms <= 3.4.3 - Unauthenticated PHP Object Injection via Form Entry Metadata | Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder | 9.8 (v3.1) | Critical |
| CVE-2026-35048 | Piwigo RCE via PHP Code Injection into Config File in Installer | Piwigo | 9.8 (v3.1) | Critical |
| CVE-2026-35471 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs | goshs | 9.8 (v3.0) | Critical |
| CVE-2026-35847 | the CheckUils.php file Arbitrary Code Execution Vulnerability | the CheckUils.php file | 9.8 (v3.1) | Critical |
| CVE-2026-37281 | the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 Command Injection Vulnerability | the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 | 9.8 (v3.1) | Critical |
| CVE-2026-38428 | kestra SQL Injection Vulnerability | kestra | 9.8 (v3.1) | Critical |
| CVE-2026-38431 | erpnext Code Injection Vulnerability | erpnext | 9.8 (v3.1) | Critical |
| CVE-2026-39394 | CI4MS has an .env CRLF Injection via Unvalidated host Parameter in Install Controller | ci4ms | 9.8 (v3.1) | Critical |
| CVE-2026-45018 | Chainlit: Command injection via MCP stdio transport allows unauthenticated remote code execution | chainlit | 9.8 (v3.1) | Critical |
| CVE-2026-46562 | Yamcs: Remote Code Execution via Mission Database algorithm override | yamcs | 9.8 (v3.1) | Critical |
| CVE-2026-47391 | PraisonAI's unauthenticated A2A official example can reach real LLM-driven eval() tool execution | PraisonAI | 9.8 (v3.1) | Critical |
| CVE-2026-48687 | fastnetmon Command Injection Vulnerability | fastnetmon | 9.8 (v3.1) | Critical |
| CVE-2026-49819 | UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmd | UpSnap | 9.8 (v3.1) | Critical |
| CVE-2026-53545 | Termix: Remote Code Execution via Tunnel Disconnect pkill Command Injection | Termix | 9.8 (v3.1) | Critical |
| CVE-2026-55559 | Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstance) | yamcs | 9.8 (v3.1) | Critical |
| CVE-2026-67919 | Halo 2.25.4 Arbitrary Code Execution Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2026-67926 | JeecgBoot v.3.9.2 Arbitrary Code Execution Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2026-72592 | dulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP File Upload | phpfm | 9.8 (v3.1) | Critical |
| CVE-2026-75337 | Yu AI Code Mother v4.3 is vulnerable to path traversal Vulnerability | Yu AI Code Mother v4.3 is vulnerable to path traversal | 9.8 (v3.1) | Critical |
| CVE-2026-75411 | JeecgBoot v3.9.2 Code Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2026-75414 | In AntFlow V2.0.0, ActivitiTest.java Code Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2026-79408 | MetaGPT 0.8.1 Command Injection Vulnerability | MetaGPT 0.8.1 | 9.8 (v3.1) | Critical |
| CVE-2026-8037 | Progress ADC LoadMaster - Command Injection | connection manager for objectscale | 9.8 (v3.1) | Critical |
| CVE-2026-84372 | Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections | predis | 9.8 (v3.1) | Critical |
| CVE-2019-8982 | Wavemaker Studio 6.6 - Local File Inclusion/Server-Side Request Forgery | wavemarker studio | 9.6 (v3.0) | Critical |
| CVE-2026-12564 | Automation-controller: automation-controller: kubernetes service account token exfiltration via hashicorp vault credenti | Red Hat Ansible Automation Platform 2 | 9.6 (v3.1) | Critical |
| CVE-2026-12605 | glassfish Server-Side Request Forgery Vulnerability | glassfish | 9.6 (v3.1) | Critical |
| CVE-2026-34449 | SiYuan: Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injection | siyuan | 9.6 (v3.1) | Critical |
| CVE-2026-35906 | An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 OS Command Injection Vulnerability | - | 9.6 (v3.1) | Critical |
| CVE-2026-53513 | Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registration | better-auth/sso | 9.6 (v3.1) | Critical |
| CVE-2026-53649 | Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE | joro | 9.6 (v3.1) | Critical |
| CVE-2026-72878 | Dokploy: OS Command Injection in backup/restore pipeline via unescaped user-controlled shell arguments | dokploy | 9.6 (v3.1) | Critical |
| CVE-2026-70477 | Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability | flowise | 9.5 (v4.0) | Critical |
| CVE-2026-88062 | OmniRoute ACP Custom-Agent Remote Code Execution (RCE) | OmniRoute | 9.5 (v4.0) | Critical |
| CVE-2026-8986 | Command Injection via Malicious OCPP Server | maxicharger single charger firmware | 9.5 (v4.0) | Critical |
| CVE-2024-9264 | Grafana Post-Auth DuckDB - SQL Injection To File Read | grafana | 9.4 (v4.0) | Critical |
| CVE-2025-62593 | Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack | ray | 9.4 (v4.0) | Critical |
| CVE-2026-11419 | Path Traversal in Altium Enterprise Server Vault UploadController Allows Arbitrary File Write | on-prem enterprise server | 9.4 (v4.0) | Critical |
| CVE-2026-11423 | Path Traversal in Altium Enterprise Server Collaboration Service Allows Privilege Escalation | Altium Enterprise Server | 9.4 (v4.0) | Critical |
| CVE-2026-33324 | SQLBot prompt injection allows arbitrary SQL execution and remote code execution | sqlbot | 9.4 (v4.0) | Critical |
| CVE-2026-39932 | OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection | openemr | 9.4 (v4.0) | Critical |
| CVE-2026-45272 | MyBooks: Remote Code Execution via SOCIAL_AUTH Key Name Injection in Python Config File | talebook | 9.4 (v4.0) | Critical |
| CVE-2026-47670 | DbGate - Remote Code Execution via Dynamic Import Bypass | dbgate | 9.4 (v4.0) | Critical |
| CVE-2026-62668 | Grav API Plugin: Webhook SSRF via Unrestricted cURL Protocols | grav | 9.4 (v4.0) | Critical |
| CVE-2026-63732 | 9router before 0.4.60 Remote Code Execution via default password | 9router | 9.4 (v4.0) | Critical |
| CVE-2026-66398 | phpMyFAQ before 4.1.6 Remote Code Execution via Configuration API | phpMyFAQ | 9.4 (v4.0) | Critical |
| CVE-2026-69256 | Flowise: Remote Code Execution Vulnerability in CSVAgent | Flowise | 9.4 (v4.0) | Critical |
| CVE-2026-72850 | Budibase before 3.40.0 Arbitrary File Write via Path Traversal | server | 9.4 (v4.0) | Critical |
| CVE-2026-72879 | Dokploy: Command Injection via Registry Credentials in Swarm Upload | dokploy | 9.4 (v4.0) | Critical |
| CVE-2026-73041 | SiYuan before v3.7.4 Remote Code Execution via PDF Annotations | siyuan | 9.4 (v4.0) | Critical |
| CVE-2026-73042 | SiYuan before v3.7.4 Remote Code Execution via Menu Metadata | siyuan | 9.4 (v4.0) | Critical |
| CVE-2026-73483 | Flowise before 3.1.3 Sandbox Escape via Puppeteer | flowise | 9.4 (v4.0) | Critical |
| CVE-2026-77086 | SiYuan before v3.7.4 Path Traversal via packageName | siyuan | 9.4 (v4.0) | Critical |
| CVE-2026-82244 | Budibase before 3.41.3 Remote Code Execution via Plugin eval() | server | 9.4 (v4.0) | Critical |
| CVE-2026-86123 | SQL Chat Unauthenticated Database-Connection Proxy in the /api/connection Endpoints | sqlchat | 9.4 (v4.0) | Critical |
| CVE-2013-1965 | Apache Struts2 S2-012 RCE | struts | 9.3 (v2.0) | High |
| CVE-2018-25114 | osCommerce 2.3.4.1 - Remote Code Execution | Online Merchant | 9.3 (v4.0) | Critical |
| CVE-2018-25357 | Dolibarr ERP CRM 7.0.3 Remote Code Execution via install/step1.php | dolibarr erp/crm | 9.3 (v4.0) | Critical |
| CVE-2019-25687 | Pegasus CMS 1.0 Remote Code Execution via extra_fields.php | pegasus cms | 9.3 (v4.0) | Critical |
| CVE-2019-25727 | WordPress Plugin ad manager wd 1.0.11 Arbitrary File Download | Ad Manager WD | 9.3 (v4.0) | Critical |
| CVE-2024-27954 | WordPress Automatic Plugin <3.92.1 - Arbitrary File Download and SSRF | Automatic | 9.3 (v3.1) | Critical |
| CVE-2024-58348 | WordPress Background Image Cropper 1.2 Remote Code Execution | Background Image Cropper | 9.3 (v4.0) | Critical |
| CVE-2025-31114 | Fooocus webui vulnerable to Remote Code Execution | Fooocus | 9.3 (v4.0) | Critical |
| CVE-2026-19586 | Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gateways | er7212pc firmware | 9.3 (v4.0) | Critical |
| CVE-2026-23734 | XWiki Platform: Path traversal via resources parameter in ssx and jsx endpoints when using leading slash | xwiki-commons | 9.3 (v4.0) | Critical |
| CVE-2026-27174 | MajorDoMo - Unauthenticated RCE | majordomo | 9.3 (v4.0) | Critical |
| CVE-2026-34361 | HAPI FHIR: Unauthenticated SSRF via /loadIG Chains with startsWith() Credential Leak for Authentication Token Theft | hl7 fhir core | 9.3 (v3.1) | Critical |
| CVE-2026-41939 | Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly | Care Everywhere Gateway | 9.3 (v4.0) | Critical |
| CVE-2026-44343 | WGDashboard < 4.3.2 - Unauthenticated File Read | wgdashboard | 9.3 (v4.0) | Critical |
| CVE-2026-44402 | Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi | SNMP Web Pro | 9.3 (v4.0) | Critical |
| CVE-2026-45668 | Trilium Notes : Note Import to RCE via #docName Path Traversal (Safe Import Enabled) | Trilium | 9.3 (v4.0) | Critical |
| CVE-2026-47669 | DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCE | dbgate | 9.3 (v4.0) | Critical |
| CVE-2026-47754 | unauthenticated path traversal in Metacat 2.x | metacat | 9.3 (v3.1) | Critical |
| CVE-2026-53975 | OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/exec | OpenChamber | 9.3 (v4.0) | Critical |
| CVE-2026-53976 | OpenChamber <1.13.0 - Unauthenticated Arbitrary File Read | OpenChamber | 9.3 (v4.0) | Critical |
| CVE-2026-60121 | Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via ping.php | flamingo | 9.3 (v4.0) | Critical |
| CVE-2026-61498 | Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via gen_graphs.php | flamingo | 9.3 (v4.0) | Critical |
| CVE-2026-61511 | vBulletin 6.x - Remote Code Execution | vBulletin | 9.3 (v4.0) | Critical |
| CVE-2026-63766 | GPT-SoVITS 20250606v2pro OS Command Injection via webui.py | GPT-SoVITS | 9.3 (v4.0) | Critical |
| CVE-2026-64625 | AVideo before 29.0 OS Command Injection via execAsync | AVideo | 9.3 (v4.0) | Critical |
| CVE-2026-64824 | Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore | Home Assistant Core | 9.3 (v4.0) | Critical |
| CVE-2026-64849 | MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirect | mlflow | 9.3 (v3.1) | Critical |
| CVE-2026-65008 | Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData | grav | 9.3 (v4.0) | Critical |
| CVE-2026-65700 | h2oGPT 0.2.1 Path Traversal via OpenAI-compatible Files API | h2ogpt | 9.3 (v4.0) | Critical |
| CVE-2026-65701 | SoftVC VITS Singing Voice Conversion Path Traversal via /wav2wav Flask Route | so-vits-svc | 9.3 (v4.0) | Critical |
| CVE-2026-66794 | Cluster-proxy-addon: cluster-proxy-addon: unauthenticated ssrf to arbitrary managed-cluster services via public route | multicluster engine for Kubernetes 2.1 | 9.3 (v3.1) | Critical |
| CVE-2026-67308 | Wazuh GitHub Actions Shell Injection via Fork Pull Request | wazuh | 9.3 (v4.0) | Critical |
| CVE-2026-67426 | Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration | flyto-core | 9.3 (v3.1) | Critical |
| CVE-2026-69110 | OpenCode Studio < 2.4.4 Unauthenticated File Read via /api/tmp and /api/music | opencode-studio | 9.3 (v4.0) | Critical |
| CVE-2026-70553 | MaxSite CMS Unauthenticated RCE via Install Endpoint | MaxSite CMS | 9.3 (v4.0) | Critical |
| CVE-2026-71921 | DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection via setget.cgi | VigorSwitch G2540xs | 9.3 (v4.0) | Critical |
| CVE-2026-71944 | D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeQuectel | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71945 | D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeFibocom | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71946 | D-Link DWR-M961 Command Injection via /boafrm/formPingDiagnosticRun | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71947 | D-Link DWR-M961 Command Injection via /boafrm/formTracerouteDiagnosticRun | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71948 | D-Link DWR-M961 Command Injection via /boafrm/formDebugDiagnosticRun | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71949 | D-Link DWR-M961 Command Injection via /boafrm/formUSSDSetup | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71950 | D-Link DWR-M961 Command Injection via /boafrm/formSmsManage | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71951 | D-Link DWR-M961 Command Injection via /boafrm/formIMEISetup | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71952 | D-Link DWR-M961 Command Injection via /boafrm/formPinManageSetup | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71953 | D-Link DWR-M961 Command Injection via /boafrm/formNtp | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71954 | D-Link DWR-M961 Command Injection via /boafrm/formL2tpv3ConfigSetup | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71955 | D-Link DWR-M961 Command Injection via /boafrm/formWsc | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71956 | D-Link DWR-M961 Command Injection via app.cgi | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71984 | MSI Radix AXE6600 v781521 Command Injection via urlfilter | Radix AXE6600 | 9.3 (v4.0) | Critical |
| CVE-2026-71992 | MSI Radix AXE6600 v781521 Command Injection via macfilter | Radix AXE6600 | 9.3 (v4.0) | Critical |
| CVE-2026-72710 | SPIP < 4.4.18 Remote Code Execution via editer_objet.php Job Queue Injection | SPIP | 9.3 (v4.0) | Critical |
| CVE-2026-74798 | SiYuan kernel Path Traversal via database_clean MCP tool | siyuan | 9.3 (v4.0) | Critical |
| CVE-2026-76070 | Netis NC63 V3.0.0.3327 Stack Buffer Overflow via Login Password Parameter | NC63 | 9.3 (v4.0) | Critical |
| CVE-2026-76071 | Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost Parameter | NC63 | 9.3 (v4.0) | Critical |
| CVE-2026-80104 | DB-GPT 0.8.0 Path Traversal Arbitrary File Write via Skill Upload Filename | DB-GPT | 9.3 (v4.0) | Critical |
| CVE-2026-86189 | WWBN AVideo Unauthenticated Path Traversal via notify.ffmpeg.json.php | AVideo | 9.3 (v4.0) | Critical |
| CVE-2023-7305 | SmartBI RMIServlet Unrestricted File Upload RCE | SmartBI | 9.2 (v4.0) | Critical |
| CVE-2026-26217 | Crawl4AI < 0.8.0 - Local File Inclusion | crawl4ai | 9.2 (v4.0) | Critical |
| CVE-2026-63304 | AVideo through 29.0 OS Command Injection via listFFmpegProcesses | AVideo | 9.2 (v4.0) | Critical |
| CVE-2026-63305 | AVideo through 29.0 OS Command Injection via ffmpeg.json.php | AVideo | 9.2 (v4.0) | Critical |
| CVE-2026-65057 | Keep Unauthenticated Server-Side Request Forgery via POST /providers/healthcheck | keep | 9.2 (v4.0) | Critical |
| CVE-2026-65317 | Verba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware Bypass | Verba | 9.2 (v4.0) | Critical |
| CVE-2026-65318 | Verba (goldenverba) Unauthenticated Server-Side Request Forgery via WebSocket Import Endpoint HTMLReader | Verba | 9.2 (v4.0) | Critical |
| CVE-2026-65760 | Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0 | Easy Store extension for Joomla | 9.2 (v4.0) | Critical |
| CVE-2026-80138 | ClipBucket V5 5.5.1 through 5.5.3-#153 OS Command Injection via Installer php_cli_filepath Parameter | clipbucket-v5 | 9.2 (v4.0) | Critical |
| CVE-2026-85614 | OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checker | openpanel | 9.2 (v4.0) | Critical |
| CVE-2026-86119 | Webstudio through 0.296.0 SSRF via /cgi proxy routes | webstudio | 9.2 (v4.0) | Critical |
| CVE-2018-14916 | Loytec LGATE-902 <6.4.2 - Local File Inclusion | lgate-902 | 9.1 (v3.0) | Critical |
| CVE-2018-16716 | NCBI ToolBox - Directory Traversal | ncbi toolbox | 9.1 (v3.0) | Critical |
| CVE-2018-19365 | Wowza Streaming Engine Manager 4.7.4.01 - Directory Traversal | streaming engine | 9.1 (v3.1) | Critical |
| CVE-2021-28918 | Netmask NPM Package - Server-Side Request Forgery | netmask | 9.1 (v3.1) | Critical |
| CVE-2022-26960 | elFinder <=2.1.60 - Local File Inclusion | elfinder | 9.1 (v3.1) | Critical |
| CVE-2024-3673 | Web Directory Free < 1.7.3 - Local File Inclusion | web directory free | 9.1 (v3.1) | Critical |
| CVE-2024-40422 | Devika v1 - Path Traversal | devika | 9.1 (v3.1) | Critical |
| CVE-2025-55526 | n8n workflow collection Path Traversal Vulnerability | n8n workflow collection | 9.1 (v3.1) | Critical |
| CVE-2026-13147 | WordPress Kirki < 6.0.12 - Server-Side Request Forgery | kirki | 9.1 (v3.1) | Critical |
| CVE-2026-17552 | Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concaten | Plack::App::Prerender | 9.1 (v3.1) | Critical |
| CVE-2026-34745 | Unauthenticated Path Traversal Arbitrary File Write in /api/uploadChunked/public | fireshare | 9.1 (v3.1) | Critical |
| CVE-2026-44313 | LinkWarden: Server-Side Request Forgery (SSRF) in Link Creation via fetchTitleAndHeaders Function | linkwarden | 9.1 (v3.1) | Critical |
| CVE-2026-46621 | Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection | yamcs | 9.1 (v3.1) | Critical |
| CVE-2026-47731 | NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by u | AIT-Core | 9.1 (v3.1) | Critical |
| CVE-2026-48024 | Wazuh: merged-file header path traversal in cluster sync allows arbitrary file write under WAZUH_PATH in Wazuh manager | wazuh | 9.1 (v3.1) | Critical |
| CVE-2026-48162 | Wazuh: cluster peer can read arbitrary master files and forge offline REST API administrator tokens via DAPI tmp_file pa | wazuh | 9.1 (v3.1) | Critical |
| CVE-2026-51152 | Server-Side Request Forgery | - | 9.1 (v3.1) | Critical |
| CVE-2026-52610 | reportico-web <= 8.1.0 Path Traversal Vulnerability | reportico-web <= 8.1.0 | 9.1 (v3.1) | Critical |
| CVE-2026-55511 | Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs executeSql | yamcs | 9.1 (v3.1) | Critical |
| CVE-2026-57499 | Liman: OS Command Injection in LogRotationController allows authenticated admin to execute arbitrary commands (RCE) | core | 9.1 (v3.1) | Critical |
| CVE-2026-58400 | GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configuration in formatter | core-geonetwork | 9.1 (v3.1) | Critical |
| CVE-2026-75332 | Zyplayer-Doc <=1.0.0 Server-Side Request Forgery Vulnerability | - | 9.1 (v3.1) | Critical |
| CVE-2026-8713 | Avada (Fusion) Builder <= 3.15.3 - Unauthenticated Arbitrary File Deletion | fusion-builder | 9.1 (v3.1) | Critical |
| CVE-2008-4668 | Joomla! Image Browser 0.1.5 rc2 - Local File Inclusion | com imagebrowser | 9.0 (v2.0) | High |
| CVE-2013-5758 | Yealink VoIP Phone SIP-T38G - Privilege Escalation | sip-t38g | 9.0 (v2.0) | High |
| CVE-2026-34612 | Kestra: Remote Code Execution via SQL Injection | kestra | 9.0 (v3.1) | Critical |
| CVE-2026-45630 | Dokploy: Authenticated Remote Code Execution via Command Injection in updateTraefikConfig Echo Statement | dokploy | 9.0 (v3.1) | Critical |
| CVE-2026-53581 | ntp: write path traversal | core | 9.0 (v3.1) | Critical |
| CVE-2026-62674 | Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE | omnigent | 9.0 (v3.1) | Critical |
| CVE-2026-69251 | Flowise RCE via TypeORM DataSource | Flowise | 9.0 (v4.0) | Critical |
| CVE-2026-73485 | Flowise before 3.1.3 Remote Code Execution via Airtable Agent | flowise | 9.0 (v4.0) | Critical |
| CVE-2026-73486 | Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV | flowise | 9.0 (v4.0) | Critical |
| CVE-2026-73487 | Flowise before 3.1.3 Prompt Injection RCE via CSV Agent | flowise | 9.0 (v4.0) | Critical |
| CVE-2026-86259 | OpenMAIC before 1.0.1 SSRF via Environment-Gated URL Validation | OpenMAIC | 9.0 (v4.0) | Critical |
| CVE-2026-43945 | FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection | FUXA | 8.9 (v4.0) | High |
| CVE-2026-7202 | Totolink A8000RU CGI cstecgi.cgi setWiFiWpsStart os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-7203 | Totolink A8000RU CGI cstecgi.cgi setUrlFilterRules os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-7204 | Totolink A8000RU CGI cstecgi.cgi setPptpServerCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-73570 | zimbra collaboration suite Arbitrary Code Execution Vulnerability | zimbra collaboration suite | 8.9 (v3.1) | High |
| CVE-2026-82866 | @pdfme/common before 5.5.10 SSRF via Unvalidated URL Fetch | common | 8.9 (v4.0) | High |
| CVE-2026-9384 | Totolink A8000RU Web Management cstecgi.cgi setDiagnosisCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9385 | Totolink A8000RU Web Management cstecgi.cgi setTracerouteCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9386 | Totolink A8000RU Web Management cstecgi.cgi setLanguageCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9387 | Totolink A8000RU Web Management cstecgi.cgi setUpgradeFW os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9388 | Totolink A8000RU Web Management cstecgi.cgi setScheduleCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9404 | Totolink A8000RU Web Management cstecgi.cgi setDdnsCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9405 | Totolink A8000RU Web Management cstecgi.cgi setGameSpeedCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9406 | Totolink A8000RU Web Management cstecgi.cgi setRemoteCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9407 | Totolink A8000RU Web Management cstecgi.cgi setFirewallType os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9408 | Totolink A8000RU Web Management cstecgi.cgi setStaticDhcpRules os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9432 | Totolink A8000RU Web Management cstecgi.cgi setWiFiAdvancedCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9433 | Totolink A8000RU Web Management cstecgi.cgi setMacFilterRules os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9434 | Totolink A8000RU Web Management cstecgi.cgi setWiFiWpsCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9435 | Totolink A8000RU Web Management cstecgi.cgi setQosCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9436 | Totolink A8000RU Web Management cstecgi.cgi setL2tpServerCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9454 | Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCertGenerationCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9455 | Totolink A8000RU Web Management cstecgi.cgi UploadOpenVpnCert os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9456 | Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9457 | Totolink A8000RU Web Management cstecgi.cgi UploadFirmwareFile os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9458 | Totolink A8000RU Web Management cstecgi.cgi setWanCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9476 | Totolink A8000RU Web Management cstecgi.cgi setPasswordCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9477 | Totolink A8000RU Web Management cstecgi.cgi setAccessDeviceCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9478 | Totolink A8000RU Web Management cstecgi.cgi setParentalRules os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2013-4863 | MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities | veralite firmware | 8.8 (v3.1) | High |
| CVE-2016-4808 | Web2py 2.14.5 - Multiple Vulnerabilities | web2py | 8.8 (v3.0) | High |
| CVE-2017-14535 | Trixbox - 2.8.0.4 OS Command Injection | trixbox | 8.8 (v3.1) | High |
| CVE-2017-6884 | Zyxel_ EMG2926 < V1.00(AAQT.4)b8 - OS Command Injection | emg2926 firmware | 8.8 (v3.1) | High |
| CVE-2018-10093 | AudioCodes 420HD - Remote Code Execution | 420hd ip phone firmware | 8.8 (v3.0) | High |
| CVE-2018-12613 | PhpMyAdmin <4.8.2 - Local File Inclusion | phpmyadmin | 8.8 (v3.1) | High |
| CVE-2018-15142 | OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions | openemr | 8.8 (v3.0) | High |
| CVE-2019-14530 | OpenEMR <5.0.2 - Local File Inclusion | openemr | 8.8 (v3.1) | High |
| CVE-2019-9189 | Prima Access Control 2.3.35 - Arbitrary File Upload | flexair | 8.8 (v3.0) | High |
| CVE-2020-13851 | Artica Pandora FMS 7.44 - Remote Code Execution | pandora fms | 8.8 (v3.1) | High |
| CVE-2020-24579 | D-Link DSL 2888a - Authentication Bypass/Remote Command Execution | dsl2888a firmware | 8.8 (v3.1) | High |
| CVE-2020-8163 | Ruby on Rails <5.0.1 - Remote Code Execution | rails | 8.8 (v3.1) | High |
| CVE-2020-8641 | Lotus Core CMS 1.0.1 - Local File Inclusion | lotus core cms | 8.8 (v3.1) | High |
| CVE-2021-25646 | Apache Druid - Remote Code Execution | druid | 8.8 (v3.1) | High |
| CVE-2023-39108 | rConfig 3.9.4 - Server-Side Request Forgery | rconfig | 8.8 (v3.1) | High |
| CVE-2023-39109 | rConfig 3.9.4 - Server-Side Request Forgery | rconfig | 8.8 (v3.1) | High |
| CVE-2023-39110 | rConfig 3.9.4 - Server-Side Request Forgery | rconfig | 8.8 (v3.1) | High |
| CVE-2024-39024 | In Packetfence 13.2.0, the WebGui interface setting Arbitrary Code Execution Vulnerability | - | 8.8 (v3.1) | High |
| CVE-2024-41667 | OpenAM<=15.0.3 FreeMarker - Template Injection | OpenAM | 8.8 (v3.1) | High |
| CVE-2024-8252 | WordPress Clean Login <= 1.14.5 Authenticated (Contributor+) - Local File Inclusion | clean login | 8.8 (v3.1) | High |
| CVE-2025-32614 | EventON Lite <= 2.4 - Authenticated Local File Inclusion | flavor | 8.8 (v3.1) | High |
| CVE-2025-59710 | biztalk360 Arbitrary Code Execution Vulnerability | biztalk360 | 8.8 (v3.1) | High |
| CVE-2026-17623 | Langflow is affected OS Command Injection in Model Context Protocol features | langflow | 8.8 (v3.1) | High |
| CVE-2026-17625 | Langflow is affected by OS Command Injection in Model Context Protocol features | langflow | 8.8 (v3.1) | High |
| CVE-2026-24893 | openITCOCKPIT has Authenticated Command Injection Leading to Remote Code Execution via Host Address Macro Expansion | openitcockpit | 8.8 (v3.1) | High |
| CVE-2026-26899 | OS Command Injection | - | 8.8 (v3.1) | High |
| CVE-2026-34197 | Apache ActiveMQ - Remote Code Execution | activemq | 8.8 (v3.1) | High |
| CVE-2026-34524 | SillyTavern: Path traversal in /api/chats/export and /api/chats/delete allows arbitrary file read/delete within user | sillytavern | 8.8 (v3.1) | High |
| CVE-2026-35031 | Jellyfin: Potential RCE via subtitle upload path traversal + .strm chain | jellyfin | 8.8 (v3.1) | High |
| CVE-2026-35196 | Chamilo LMS has OS Command Injection via export_all_certificates action | chamilo lms | 8.8 (v3.1) | High |
| CVE-2026-36723 | bookcars v8.3 Arbitrary Code Execution Vulnerability | bookcars v8.3 | 8.8 (v3.1) | High |
| CVE-2026-42605 | AzuraCast: Path Traversal in currentDirectory Parameter Enables Remote Code Execution via Media Upload | azuracast | 8.8 (v3.1) | High |
| CVE-2026-43624 | F5-TTS 1.1.20 Path Traversal via finetune_gradio.py create_data_project() | F5-TTS | 8.8 (v4.0) | High |
| CVE-2026-44829 | Gotenberg: Path traversal in zip entry name via Windows-style separators in upload filename | gotenberg | 8.8 (v3.1) | High |
| CVE-2026-45505 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia addNetworkConnector Discovery Wrapper Bypass | activemq | 8.8 (v3.1) | High |
| CVE-2026-45578 | WWBN AVideo Live: OS command injection in on_publish.php execAsync via unescaped m3u8 URL | avideo | 8.8 (v3.1) | High |
| CVE-2026-45662 | Dokploy: Command Injection via incomplete shell escaping in docker logout (registry deletion) | dokploy | 8.8 (v3.1) | High |
| CVE-2026-48017 | DbGate: Remote Code Execution via functionName injection in loadReader endpoint | dbgate | 8.8 (v3.1) | High |
| CVE-2026-50186 | 4gaBoards: Path Traversal leading to Arbitrary File Read and Deletion in Board Export | 4gaBoards | 8.8 (v3.1) | High |
| CVE-2026-55585 | QWED: Authenticated Remote Code Execution via Unsafe SymPy parse_expr() | qwed-verification | 8.8 (v3.1) | High |
| CVE-2026-58195 | Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into ex | agentic-flow | 8.8 (v3.1) | High |
| CVE-2026-62675 | Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools | omnigent | 8.8 (v3.1) | High |
| CVE-2026-62677 | Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUN | omnigent | 8.8 (v3.1) | High |
| CVE-2026-62857 | Fedify: Server-Side Request Forgery in getNodeInfo() Allows Access to Internal Network Resources | fedify | 8.8 (v4.0) | High |
| CVE-2026-65702 | Vanna 2.0.2 Path Traversal via FileSystemConversationStore | vanna | 8.8 (v4.0) | High |
| CVE-2026-72875 | Dokploy: Remote Code Execution (RCE) via Command Injection in settings.readTraefikFile | dokploy | 8.8 (v3.1) | High |
| CVE-2026-73222 | Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (–studio) | claude-code-templates | 8.8 (v3.1) | High |
| CVE-2026-76842 | Mercado Pago Node.js SDK through 3.4.0 Path Injection via Unencoded Identifiers in Payment Clients | mercadopago | 8.8 (v4.0) | High |
| CVE-2026-78834 | Code Injection | - | 8.8 (v3.1) | High |
| CVE-2026-79423 | seacms v13.6 Arbitrary Code Execution Vulnerability | seacms v13.6 | 8.8 (v3.1) | High |
| CVE-2026-81730 | Dolibarr 9.0.0 through 23.0.4 Path Traversal via EmailCollector Attachment Filename | dolibarr erp/crm | 8.8 (v4.0) | High |
| CVE-2026-82217 | Eclipse Theia Path Traversal Vulnerability | Eclipse Theia | 8.8 (v3.1) | High |
| CVE-2026-82286 | gpt-crawler Arbitrary File Write via outputFileName Parameter | gpt-crawler | 8.8 (v4.0) | High |
| CVE-2026-84889 | A path traversal vulnerability in file handling components could allow an authenticated attacker to write files to arbit | Langflow OSS | 8.8 (v3.1) | High |
| CVE-2026-85199 | Eclipse aeriOS Path Traversal Vulnerability | Eclipse aeriOS | 8.8 (v4.0) | High |
| CVE-2026-86542 | knowns before 0.30.0 Path Traversal via Import Name | knowns | 8.8 (v4.0) | High |
| CVE-2026-86775 | knowns before 0.30.0 Path Traversal via Document API | knowns | 8.8 (v4.0) | High |
| CVE-2026-87927 | MaxSite CMS through 109.6 Local File Inclusion via ajax dispatcher | MaxSite CMS | 8.8 (v4.0) | High |
| CVE-2017-20248 | WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File Download | Apptha Slider Gallery | 8.7 (v4.0) | High |
| CVE-2017-20250 | WordPress Plugin Mac Photo Gallery 3.0 Arbitrary File Download | Mac Photo Gallery | 8.7 (v4.0) | High |
| CVE-2018-25374 | Softneta MedDream PACS Server Premium 6.7.1.1 Directory Traversal | MedDream PACS Server Premium | 8.7 (v4.0) | High |
| CVE-2019-25671 | VA MAX 8.3.4 Remote Code Execution via changeip.php | VA MAX | 8.7 (v4.0) | High |
| CVE-2021-4463 | Longjing Technology BEMS API 1.21 - Unauthenticated Arbitrary File Download | BEMS API | 8.7 (v4.0) | High |
| CVE-2021-47938 | ImpressCMS 1.4.2 Remote Code Execution via Autotasks | ImpressCMS | 8.7 (v4.0) | High |
| CVE-2021-47943 | TextPattern CMS 4.8.7 Remote Code Execution via File Upload | TextPattern CMS | 8.7 (v4.0) | High |
| CVE-2022-50944 | Aero CMS 0.0.1 PHP Code Injection via posts.php | Aero CMS | 8.7 (v4.0) | High |
| CVE-2023-54350 | WordPress Augmented-Reality Plugin Remote Code Execution Unauthenticated | Augmented Reality | 8.7 (v4.0) | High |
| CVE-2024-26291 | Avid NEXIS Agent - Arbitrary File Read | nexis | 8.7 (v4.0) | High |
| CVE-2025-30007 | HestiaCP < 1.9.5 Authenticated OS Command Injection via DNS Record Management | control panel | 8.7 (v4.0) | High |
| CVE-2025-34031 | Moodle Jmol Filter 6.1 - Local File Inclusion | jmol | 8.7 (v4.0) | High |
| CVE-2025-34045 | WeiPHP 5.0 - Path Traversal | weiphp | 8.7 (v4.0) | High |
| CVE-2025-34115 | OP5 Monitor <= 7.1.9 Authenticated Command Execution via command_test.php | OP5 Monitor | 8.7 (v4.0) | High |
| CVE-2026-10108 | xiaomusic 0.5.7 Path Traversal via GET /music endpoint | xiaomusic | 8.7 (v4.0) | High |
| CVE-2026-17524 | zip-lib Path Traversal Vulnerability | zip-lib | 8.7 (v4.0) | High |
| CVE-2026-25559 | OpenBullet2 0.3.2 Path Traversal via Wordlist Endpoint | openbullet2 | 8.7 (v4.0) | High |
| CVE-2026-25855 | OpenBullet2 0.3.2 Authenticated RCE via FileProxySource Script Upload | openbullet2 | 8.7 (v4.0) | High |
| CVE-2026-25856 | OpenBullet2 0.3.2 Authenticated RCE via Job Configuration Interface | openbullet2 | 8.7 (v4.0) | High |
| CVE-2026-28797 | RAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" Compone | ragflow | 8.7 (v4.0) | High |
| CVE-2026-34228 | Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File Write | emlog | 8.7 (v4.0) | High |
| CVE-2026-34367 | InvoiceShelf: SSRF in Invoice PDF Rendering via Unsanitised HTML in Notes Field | invoiceshelf | 8.7 (v3.1) | High |
| CVE-2026-34735 | Hytale Modding Vulnerable to Remote Code Execution via File Upload Bypass in FileController | wiki | 8.7 (v4.0) | High |
| CVE-2026-34792 | Endian Firewall /cgi-bin/logs_clamav.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-34793 | Endian Firewall /cgi-bin/logs_firewall.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-34794 | Endian Firewall /cgi-bin/logs_ids.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-34795 | Endian Firewall /cgi-bin/logs_log.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-34796 | Endian Firewall /cgi-bin/logs_openvpn.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-34797 | Endian Firewall /cgi-bin/logs_smtp.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-35029 | LiteLLM - Arbitrary File Read | litellm | 8.7 (v4.0) | High |
| CVE-2026-35214 | Budibase: Path traversal in plugin file upload enables arbitrary directory deletion and file write | budibase | 8.7 (v3.1) | High |
| CVE-2026-39352 | Frappe Framework < 16.15.0 - Arbitrary File Read via render_include Path Traversal | frappe | 8.7 (v4.0) | High |
| CVE-2026-43982 | Algernon: Path traversal file write via savein() | algernon | 8.7 (v4.0) | High |
| CVE-2026-46746 | sinec ins OS Command Injection Vulnerability | sinec ins | 8.7 (v4.0) | High |
| CVE-2026-47394 | PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate | PraisonAI | 8.7 (v4.0) | High |
| CVE-2026-47659 | Pathling has path traversal in $import-pnp manifest that enables read-capable SSRF via /jobs/{jobId}/{filename} | pathling | 8.7 (v4.0) | High |
| CVE-2026-47661 | Pathling has path traversal in $result endpoint that allows arbitrary warehouse file read | pathling | 8.7 (v4.0) | High |
| CVE-2026-49143 | BrowserStack Runner 0.9.5 Unauthenticated RCE via /_log HTTP Handler | browserstack-runner | 8.7 (v4.0) | High |
| CVE-2026-55245 | Bifrost: SSRF deny-list incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL | bifrost | 8.7 (v4.0) | High |
| CVE-2026-57863 | Crater Invoice 6.0.6 Path Traversal RCE via update/unzip endpoint | crater | 8.7 (v4.0) | High |
| CVE-2026-62865 | TypeBot: Arbitrary server file read via Send Email block attachment path | typebot.io | 8.7 (v4.0) | High |
| CVE-2026-63722 | ICEcoder 8.1 Unauthenticated RCE via terminal-xhr.php | ICEcoder | 8.7 (v4.0) | High |
| CVE-2026-64837 | ICEcoder through 8.1 OS Command Injection via lib/properties.php | ICEcoder | 8.7 (v4.0) | High |
| CVE-2026-64838 | ICEcoder through 8.1 Path Traversal via oldFileName Parameter | ICEcoder | 8.7 (v4.0) | High |
| CVE-2026-64850 | Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData() | grav | 8.7 (v4.0) | High |
| CVE-2026-65694 | Microweber CMS <= 2.0.20 - Unauthenticated Arbitrary File Read | microweber | 8.7 (v4.0) | High |
| CVE-2026-65759 | Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 | Easy Store extension for Joomla | 8.7 (v4.0) | High |
| CVE-2026-65919 | Meshery < 1.0.57 Unauthenticated Arbitrary File Read via fileView and fileDownload | meshery | 8.7 (v4.0) | High |
| CVE-2026-67200 | Perspective 5.0.0 Path Traversal via cwd_static_file_handler | perspective | 8.7 (v4.0) | High |
| CVE-2026-67206 | Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload | wolfcms | 8.7 (v4.0) | High |
| CVE-2026-67281 | Unauthenticated file read in Mikrotik RouterOS | RouterOS | 8.7 (v4.0) | High |
| CVE-2026-69089 | Grav CMS before 2.0.11 Path Traversal via watermark | grav | 8.7 (v4.0) | High |
| CVE-2026-69095 | OpenWrt luci-app-bmx7 Path Traversal via bmx7-info | luci | 8.7 (v4.0) | High |
| CVE-2026-69096 | OpenWrt luci-app-dockerman Read ACL Remote Code Execution | luci | 8.7 (v4.0) | High |
| CVE-2026-69100 | LAMP 5.6.2 GlueFactory Unsandboxed Groovy Script Remote Code Execution | lamp-cloud | 8.7 (v4.0) | High |
| CVE-2026-71966 | CyberPanel 2.4.3 Authenticated Command Injection via starRemoteTransfer | cyberpanel | 8.7 (v4.0) | High |
| CVE-2026-72713 | XAgent Path Traversal Arbitrary File Read via /workspace/file | XAgent | 8.7 (v4.0) | High |
| CVE-2026-72819 | Grav CMS before 2.0.13 Remote Code Execution via ZIP Upload | grav | 8.7 (v4.0) | High |
| CVE-2026-72830 | Grav API Plugin before 1.0.13 RCE via ConfigController scope bypass | grav | 8.7 (v4.0) | High |
| CVE-2026-72870 | Dokploy: Command Injection via Docker Credentials in buildRemoteDocker | dokploy | 8.7 (v4.0) | High |
| CVE-2026-72874 | Dokploy: Command Injection via Unescaped Git URL in Clone Commands | dokploy | 8.7 (v4.0) | High |
| CVE-2026-73680 | Cockpit CMS 2.14.0 Authenticated Command Injection via FFmpeg Filename | Cockpit CMS | 8.7 (v4.0) | High |
| CVE-2026-75111 | Evidently UI Path Traversal via Dataset Materialization Filename | evidently | 8.7 (v4.0) | High |
| CVE-2026-75482 | SWE-agent Trajectory Inspector Path Traversal File Disclosure | SWE-agent | 8.7 (v4.0) | High |
| CVE-2026-75914 | CodeWhale before 0.8.64 Path Traversal via image_analyze symlink | CodeWhale | 8.7 (v4.0) | High |
| CVE-2026-76060 | OS Command Injection in PayRange API | Zoneminder | 8.7 (v4.0) | High |
| CVE-2026-76836 | AzuraCast through 0.23.8 Liquidsoap Configuration Write via Profile Edit Serialization Group Bypass | AzuraCast | 8.7 (v4.0) | High |
| CVE-2026-78416 | Authenticated RCE via condition.config JSON cleanse bypass | cms | 8.7 (v4.0) | High |
| CVE-2026-79756 | Nuclio: Unauthenticated OS command injection via namespace header in list-all resource path on local platform | nuclio | 8.7 (v4.0) | High |
| CVE-2026-79987 | Low-privilege RCE through element-search eager loading | cms | 8.7 (v4.0) | High |
| CVE-2026-82270 | Portkey AI Gateway Server-Side Request Forgery via /v1/proxy/* | gateway | 8.7 (v4.0) | High |
| CVE-2026-82278 | BISHENG Authenticated Arbitrary Python Code Execution via Workflow run_once | bisheng | 8.7 (v4.0) | High |
| CVE-2026-82638 | jina-ai reader Server-Side Request Forgery via disabled private-address guard | reader | 8.7 (v4.0) | High |
| CVE-2026-85608 | Douyin_TikTok_Download_API 4.1.2 SSRF via url parameter | Douyin TikTok Download API | 8.7 (v4.0) | High |
| CVE-2026-85610 | OpenPanel before 2.3.0 Remote Code Execution via chart formulas | openpanel | 8.7 (v4.0) | High |
| CVE-2026-85612 | OpenPanel before 2.3.0 SSRF via favicon and og endpoints | openpanel | 8.7 (v4.0) | High |
| CVE-2026-85666 | ogx 1.3.1 Server-Side Request Forgery via MCP tool server_url | ogx | 8.7 (v4.0) | High |
| CVE-2026-85673 | LLaMA-Factory SSRF Guard Bypass via Redirect and DNS Rebinding | LlamaFactory | 8.7 (v4.0) | High |
| CVE-2026-85685 | AgentScope through 2.0.7.post1 Arbitrary Directory Copy via add_skill | agentscope | 8.7 (v4.0) | High |
| CVE-2026-85691 | MegaParse 0.0.55 Server-Side Request Forgery via POST /v1/url | megaparse | 8.7 (v4.0) | High |
| CVE-2026-86538 | knowns before 0.30.0 Path Traversal via templateFile parameter | knowns | 8.7 (v4.0) | High |
| CVE-2026-86732 | Craft CMS before 5.10.12 Remote Code Execution via element-index | cms | 8.7 (v4.0) | High |
| CVE-2026-89250 | WWBN AVideo Unauthenticated File Read via getRecordedFile.php | AVideo | 8.7 (v4.0) | High |
| CVE-2026-9506 | Path Traversal Vulnerability in Bagisto | Bagisto | 8.7 (v4.0) | High |
| CVE-2015-4694 | WordPress Zip Attachments <= 1.1.4 - Arbitrary File Retrieval | zip attachments | 8.6 (v3.0) | High |
| CVE-2021-32820 | Express-handlebars - Local File Inclusion | express handlebars | 8.6 (v3.1) | High |
| CVE-2022-24900 | Piano LED Visualizer 1.3 - Local File Inclusion | piano led visualizer | 8.6 (v3.1) | High |
| CVE-2023-26360 | Adobe ColdFusion - Local File Read | coldfusion | 8.6 (v3.1) | High |
| CVE-2024-20353 | adaptive security appliance software Denial of Service Vulnerability | adaptive security appliance software | 8.6 (v3.1) | High |
| CVE-2024-34470 | HSC Mailinspector 5.2.17-3 through 5.2.18 - Local File Inclusion | mailinspector | 8.6 (v3.1) | High |
| CVE-2024-48248 | NAKIVO Backup and Replication Solution - Unauthenticated Arbitrary File Read | backup & replication director | 8.6 (v3.1) | High |
| CVE-2024-48766 | NetAlert X - Arbitary File Read | netalertx | 8.6 (v3.1) | High |
| CVE-2025-10897 | WooCommerce Designer Pro <= 1.9.28 - Arbitrary File Read | WooCommerce Designer Pro | 8.6 (v3.1) | High |
| CVE-2025-2558 | WordPress The Wound Theme <= 0.0.1 - Local File Inclusion | the wound | 8.6 (v3.1) | High |
| CVE-2025-27222 | TRUfusion Enterprise <= 7.10.4.0 - Path Traversal | trufusion enterprise | 8.6 (v3.1) | High |
| CVE-2026-11974 | Media folder Addon < 4.1.7 - Unauthenticated Arbitrary File Download | wp-media-folder-addon | 8.6 (v3.1) | High |
| CVE-2026-34160 | Chamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata ser | chamilo lms | 8.6 (v3.1) | High |
| CVE-2026-34577 | Postiz: Unauthenticated Full-Read SSRF via /public/stream Endpoint with Trivially Bypassable Extension Check | postiz | 8.6 (v3.1) | High |
| CVE-2026-35032 | Jellyfin: Potential SSRF + Arbitrary file read via LiveTV M3U tuner | jellyfin | 8.6 (v4.0) | High |
| CVE-2026-40187 | Authenticated RCE via Malicious eTemplate Upload in EGroupware | egroupware | 8.6 (v4.0) | High |
| CVE-2026-42785 | OpenKM 6.3.12 Remote Code Execution via Administrative Scripting | OpenKM Community Edition | 8.6 (v4.0) | High |
| CVE-2026-45298 | Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy) | dozzle | 8.6 (v3.1) | High |
| CVE-2026-46491 | SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditi | simplesamlphp-module-casserver | 8.6 (v3.1) | High |
| CVE-2026-50553 | Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p) | note-mark | 8.6 (v4.0) | High |
| CVE-2026-53804 | OTRS Community Edition OS Command Injection via PGP Configuration | OTRS Community Edition | 8.6 (v4.0) | High |
| CVE-2026-55182 | LibreNMS: Remote Code Execution by Signal Alert Transportation Module | librenms | 8.6 (v4.0) | High |
| CVE-2026-56677 | 9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint | 9router | 8.6 (v3.1) | High |
| CVE-2026-56703 | Adminer before 5.4.3 Remote Code Execution via SQLite VACUUM INTO | adminer | 8.6 (v4.0) | High |
| CVE-2026-61517 | Netis NX10 OS Command Injection via Ping Diagnostic Handler | NX10 | 8.6 (v4.0) | High |
| CVE-2026-61523 | WebsiteBaker CMS < 2.13.10 Code Injection via Droplets Editor | WebsiteBaker CMS | 8.6 (v4.0) | High |
| CVE-2026-63725 | sysPass FileBackupService Authenticated OS Command Injection via Backup Path | sysPass | 8.6 (v4.0) | High |
| CVE-2026-65693 | Microweber CMS 2.0.20 Server-Side Template Injection via Mail Templates | microweber | 8.6 (v4.0) | High |
| CVE-2026-65711 | sysPass 3.2.11 Authenticated OS Command Injection via Backup Path | sysPass | 8.6 (v4.0) | High |
| CVE-2026-66397 | phpMyFAQ before 4.1.6 Path Traversal via category image deletion | phpMyFAQ | 8.6 (v4.0) | High |
| CVE-2026-67599 | ClearOS 7.9 OS Command Injection via Log Viewer filter parameter | ClearOS | 8.6 (v4.0) | High |
| CVE-2026-67608 | Telenia TVox 26.5.3 OS Command Injection via action_audio.php | TVox | 8.6 (v4.0) | High |
| CVE-2026-69088 | Grav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via Blueprint | grav | 8.6 (v4.0) | High |
| CVE-2026-71906 | DrayTek VigorAP Multiple Models OS Command Injection via setLan | VigorAP 918R | 8.6 (v4.0) | High |
| CVE-2026-71907 | DrayTek VigorAP Multiple Models OS Command Injection via setcamset | VigorAP 918R | 8.6 (v4.0) | High |
| CVE-2026-71908 | DrayTek VigorAP Multiple Models OS Command Injection via mesh_start_speed_test | VigorAP 918R | 8.6 (v4.0) | High |
| CVE-2026-71913 | DrayTek VigorAP Multiple Models OS Command Injection via upload_settings.cgi | VigorAP 918R | 8.6 (v4.0) | High |
| CVE-2026-71915 | DrayTek VigorSwitch Multiple Models OS Command Injection via jsonstatus | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71918 | DrayTek VigorSwitch Multiple Models OS Command Injection via webBackupAction | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71919 | DrayTek VigorSwitch Multiple Models OS Command Injection via sysreboot | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71923 | DrayTek VigorSwitch Multiple Models OS Command Injection via auth_set | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71924 | DrayTek VigorSwitch Multiple Models OS Command Injection via getVid | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71925 | DrayTek VigorSwitch Multiple Models OS Command Injection via getDetail | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71926 | DrayTek VigorSwitch Multiple Models OS Command Injection via setDevice | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71927 | DrayTek VigorSwitch Multiple Models OS Command Injection via rebDevice | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71928 | DrayTek VigorSwitch Multiple Models OS Command Injection via fdftDevice | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71929 | DrayTek VigorSwitch Multiple Models OS Command Injection via setDevProto | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71930 | DrayTek VigorSwitch Multiple Models OS Command Injection via setTime | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71931 | DrayTek VigorSwitch Multiple Models OS Command Injection via tftp_upgrade | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71943 | DrayTek VigorSwitch Multiple Models OS Command Injection via setDevNet | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-73664 | FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Module | backup | 8.6 (v4.0) | High |
| CVE-2026-7412 | Eclipse BaSyx SSRF Vulnerability | Eclipse BaSyx | 8.6 (v3.1) | High |
| CVE-2026-75121 | PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_vlan_membership_edit_dialog_post | PLANET GS-4210-16P2S V3 | 8.6 (v4.0) | High |
| CVE-2026-75122 | PLANET GS-4210-16P2S Command Injection via httpuploadcert.cgi | PLANET GS-4210-16P2S V3 | 8.6 (v4.0) | High |
| CVE-2026-75123 | PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_smtp_test_post | PLANET GS-4210-16P2S V3 | 8.6 (v4.0) | High |
| CVE-2026-80214 | LibreNMS Virtualisation Discovery Module RCE | librenms | 8.6 (v4.0) | High |
| CVE-2026-81213 | Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches | Langflow OSS | 8.6 (v3.1) | High |
| CVE-2026-81889 | elFinder: SSRF protection bypass via DNS rebinding in the fsock_get_contents() fallback | elFinder | 8.6 (v3.1) | High |
| CVE-2026-82692 | D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injection | DNS-340L | 8.6 (v4.0) | High |
| CVE-2026-84194 | LibreNMS 23.10.0 before 26.4.0 OS Command Injection via Hostname | librenms | 8.6 (v4.0) | High |
| CVE-2026-85223 | D-Link DNS-340L CGI dropbox.cgi os command injection | DNS-340L | 8.6 (v4.0) | High |
| CVE-2026-86299 | Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection | RE7000 | 8.6 (v4.0) | High |
| CVE-2026-86437 | Lara Dashboard before 1.3.2 Incorrect Authorization in Core-Upgrade Archive Upload | laradashboard | 8.6 (v4.0) | High |
| CVE-2026-86438 | Lara Dashboard before 1.3.2 Missing Authorization in Marketplace Module Install Action | laradashboard | 8.6 (v4.0) | High |
| CVE-2026-86733 | Snipe-IT before 8.7.0 Remote Code Execution via Backup Restore | snipe-it | 8.6 (v4.0) | High |
| CVE-2026-88937 | knowns through 0.33.0 Path Traversal via Template Engine | knowns | 8.6 (v4.0) | High |
| CVE-2015-2996 | SysAid Help Desk <15.2 - Local File Inclusion | sysaid | 8.5 (v2.0) | High |
| CVE-2025-34023 | Karel IP Phone IP1211 Web Management Panel - Local File Inclusion | Karel IP Phone IP1211 | 8.5 (v4.0) | High |
| CVE-2026-16033 | Arbitrary file read+write on host via templates/ symlink in malicious image | lxd | 8.5 (v3.1) | High |
| CVE-2026-22244 | OpenMetadata Server-Side Template Injection (SSTI) in FreeMarker email templates that leads to RCE | openmetadata | 8.5 (v4.0) | High |
| CVE-2026-44881 | Portainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-Update | portainer | 8.5 (v4.0) | High |
| CVE-2026-46372 | SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrl | SillyTavern | 8.5 (v3.1) | High |
| CVE-2026-51583 | usememos through v0.30.0 Server-Side Request Forgery Vulnerability | - | 8.5 (v3.1) | High |
| CVE-2026-57894 | Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfil | Gitea Open Source Git Server | 8.5 (v3.1) | High |
| CVE-2026-61640 | Wallos: SSRF via OIDC Token/UserInfo URL Configuration | Wallos | 8.5 (v4.0) | High |
| CVE-2026-67424 | Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation | flyto-core | 8.5 (v3.1) | High |
| CVE-2026-67428 | Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF | flyto-core | 8.5 (v3.1) | High |
| CVE-2026-68558 | Wekan: SSRF filter bypass via DNS-resolving hostname in outgoing webhooks (incomplete fix of CVE-2026-53446) | wekan | 8.5 (v3.1) | High |
| CVE-2026-69250 | Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration | Flowise | 8.5 (v4.0) | High |
| CVE-2026-73079 | Sub2API: Path traversal in the Responses subpath routes lets an authenticated tenant relay requests to arbitrary upstrea | sub2api | 8.5 (v3.1) | High |
| CVE-2026-82690 | D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injection | DNS-327L | 8.5 (v4.0) | High |
| CVE-2026-82691 | D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 CGI usb_device.cgi os command injection | DNS-320L | 8.5 (v4.0) | High |
| CVE-2026-85222 | D-Link DNS-340L Add-On Center addon_center.cgi os command injection | DNS-340L | 8.5 (v4.0) | High |
| CVE-2026-85224 | D-Link DNS-320 ShareCenter File Sharing file_sharing.cgi os command injection | DNS-320 ShareCenter | 8.5 (v4.0) | High |
| CVE-2026-57862 | Kanboard 1.2.52 and prior SSRF Filter Bypass via Hexadecimal IP Notation | Kanboard | 8.4 (v4.0) | High |
| CVE-2026-62234 | Grav < 2.0.4 SSRF via Unrestricted cURL Protocols | grav | 8.4 (v4.0) | High |
| CVE-2026-72855 | Budibase before 3.40.0 DNS Rebinding SSRF via OpenAPI and REST | server | 8.4 (v4.0) | High |
| CVE-2026-73629 | Serendipity before 2.6.0 SSRF via hex IPv4 and IPv6 addresses | Serendipity | 8.4 (v4.0) | High |
| CVE-2026-75855 | ArcadeDB before 26.8.1 Path Traversal via create/drop database | arcadedb | 8.4 (v4.0) | High |
| CVE-2026-75898 | RAGFlow < 0.26.3 - Server-Side Request Forgery via Agent Invoke Component | ragflow | 8.4 (v4.0) | High |
| CVE-2025-59711 | biztalk360 Path Traversal Vulnerability | biztalk360 | 8.3 (v3.1) | High |
| CVE-2026-22681 | OpenViking < 0.3.4 SSRF via /api/v1/resources | OpenViking | 8.3 (v4.0) | High |
| CVE-2026-34576 | Postiz: SSRF in upload-from-url endpoint allows fetching internal resources and cloud metadata | postiz | 8.3 (v4.0) | High |
| CVE-2026-34966 | Gitea prior to 1.27.0 SSRF via Migration URI Fetch Bypass | Gitea | 8.3 (v4.0) | High |
| CVE-2026-48105 | Arc Enterprise cluster FSM applyRegisterFile accepts arbitrary file paths without validation, enabling cluster-wide path | arc | 8.3 (v4.0) | High |
| CVE-2026-49471 | Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE | serena | 8.3 (v3.1) | High |
| CVE-2026-52769 | YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub Signature.keyId | yeswiki | 8.3 (v3.1) | High |
| CVE-2026-63313 | 9Router before 0.4.72 Server-Side Request Forgery via /v1/web/fetch | 9router | 8.3 (v4.0) | High |
| CVE-2026-65056 | mcp-webresearch Server-Side Request Forgery in visit_page Due to Missing Internal-IP Filtering | mcp-webresearch | 8.3 (v4.0) | High |
| CVE-2026-69086 | SiYuan before v3.7.3 Path Traversal via unvalidated avID | siyuan | 8.3 (v4.0) | High |
| CVE-2026-69101 | Datavane TIS v5.0.0 XXE Injection via doEditWorkflow Endpoint | tis | 8.3 (v4.0) | High |
| CVE-2026-75842 | ArcadeDB before 26.8.1 Arbitrary File Read via LOAD CSV | arcadedb | 8.3 (v4.0) | High |
| CVE-2026-76225 | ArcadeDB before 26.8.1 Server-Side Request Forgery via LOAD CSV | arcadedb | 8.3 (v4.0) | High |
| CVE-2026-79659 | Ech0 before 4.7.3 Server-Side Request Forgery via fetchPeerConnectInfo | Ech0 | 8.3 (v4.0) | High |
| CVE-2026-82243 | Budibase Server before 3.41.3 SSRF with Credential Leakage | server | 8.3 (v4.0) | High |
| CVE-2026-82673 | Path traversal in AshAdmin file uploads via unsanitized client filename | ash admin | 8.3 (v4.0) | High |
| CVE-2026-84196 | Kyverno before 1.18.0 Server-Side Request Forgery via apiCall | kyverno | 8.3 (v4.0) | High |
| CVE-2026-86771 | Snipe-IT before 8.7.0 Server-Side Request Forgery via employee_num | snipe-it | 8.3 (v4.0) | High |
| CVE-2026-9133 | Amazon rabbitmq-aws 0.1.0 through 0.2.0 - Arbitrary File Read | RabbitMQ AWS | 8.3 (v4.0) | High |
| CVE-2025-44137 | MapTiler Tileserver-php v2.0 - Unauthenticated File Read | tileserver php | 8.2 (v3.1) | High |
| CVE-2025-69755 | Neterbit NW-431F Router vNW-431F-20241014-IR03 Arbitrary Code Execution Vulnerability | - | 8.2 (v3.1) | High |
| CVE-2026-16268 | Newsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Bounce Handler | Newsletters | 8.2 (v3.1) | High |
| CVE-2026-39363 | Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket | vite | 8.2 (v4.0) | High |
| CVE-2026-39364 | Vite Dev Server - Directory Traversal | vite | 8.2 (v4.0) | High |
| CVE-2026-40075 | OpenMRS Core arbitrary file read via path traversal in ModuleResourcesServlet | openmrs | 8.2 (v4.0) | High |
| CVE-2026-43910 | Appium java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor | java-client | 8.2 (v3.1) | High |
| CVE-2026-45711 | Mailpit: Path traversal & arbitrary file write in mailpit dump –http via attacker-controlled message IDs | mailpit | 8.2 (v3.1) | High |
| CVE-2026-48126 | Algernon: Host header path traversal in –domain mode reads files and runs Lua from parent dir | algernon | 8.2 (v3.1) | High |
| CVE-2026-54691 | datamodel-code-generator vulnerable to SSRF via –url: no host/IP validation, follows redirects | datamodel-code-generator | 8.2 (v3.1) | High |
| CVE-2026-61638 | Wallos: SSRF via Test Email Notification - unvalidated SMTP host/port | Wallos | 8.2 (v4.0) | High |
| CVE-2026-74907 | Grav before 2.0.15 Path Traversal via plugin-asset-map.php | grav | 8.2 (v4.0) | High |
| CVE-2026-77348 | Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.ph | Wallos | 8.2 (v3.1) | High |
| CVE-2026-82262 | Logto Server-Side Request Forgery via webhook test endpoint | logto | 8.2 (v4.0) | High |
| CVE-2013-4862 | MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities | veralite firmware | 8.1 (v3.1) | High |
| CVE-2014-3120 | ElasticSearch v1.1.1/1.2 RCE | elasticsearch | 8.1 (v3.1) | High |
| CVE-2016-3081 | Apache S2-032 Struts - Remote Code Execution | struts | 8.1 (v3.0) | High |
| CVE-2017-12615 | Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (1) | tomcat | 8.1 (v3.1) | High |
| CVE-2017-9805 | Apache Struts2 S2-052 - Remote Code Execution | struts | 8.1 (v3.1) | High |
| CVE-2024-30188 | Apache DolphinScheduler >= 3.1.0, < 3.2.2 Resource File Read And Write | dolphinscheduler | 8.1 (v3.1) | High |
| CVE-2025-48157 | WordPress Formality Plugin <= 1.5.9 - Local File Inclusion | Formality | 8.1 (v3.1) | High |
| CVE-2026-19303 | Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing c | langflow | 8.1 (v3.1) | High |
| CVE-2026-33236 | NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite | nltk | 8.1 (v3.1) | High |
| CVE-2026-34365 | InvoiceShelf: SSRF in Estimate PDF Rendering via Unsanitised HTML in Notes Field | invoiceshelf | 8.1 (v3.1) | High |
| CVE-2026-34366 | InvoiceShelf: SSRF in Payment Receipt PDF Rendering via Unsanitised HTML in Notes Field | invoiceshelf | 8.1 (v3.1) | High |
| CVE-2026-34522 | SillyTavern: Path traversal in /api/chats/import allows arbitrary file write outside intended chat directory | sillytavern | 8.1 (v3.1) | High |
| CVE-2026-42588 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnector | activemq | 8.1 (v3.1) | High |
| CVE-2026-45344 | LinkAce: Setup database password newline injection enables pre-auth RCE on uninitialized instances | LinkAce | 8.1 (v3.1) | High |
| CVE-2026-46484 | Headplane: Path Traversal + RBAC Bypass in renameNode allows authenticated OIDC users to expire or rename any node/user | headplane | 8.1 (v3.1) | High |
| CVE-2026-47398 | PraisonAI: Arbitrary code execution via unguarded spec.loader.exec_module in agents_generator.py - sibling of CVE-20 | PraisonAI | 8.1 (v3.1) | High |
| CVE-2026-48695 | fastnetmon Command Injection Vulnerability | fastnetmon | 8.1 (v3.1) | High |
| CVE-2026-50143 | Actor MCP path authority injection leaks Apify token | apify-mcp-server | 8.1 (v3.1) | High |
| CVE-2026-54083 | Wazuh: Path traversal in ip-customblock active response allows arbitrary file creation and deletion | wazuh | 8.1 (v3.1) | High |
| CVE-2026-64679 | Atlantis: Path Traversal in Atlantis Workspace Handling Allows Out-of-Bounds Directory Deletion/Creation | atlantis | 8.1 (v3.1) | High |
| CVE-2026-71320 | Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props | nuxt | 8.1 (v3.1) | High |
| CVE-2026-73659 | Trigger.dev: Cross-tenant object read/write via path traversal in packet presign API | trigger.dev | 8.1 (v3.1) | High |
| CVE-2026-79755 | Nuclio: Unauthenticated OS command injection via function namespace in docker ps –filter label (local Docker platform) | nuclio | 8.0 (v3.1) | High |
| CVE-2009-1558 | Cisco Linksys WVC54GCA 1.00R22/1.00R24 - Local File Inclusion | wvc54gca | 7.8 (v2.0) | High |
| CVE-2011-3315 | Cisco CUCM, UCCX, and Unified IP-IVR- Directory Traversal | unified ip interactive voice response | 7.8 (v2.0) | High |
| CVE-2014-2962 | Belkin N150 Router 1.00.08/1.00.09 - Path Traversal | n150 f9k1009 firmware | 7.8 (v2.0) | High |
| CVE-2015-4669 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 7.8 (v3.0) | High |
| CVE-2021-21315 | Node.JS System Information Library <5.3.1 - Remote Command Injection | systeminformation | 7.8 (v3.1) | High |
| CVE-2022-25485 | Cuppa CMS v1.0 - Local File Inclusion | cuppacms | 7.8 (v3.1) | High |
| CVE-2022-25486 | Cuppa CMS v1.0 - Local File Inclusion | cuppacms | 7.8 (v3.1) | High |
| CVE-2026-40280 | Gotenberg <= 8.30.1 - Server Side Request Forgery | gotenberg | 7.8 (v4.0) | High |
| CVE-2026-65600 | Traefik before v2.11.52 Authentication Bypass via ReplacePathRegex | traefik | 7.8 (v4.0) | High |
| CVE-2026-67179 | Genkit improper host header validation | genkit | 7.8 (v3.1) | High |
| CVE-2026-67309 | Traefik v3.7.0 Path Traversal via RewriteTarget Authentication Bypass | traefik | 7.8 (v4.0) | High |
| CVE-2020-35749 | WordPress Simple Job Board <2.9.4 - Local File Inclusion | simple board job | 7.7 (v3.1) | High |
| CVE-2021-21234 | Spring Boot Actuator Logview Directory Traversal | spring-boot-actuator-logview | 7.7 (v3.1) | High |
| CVE-2025-27621 | UpTrain has a Constant Default API Key | uptrain | 7.7 (v4.0) | High |
| CVE-2026-34163 | Server-Side Request Forgery via MCP Tools Endpoint in FastGPT | fastgpt | 7.7 (v3.1) | High |
| CVE-2026-34936 | PraisonAI: SSRF via Unvalidated api_base in passthrough() Fallback | praisonai | 7.7 (v3.1) | High |
| CVE-2026-39361 | OpenObserve has a SSRF Protection Bypass via IPv6 Bracket Notation in validate_enrichment_url | openobserve | 7.7 (v3.1) | High |
| CVE-2026-39965 | TypeBot: SSRF via Open Redirect Bypass in HTTP Request and Code Blocks | typebot.io | 7.7 (v3.1) | High |
| CVE-2026-40519 | Nginx Proxy Manager Authenticated RCE via setupCertbotPlugins() | nginx-proxy-manager | 7.7 (v4.0) | High |
| CVE-2026-42345 | FastGPT: Cloud metadata endpoint SSRF protection bypass via port specification, IPv6 mapping, hex/decimal IP encoding, a | FastGPT | 7.7 (v3.1) | High |
| CVE-2026-44285 | FastGPT: SSRF Protection Bypass via externalFile in Dataset Preview API | FastGPT | 7.7 (v3.1) | High |
| CVE-2026-45806 | Penpot: Authenticated SSRF in remote image import via create-file-media-object-from-url | penpot | 7.7 (v3.1) | High |
| CVE-2026-47179 | Arcane: Authenticated Arbitrary Host File Read via Docker Compose Include Directives in Arcane | arcane | 7.7 (v3.1) | High |
| CVE-2026-53549 | Termix: Server-Side Request Forgery via Proxy Connectivity Test | Termix | 7.7 (v3.1) | High |
| CVE-2026-53553 | Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server Compromise | goploy | 7.7 (v3.1) | High |
| CVE-2026-54910 | FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files | filebrowser | 7.7 (v3.1) | High |
| CVE-2026-58314 | Two SSRF findings in Gitea 1.26.2 | Gitea Open Source Git Server | 7.7 (v3.1) | High |
| CVE-2026-61835 | Directus: SSRF Protection Bypass via 0.0.0.0 in File Import | directus | 7.7 (v3.1) | High |
| CVE-2026-63464 | Nebula-mesh allows non-admin operators to disable webhook SSRF protection via allow_private | nebula-mesh | 7.7 (v3.1) | High |
| CVE-2026-63764 | LMDeploy Server-Side Request Forgery via HTTP Redirect Bypass | lmdeploy | 7.7 (v4.0) | High |
| CVE-2026-66738 | SPIP < 4.4.18 Code Injection via Navigation Endpoint on SQLite | SPIP | 7.7 (v4.0) | High |
| CVE-2026-67346 | Swarms 6.8.1 Server-Side Request Forgery via DNS Rebinding Bypass | swarms | 7.7 (v4.0) | High |
| CVE-2026-69192 | ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trus | ip-address | 7.7 (v4.0) | High |
| CVE-2026-71303 | Lemur: Incomplete fix for CVE-2026-55166 – ACME authority update endpoint allows non-admin to replace acme_url with i | lemur | 7.7 (v3.1) | High |
| CVE-2026-71365 | Awx: webhook status callback ssrf leaks the git pat | Red Hat Ansible Automation Platform 2.5 for RHEL 8 | 7.7 (v3.1) | High |
| CVE-2026-73498 | MCP Atlassian is a Model Context Protocol (MCP): Arbitrary file read via missing path validation in confluence_upload_at | mcp-atlassian | 7.7 (v3.1) | High |
| CVE-2026-77775 | Headroom Proxy Sends Upstream Requests to a Client-Supplied Base URL Without Address Validation | Headroom | 7.7 (v4.0) | High |
| CVE-2026-8183 | Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement | langflow | 7.7 (v3.1) | High |
| CVE-2026-39369 | WWBN AVideo's GIF poster fetch bypasses traversal scrubbing and exposes local files through public media URLs | avideo | 7.6 (v3.1) | High |
| CVE-2026-44239 | FreePBX: Authenticated Local File Inclusion in Dashboard Module | freepbx | 7.6 (v4.0) | High |
| CVE-2026-45082 | Karakeep has a SSRF Protection Bypass via Redirect Handling | karakeep | 7.6 (v3.1) | High |
| CVE-2026-65695 | Office-Word-MCP-Server 1.1.11 Path Traversal via document tools | Office-Word-MCP-Server | 7.6 (v4.0) | High |
| CVE-2026-79749 | MCPHub: SSRF Guard Bypass via IPv6 Transition Addresses in URL Validation | mcphub | 7.6 (v4.0) | High |
| CVE-2006-2842 | Squirrelmail <=1.4.6 - Local File Inclusion | squirrelmail | 7.5 (v2.0) | High |
| CVE-2008-1059 | WordPress Sniplets 1.1.2 - Local File Inclusion | sniplets plugin | 7.5 (v2.0) | High |
| CVE-2009-1479 | boxalino 09.05.25-0421 - Directory Traversal | boxalino | 7.5 (v2.0) | High |
| CVE-2009-2015 | Joomla! MooFAQ 1.0 - Local File Inclusion | Joomla! | 7.5 (v2.0) | High |
| CVE-2009-3318 | Joomla! Roland Breedveld Album 1.14 - Local File Inclusion | Joomla! | 7.5 (v2.0) | High |
| CVE-2009-4202 | Joomla! Omilen Photo Gallery 0.5b - Local File Inclusion | joomla! | 7.5 (v2.0) | High |
| CVE-2009-4679 | Joomla! Portfolio Nexus - Remote File Inclusion | com if nexus | 7.5 (v2.0) | High |
| CVE-2010-0157 | Joomla! Component com_biblestudy - Local File Inclusion | joomla! | 7.5 (v2.0) | High |
| CVE-2010-0759 | Joomla! Plugin Core Design Scriptegrator - Local File Inclusion | scriptegrator plugin | 7.5 (v2.0) | High |
| CVE-2010-0972 | Joomla! Component com_gcalendar Suite 2.1.5 - Local File Inclusion | com gcalendar | 7.5 (v2.0) | High |
| CVE-2010-0985 | Joomla! Component com_abbrev - Local File Inclusion | com abbrev | 7.5 (v2.0) | High |
| CVE-2010-1306 | Joomla! Component Picasa 2.0 - Local File Inclusion | com joomlapicasa2 | 7.5 (v2.0) | High |
| CVE-2010-1470 | Joomla! Component Web TV 1.0 - Local File Inclusion | com webtv | 7.5 (v2.0) | High |
| CVE-2010-1471 | Joomla! Component Address Book 1.5.0 - Local File Inclusion | com addressbook | 7.5 (v2.0) | High |
| CVE-2010-1472 | Joomla! Component Horoscope 1.5.0 - Local File Inclusion | com horoscope | 7.5 (v2.0) | High |
| CVE-2010-1495 | Joomla! Component Matamko 1.01 - Local File Inclusion | com matamko | 7.5 (v2.0) | High |
| CVE-2010-1531 | Joomla! Component redSHOP 1.0 - Local File Inclusion | com redshop | 7.5 (v2.0) | High |
| CVE-2010-1533 | Joomla! Component TweetLA 1.0.1 - Local File Inclusion | com tweetla | 7.5 (v2.0) | High |
| CVE-2010-1535 | Joomla! Component TRAVELbook 1.0.1 - Local File Inclusion | com travelbook | 7.5 (v2.0) | High |
| CVE-2010-1602 | Joomla! Component ZiMB Comment 0.8.1 - Local File Inclusion | com zimbcomment | 7.5 (v2.0) | High |
| CVE-2010-1603 | Joomla! Component ZiMBCore 0.1 - Local File Inclusion | com zimbcore | 7.5 (v2.0) | High |
| CVE-2010-1653 | Joomla! Component Graphics 1.0.6 - Local File Inclusion | com graphics | 7.5 (v2.0) | High |
| CVE-2010-1717 | Joomla! Component iF surfALERT 1.2 - Local File Inclusion | if surfalert | 7.5 (v2.0) | High |
| CVE-2010-1875 | Joomla! Component Property - Local File Inclusion | com properties | 7.5 (v2.0) | High |
| CVE-2010-1878 | Joomla! Component OrgChart 1.0.0 - Local File Inclusion | com orgchart | 7.5 (v2.0) | High |
| CVE-2010-1952 | Joomla! Component BeeHeard 1.0 - Local File Inclusion | com beeheard | 7.5 (v2.0) | High |
| CVE-2010-1953 | Joomla! Component iNetLanka Multiple Map 1.0 - Local File Inclusion | com multimap | 7.5 (v2.0) | High |
| CVE-2010-1954 | Joomla! Component iNetLanka Multiple root 1.0 - Local File Inclusion | com multiroot | 7.5 (v2.0) | High |
| CVE-2010-1955 | Joomla! Component Deluxe Blog Factory 1.1.2 - Local File Inclusion | com blogfactory | 7.5 (v2.0) | High |
| CVE-2010-1956 | Joomla! Component Gadget Factory 1.0.0 - Local File Inclusion | com gadgetfactory | 7.5 (v2.0) | High |
| CVE-2010-1957 | Joomla! Component Love Factory 1.3.4 - Local File Inclusion | com lovefactory | 7.5 (v2.0) | High |
| CVE-2010-1977 | Joomla! Component J!WHMCS Integrator 1.5.0 - Local File Inclusion | com jwhmcs | 7.5 (v2.0) | High |
| CVE-2010-1980 | Joomla! Component Joomla! Flickr 1.0 - Local File Inclusion | com joomlaflickr | 7.5 (v2.0) | High |
| CVE-2010-1983 | Joomla! Component redTWITTER 1.0 - Local File Inclusion | com redtwitter | 7.5 (v2.0) | High |
| CVE-2010-2033 | Joomla! Percha Categories Tree 0.6 - Local File Inclusion | com perchacategoriestree | 7.5 (v2.0) | High |
| CVE-2010-2034 | Joomla! Component Percha Image Attach 1.1 - Directory Traversal | com perchaimageattach | 7.5 (v2.0) | High |
| CVE-2010-2035 | Joomla! Component Percha Gallery 1.6 Beta - Directory Traversal | com perchagallery | 7.5 (v2.0) | High |
| CVE-2010-2036 | Joomla! Component Percha Fields Attach 1.0 - Directory Traversal | com perchafieldsattach | 7.5 (v2.0) | High |
| CVE-2010-2037 | Joomla! Component Percha Downloads Attach 1.1 - Directory Traversal | com perchadownloadsattach | 7.5 (v2.0) | High |
| CVE-2010-2045 | Joomla! Component FDione Form Wizard 1.0.2 - Local File Inclusion | com dioneformwizard | 7.5 (v2.0) | High |
| CVE-2010-2050 | Joomla! Component MS Comment 0.8.0b - Local File Inclusion | com mscomment | 7.5 (v2.0) | High |
| CVE-2010-2128 | Joomla! Component JE Quotation Form 1.0b1 - Local File Inclusion | com jequoteform | 7.5 (v2.0) | High |
| CVE-2010-2259 | Joomla! Component com_bfsurvey - Local File Inclusion | com bfsurvey profree | 7.5 (v2.0) | High |
| CVE-2010-2682 | Joomla! Component Realtyna Translator 1.0.15 - Local File Inclusion | com realtyna | 7.5 (v2.0) | High |
| CVE-2010-2918 | Joomla! Component Visites 1.1 - MosConfig_absolute_path Remote File Inclusion | com joomla visites | 7.5 (v2.0) | High |
| CVE-2010-3426 | Joomla! Component Jphone 1.0 Alpha 3 - Local File Inclusion | com jphone | 7.5 (v2.0) | High |
| CVE-2010-4282 | Pandora Fms < 3.1.1 - Directory Traversal | pandora fms | 7.5 (v2.0) | High |
| CVE-2010-4719 | Joomla! Component JRadio - Local File Inclusion | com jradio | 7.5 (v2.0) | High |
| CVE-2010-4769 | Joomla! Component Jimtawl 1.0.2 - Local File Inclusion | com jimtawl | 7.5 (v2.0) | High |
| CVE-2010-4977 | Joomla! Component Canteen 1.0 - Local File Inclusion | com canteen | 7.5 (v2.0) | High |
| CVE-2010-5028 | Joomla! Component JE Job 1.0 - Local File Inclusion | com jejob | 7.5 (v2.0) | High |
| CVE-2011-4448 | WikkaWiki 1.3.2 - Multiple Vulnerabilities | wikkawiki | 7.5 (v2.0) | High |
| CVE-2012-1226 | Dolibarr ERP/CRM 3.2 Alpha - Multiple Directory Traversal Vulnerabilities | dolibarr erp/crm | 7.5 (v2.0) | High |
| CVE-2013-5639 | Gnew 2013.1 - Multiple Vulnerabilities (2) | gnew | 7.5 (v2.0) | High |
| CVE-2013-5640 | Gnew 2013.1 - Multiple Vulnerabilities (2) | gnew | 7.5 (v2.0) | High |
| CVE-2013-6041 | Webuzo 2.1.3 - Multiple Vulnerabilities | webuzo | 7.5 (v2.0) | High |
| CVE-2014-10037 | DomPHP 0.83 - Directory Traversal | domphp | 7.5 (v2.0) | High |
| CVE-2014-2846 | WD Arkeia Virtual Appliance 10.2.9 - Local File Inclusion | arkeia virtual appliance firmware | 7.5 (v2.0) | High |
| CVE-2014-9145 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | 7.5 (v2.0) | High |
| CVE-2014-9147 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | 7.5 (v3.0) | High |
| CVE-2015-1000005 | WordPress Candidate Application Form <= 1.3 - Local File Inclusion | candidate-application-form | 7.5 (v3.0) | High |
| CVE-2015-1000010 | WordPress Simple Image Manipulator < 1.0 - Local File Inclusion | simple-image-manipulator | 7.5 (v3.0) | High |
| CVE-2015-1000012 | WordPress MyPixs <=0.3 - Local File Inclusion | mypixs | 7.5 (v3.0) | High |
| CVE-2015-1503 | IceWarp Mail Server < 11.1.1 - Directory Traversal | mail server | 7.5 (v3.0) | High |
| CVE-2015-3648 | ResourceSpace - Local File inclusion | resourcespace | 7.5 (v2.0) | High |
| CVE-2015-4074 | Joomla! Helpdesk Pro plugin <1.4.0 - Local File Inclusion | helpdesk pro | 7.5 (v3.0) | High |
| CVE-2015-4632 | Koha 3.20.1 - Directory Traversal | koha | 7.5 (v3.0) | High |
| CVE-2015-5469 | WordPress MDC YouTube Downloader 2.1.0 - Local File Inclusion | mdc youtube downloader | 7.5 (v3.0) | High |
| CVE-2015-9406 | mTheme Unus < 2.3 - Directory Traversal | mtheme-unus | 7.5 (v3.1) | High |
| CVE-2016-10924 | Wordpress Zedna eBook download <1.2 - Local File Inclusion | zedna ebook download | 7.5 (v3.0) | High |
| CVE-2016-10956 | WordPress Mail Masta 1.0 - Local File Inclusion | mail-masta | 7.5 (v3.1) | High |
| CVE-2016-2389 | SAP xMII 15.0 for SAP NetWeaver 7.4 - Local File Inclusion | netweaver | 7.5 (v3.0) | High |
| CVE-2016-4806 | Web2py 2.14.5 - Multiple Vulnerabilities | web2py | 7.5 (v3.0) | High |
| CVE-2016-6601 | WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities | webnms framework | 7.5 (v3.0) | High |
| CVE-2017-15647 | FiberHome Routers - Local File Inclusion | routerfiberhome firmware | 7.5 (v3.0) | High |
| CVE-2017-9833 | BOA Web Server 0.94.14 - Arbitrary File Access | boa | 7.5 (v3.1) | High |
| CVE-2018-12054 | Schools Alert Management Script - Arbitrary File Read | schools alert management script | 7.5 (v3.0) | High |
| CVE-2018-12909 | Webgrind <= 1.5 - Local File Inclusion | webgrind | 7.5 (v3.0) | High |
| CVE-2018-14912 | cgit < 1.2.1 - Directory Traversal | cgit | 7.5 (v3.0) | High |
| CVE-2018-14918 | LOYTEC LGATE-902 6.3.2 - Local File Inclusion | lgate-902 firmware | 7.5 (v3.0) | High |
| CVE-2018-15138 | LG-Ericsson iPECS NMS 30M - Local File Inclusion | ipecs nms | 7.5 (v3.0) | High |
| CVE-2018-15535 | Responsive FileManager < 9.13.4 - Directory Traversal | responsive filemanager | 7.5 (v3.0) | High |
| CVE-2018-16299 | WordPress Localize My Post 1.0 - Local File Inclusion | localize my post | 7.5 (v3.0) | High |
| CVE-2018-18323 | Centos Web Panel 0.9.8.480 - Local File Inclusion | webpanel | 7.5 (v3.0) | High |
| CVE-2018-19458 | PHP Proxy 3.0.3 - Local File Inclusion | php-proxy | 7.5 (v3.0) | High |
| CVE-2018-19753 | Tarantella Enterprise <3.11 - Local File Inclusion | tarantella enterprise | 7.5 (v3.0) | High |
| CVE-2018-20463 | WordPress JSmol2WP <=1.07 - Local File Inclusion | jsmol2wp | 7.5 (v3.0) | High |
| CVE-2018-6008 | Joomla! Jtag Members Directory 5.3.7 - Local File Inclusion | jtag members directory | 7.5 (v3.0) | High |
| CVE-2018-7422 | WordPress Site Editor <=1.1.1 - Local File Inclusion | site editor | 7.5 (v3.0) | High |
| CVE-2018-9118 | WordPress 99 Robots WP Background Takeover Advertisements <=4.1.4 - Local File Inclusion | wp background takeover advertisements | 7.5 (v3.0) | High |
| CVE-2018-9205 | Drupal avatar_uploader v7.x-1.0-beta8 - Local File Inclusion | avatar uploader | 7.5 (v3.0) | High |
| CVE-2019-12276 | GrandNode 4.40 - Local File Inclusion | grandnode | 7.5 (v3.0) | High |
| CVE-2019-12593 | IceWarp Mail Server <=10.4.4 - Local File Inclusion | mail server | 7.5 (v3.0) | High |
| CVE-2019-14205 | WordPress Nevma Adaptive Images <0.6.67 - Local File Inclusion | adaptive images | 7.5 (v3.1) | High |
| CVE-2019-14251 | T24 Web Server - Local File Inclusion | t24 | 7.5 (v3.1) | High |
| CVE-2019-16123 | PilusCart <=1.4.1 - Local File Inclusion | piluscart | 7.5 (v3.1) | High |
| CVE-2019-17538 | Jiangnan Online Judge 0.8.0 - Local File Inclusion | jiangnan online judge | 7.5 (v3.1) | High |
| CVE-2019-18665 | DOMOS 5.5 - Local File Inclusion | domos | 7.5 (v3.1) | High |
| CVE-2019-25213 | WordPress Advanced Access Manager - Path Traversal | advanced access manager | 7.5 (v3.1) | High |
| CVE-2019-7254 | eMerge E3 1.00-06 - Local File Inclusion | linear emerge essential firmware | 7.5 (v3.1) | High |
| CVE-2019-9757 | LabKey Server 19.1.0 - XML External Entity (XXE) | labkey server | 7.5 (v3.1) | High |
| CVE-2019-9922 | Joomla! Harmis Messenger 1.2.2 - Local File Inclusion | je messenger | 7.5 (v3.1) | High |
| CVE-2020-11738 | WordPress Duplicator 1.3.24 & 1.3.26 - Local File Inclusion | duplicator | 7.5 (v3.1) | High |
| CVE-2020-13158 | Artica Proxy Community Edition <4.30.000000 - Local File Inclusion | artica proxy | 7.5 (v3.1) | High |
| CVE-2020-14864 | Oracle Fusion - Directory Traversal/Local File Inclusion | business intelligence | 7.5 (v3.1) | High |
| CVE-2020-19360 | FHEM 6.0 - Local File Inclusion | fhem | 7.5 (v3.1) | High |
| CVE-2020-24285 | INTELBRAS TELEFONE IP TIP200 60.61.75.22 - Local File Inclusion | tip200 | 7.5 (v3.1) | High |
| CVE-2020-27191 | LionWiki <3.2.12 - Local File Inclusion | lionwiki | 7.5 (v3.1) | High |
| CVE-2020-27467 | Processwire CMS <2.7.1 - Local File Inclusion | processwire | 7.5 (v3.1) | High |
| CVE-2020-35580 | SearchBlox <9.2.2 - Local File Inclusion | searchblox | 7.5 (v3.1) | High |
| CVE-2020-35598 | Advanced Comment System 1.0 - Local File Inclusion | advanced comment system | 7.5 (v3.1) | High |
| CVE-2020-8209 | Citrix XenMobile Server - Local File Inclusion | xenmobile server | 7.5 (v3.1) | High |
| CVE-2021-20123 | Draytek VigorConnect 1.6.0-B - Local File Inclusion | vigorconnect | 7.5 (v3.1) | High |
| CVE-2021-20124 | Draytek VigorConnect 6.0-B3 - Local File Inclusion | vigorconnect | 7.5 (v3.1) | High |
| CVE-2021-24227 | Patreon WordPress <1.7.0 - Unauthenticated Local File Inclusion | patreon wordpress | 7.5 (v3.1) | High |
| CVE-2021-33807 | Cartadis Gespage 8.2.1 - Directory Traversal | gespage | 7.5 (v3.1) | High |
| CVE-2021-39312 | WordPress True Ranker <2.2.4 - Local File Inclusion | true ranker | 7.5 (v3.1) | High |
| CVE-2021-39316 | WordPress DZS Zoomsounds <=6.50 - Local File Inclusion | zoomsounds | 7.5 (v3.1) | High |
| CVE-2021-39433 | BIQS IT Biqs-drive v1.83 Local File Inclusion | biqsdrive | 7.5 (v3.1) | High |
| CVE-2021-41277 | Metabase - Local File Inclusion | metabase | 7.5 (v3.1) | High |
| CVE-2021-41291 | ECOA Building Automation System - Directory Traversal Content Disclosure | ecs router controller-ecs firmware | 7.5 (v3.1) | High |
| CVE-2021-41569 | SAS/Internet 9.4 1520 - Local File Inclusion | sas/intrnet | 7.5 (v3.1) | High |
| CVE-2021-43287 | Pre-Auth Takeover of Build Pipelines in GoCD | gocd | 7.5 (v3.1) | High |
| CVE-2021-43734 | kkFileview v4.0.0 - Local File Inclusion | kkfileview | 7.5 (v3.1) | High |
| CVE-2021-43778 | GLPI plugin Barcode < 2.6.1 - Path Traversal Vulnerability. | barcode | 7.5 (v3.1) | High |
| CVE-2021-45043 | HD-Network Realtime Monitoring System 2.0 - Local File Inclusion | hd-network real-time monitoring system | 7.5 (v3.1) | High |
| CVE-2021-46107 | Ligeo Archives Ligeo Basics - Server Side Request Forgery | ligeo basics | 7.5 (v3.1) | High |
| CVE-2021-46381 | DLINK DAP-1620 A1 v1.01 - Directory Traversal | dap-1620 firmware | 7.5 (v3.1) | High |
| CVE-2021-46417 | Franklin Fueling Systems Colibri Controller Module 1.8.19.8580 - Local File Inclusion (LFI) | colibri firmware | 7.5 (v3.1) | High |
| CVE-2022-0656 | uDraw <3.3.3 - Local File Inclusion | [web to print shop](/vendors/webtoprint/web-to-print-shop/) | 7.5 (v3.1) | High |
| CVE-2022-1119 | WordPress Simple File List <3.2.8 - Local File Inclusion | simple-file-list | 7.5 (v3.1) | High |
| CVE-2022-29014 | Razer Sila Gaming Router 2.0.441_api-2.0.418 - Local File Inclusion | sila firmware | 7.5 (v3.1) | High |
| CVE-2022-29298 | SolarView Compact 6.00 - Local File Inclusion | sv-cpt-mc310 firmware | 7.5 (v3.1) | High |
| CVE-2022-31474 | BackupBuddy - Local File Inclusion | backupbuddy | 7.5 (v3.1) | High |
| CVE-2022-33901 | WordPress MultiSafepay for WooCommerce <=4.13.1 - Arbitrary File Read | multisafepay plugin for woocommerce | 7.5 (v3.1) | High |
| CVE-2022-34121 | CuppaCMS v1.0 - Local File Inclusion | cuppacms | 7.5 (v3.1) | High |
| CVE-2022-34127 | GLPI 4.0.2 - Unauthenticated Local File Inclusion on Manageentities plugin | manageentities | 7.5 (v3.1) | High |
| CVE-2022-37122 | Carel pCOWeb HVAC BACnet Gateway 2.1.0 - Path Traversal | pcoweb hvac bacnet gateway | 7.5 (v3.1) | High |
| CVE-2022-38840 | Güralp MAN-EAM-0003 3.2.4 - XML External Entity (XXE) | man-eam-0003 | 7.5 (v3.1) | High |
| CVE-2022-4140 | WordPress Welcart e-Commerce <2.8.5 - Arbitrary File Access | welcart e-commerce | 7.5 (v3.1) | High |
| CVE-2022-47501 | Apache OFBiz < 18.12.07 - Local File Inclusion | ofbiz | 7.5 (v3.1) | High |
| CVE-2023-0159 | Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE | extensive vc addons for wpbakery page builder | 7.5 (v3.1) | High |
| CVE-2023-22047 | Oracle Peoplesoft - Unauthenticated File Read | peoplesoft enterprise | 7.5 (v3.1) | High |
| CVE-2023-23063 | Cellinx NVT Web Server - Local File Disclosure | nvt web server | 7.5 (v3.1) | High |
| CVE-2023-26256 | STAGIL Navigation for Jira Menu & Themes <2.0.52 - Local File Inclusion | stagil navigation | 7.5 (v3.1) | High |
| CVE-2023-29887 | Nuovo Spreadsheet Reader 0.5.11 - Local File Inclusion | spreadsheet-reader | 7.5 (v3.1) | High |
| CVE-2023-33510 | Jeecg P3 Biz Chat - Local File Inclusion | jeecg p3 biz chat | 7.5 (v3.1) | High |
| CVE-2023-38879 | openSIS v9.0 - Path Traversal | opensis | 7.5 (v3.1) | High |
| CVE-2023-40924 | SolarView Compact < 6.00 - Directory Traversal | solarview compact firmware | 7.5 (v3.1) | High |
| CVE-2023-6023 | VertaAI ModelDB - Path Traversal | modeldb | 7.5 (v3.1) | High |
| CVE-2023-6038 | H2O ImportFiles - Local File Inclusion | h2o | 7.5 (v3.1) | High |
| CVE-2023-6977 | Mlflow <2.8.0 - Local File Inclusion | mlflow | 7.5 (v3.1) | High |
| CVE-2024-12849 | Error Log Viewer By WP Guru <= 1.0.1.3 - Missing Authorization to Arbitrary File Read | error-log-viewer-wp | 7.5 (v3.1) | High |
| CVE-2024-1728 | Gradio > 4.19.1 UploadButton - Path Traversal | gradio | 7.5 (v3.1) | High |
| CVE-2024-27292 | Docassemble - Local File Inclusion | docassemble | 7.5 (v3.1) | High |
| CVE-2024-36420 | Flowise 1.4.3 - Arbitrary File Read | flowise | 7.5 (v3.1) | High |
| CVE-2024-45388 | Hoverfly < 1.10.3 - Arbitrary File Read | hoverfly | 7.5 (v3.1) | High |
| CVE-2024-46938 | Sitecore Experience Platform <= 10.4 - Arbitrary File Read | experience commerce | 7.5 (v3.1) | High |
| CVE-2024-5334 | Devika - Local File Inclusion | devika | 7.5 (v3.0) | High |
| CVE-2024-6893 | Journyx - XML External Entities Injection (XXE) | journyx-jtime | 7.5 (v3.1) | High |
| CVE-2024-9362 | Polyaxon - Unauthenticated Directory Traversal | polyaxon/polyaxon | 7.5 (v3.0) | High |
| CVE-2024-9935 | PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Arbitrary File Download | pdf-generator-addon-for-elementor-page-builder | 7.5 (v3.1) | High |
| CVE-2025-10162 | WordPress OrderConvo < 14 - Path Traversal | Admin and Customer Messages After Order for WooCommerce: OrderConvo | 7.5 (v3.1) | High |
| CVE-2025-11371 | Gladinet CentreStack & TrioFox - Local File Inclusion | centrestack | 7.5 (v3.1) | High |
| CVE-2025-13339 | Hippoo Mobile App for WooCommerce <= 1.7.1 - Unauthenticated Arbitrary File Read | Hippoo Mobile App for WooCommerce | 7.5 (v3.1) | High |
| CVE-2025-13801 | Yoco Payments <= 3.8.8 - Path Traversal | Yoco Payments | 7.5 (v3.1) | High |
| CVE-2025-24963 | Vitest Browser Mode - Local File Read | vitest | 7.5 (v3.1) | High |
| CVE-2025-2539 | File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read | file away | 7.5 (v3.1) | High |
| CVE-2025-27817 | Apache Kafka Client - Arbitrary File Read | kafka | 7.5 (v3.1) | High |
| CVE-2025-31131 | Yeswiki < 4.5.2 - Unauthenticated Path Traversal | yeswiki | 7.5 (v3.1) | High |
| CVE-2025-45145 | Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 Path Traversal Vulnerability | - | 7.5 (v3.1) | High |
| CVE-2025-57231 | Path Traversal in avatar attachments in Docmost v0.21.0 Vulnerability | - | 7.5 (v3.1) | High |
| CVE-2025-61884 | Oracle E-Business Suite - Server-Side Request Forgery | configurator | 7.5 (v3.1) | High |
| CVE-2025-69411 | ionCube Tester Plus <= 1.3 - Local File Inclusion | ionCube tester plus | 7.5 (v3.1) | High |
| CVE-2026-1557 | WP Responsive Images <= 1.0 - Arbitrary File Read | WP Responsive Images | 7.5 (v3.1) | High |
| CVE-2026-23536 | Feast Feature Server <=0.58.0 - Arbitrary File Read | feast | 7.5 (v3.1) | High |
| CVE-2026-29962 | HSC MailInspector - Local File Inclusion | mailinspector | 7.5 (v3.1) | High |
| CVE-2026-32820 | dataCycle Public Markdown Path Traversal Via /docs/*path | dataCycle-CORE | 7.5 (v3.1) | High |
| CVE-2026-34239 | Chamilo Authenticated Remote Code Execution | chamilo-lms | 7.5 (v4.0) | High |
| CVE-2026-36783 | Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to Denial of Service Vulnerability | - | 7.5 (v3.1) | High |
| CVE-2026-36796 | Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to Denial of Service Vulnerability | - | 7.5 (v3.1) | High |
| CVE-2026-36851 | UnPoller 2.33.0 password field Path Traversal Vulnerability | UnPoller 2.33.0 password field | 7.5 (v3.1) | High |
| CVE-2026-39359 | Wazuh: Unauthenticated Path Traversal in authd via Agent Group Name | wazuh | 7.5 (v3.1) | High |
| CVE-2026-39844 | NiceGUI has a Path Traversal in NiceGUI Upload Filename on Windows via Backslash Bypass of PurePosixPath Sanitization | nicegui | 7.5 (v3.1) | High |
| CVE-2026-39847 | Emmett has a path traversal in internal assets handler | emmett | 7.5 (v3.1) | High |
| CVE-2026-46581 | mojarra Path Traversal Vulnerability | mojarra | 7.5 (v3.1) | High |
| CVE-2026-50776 | Pronis Loisirs Billetterie CSE - < 04/2026 Arbitrary Code Execution Vulnerability | Pronis Loisirs Billetterie CSE - < 04/2026 | 7.5 (v3.1) | High |
| CVE-2026-51078 | Dede CMS v.5.7.118 Information Disclosure Vulnerability | - | 7.5 (v3.1) | High |
| CVE-2026-53599 | Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mo | core | 7.5 (v3.1) | High |
| CVE-2026-5487 | DriveLock Directory Traversal Information Disclosure Vulnerability | DriveLock | 7.5 (v3.0) | High |
| CVE-2026-5491 | DriveLock Directory Traversal Information Disclosure Vulnerability | DriveLock | 7.5 (v3.0) | High |
| CVE-2026-55552 | Yamcs: Unauthenticated Directory Traversal | yamcs | 7.5 (v3.1) | High |
| CVE-2026-56671 | ComfyUI: Path traversal in /experiment/models/preview allows arbitrary image file read | ComfyUI | 7.5 (v3.1) | High |
| CVE-2026-59765 | SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata | Gitea Open Source Git Server | 7.5 (v3.1) | High |
| CVE-2026-61891 | theia Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | theia | 7.5 (v3.1) | High |
| CVE-2026-71209 | audiobookshelf - %2F Encoding Discrepancy Bypasses Cover/Image Auth Exemption Regex, Enabling Unauthenticated Path Trave | audiobookshelf | 7.5 (v3.1) | High |
| CVE-2026-75328 | In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java Path Traversal Vulnerability | In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java | 7.5 (v3.1) | High |
| CVE-2026-75333 | yx-image-recognition v1.0 Path Traversal Vulnerability | - | 7.5 (v3.1) | High |
| CVE-2026-79407 | the SPO extension of MetaGPT 0.8.1 Path Traversal Vulnerability | the SPO extension of MetaGPT 0.8.1 | 7.5 (v3.1) | High |
| CVE-2026-81265 | Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches | Langflow OSS | 7.5 (v3.1) | High |
| CVE-2026-9282 | W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read | W3 Total Cache | 7.5 (v3.1) | High |
| CVE-2026-49857 | auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 Loopback | auth-fetch-mcp | 7.4 (v3.1) | High |
| CVE-2026-70666 | Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs | lemur | 7.4 (v3.1) | High |
| CVE-2026-10870 | Shibby Tomato Web UI rc start_dhcpc os command injection | Tomato | 7.3 (v4.0) | High |
| CVE-2026-10871 | Shibby Tomato Web UI rc start_6rd_tunnel os command injection | Tomato | 7.3 (v4.0) | High |
| CVE-2026-10873 | Shibby Tomato Web UI rstats rstats_path os command injection | Tomato | 7.3 (v4.0) | High |
| CVE-2026-18900 | H3C NX15 Backend RPC esps file.exec os command injection | NX15 | 7.3 (v4.0) | High |
| CVE-2026-19771 | Baicells EG3661M LuCI Web luci os command injection | EG3661M | 7.3 (v4.0) | High |
| CVE-2026-15244 | HUSKY - Products Filter Professional for WooCommerce < 1.4.1 - Shop Manager+ Local File Inclusion via meta_filter search | HUSKY | 7.2 (v3.1) | High |
| CVE-2026-15686 | Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability | Adminer | 7.2 (v3.0) | High |
| CVE-2026-18274 | Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability | Database Proxy | 7.2 (v3.0) | High |
| CVE-2026-20297 | Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise | splunk | 7.2 (v3.1) | High |
| CVE-2026-27891 | Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanism | facturascripts | 7.2 (v3.1) | High |
| CVE-2026-33715 | Chamilo LMS has Unauthenticated SSRF and Open Email Relay via install.ajax.php test_mailer action | chamilo lms | 7.2 (v3.1) | High |
| CVE-2026-34607 | Emlog: Path Traversal in emUnZip() allows arbitrary file write leading to RCE | emlog | 7.2 (v3.1) | High |
| CVE-2026-34968 | Adminer before 5.4.3 Arbitrary File Deletion via SQLite Drop | adminer | 7.2 (v4.0) | High |
| CVE-2026-35174 | Chyrp Lite has a Path Traversal to Remote Code Execution | chyrp lite | 7.2 (v3.1) | High |
| CVE-2026-3576 | Planyo Online Reservation System <= 3.0 - Arbitrary File Read | Planyo online reservation system | 7.2 (v3.1) | High |
| CVE-2026-39387 | BoidCMS: Local File Inclusion (LFI) leads to Remote Code Execution (RCE) via tpl parameter | boidcms | 7.2 (v3.1) | High |
| CVE-2026-45019 | Chainlit: SSRF via MCP SSE and streamable-http transports allows unauthenticated internal network access | chainlit | 7.2 (v3.1) | High |
| CVE-2026-6229 | Royal Addons for Elementor <= 1.7.1057 - Authenticated (Contributor+) Server-Side Request Forgery via CSV URL Parameter | Royal Addons for Elementor – Addons and Templates Kit for Elementor | 7.2 (v3.1) | High |
| CVE-2026-71284 | Fledge IoT Gateway Backup Restore OS Command Injection via Tar Member Filename | fledge | 7.2 (v3.1) | High |
| CVE-2026-85160 | AVideo through c91b5975d CSRF and Path Traversal via stopLive.php | AVideo | 7.2 (v4.0) | High |
| CVE-2018-25393 | Navigate CMS 2.8.5 Path Traversal via navigate_download.php | Navigate CMS | 7.1 (v4.0) | High |
| CVE-2018-25421 | Open STA Manager 2.3 Arbitrary File Download via Path Traversal | Open STA Manager | 7.1 (v4.0) | High |
| CVE-2019-25246 | BEWARD N100 H.264 VGA IP Camera M2.1.6 - Arbitrary File Disclosure | N100 H.264 VGA IP Camera | 7.1 (v4.0) | High |
| CVE-2026-22664 | prompts.chat SSRF via Fal.ai Media Status Polling | prompts.chat | 7.1 (v4.0) | High |
| CVE-2026-39370 | WWBN AVideo has an Allowlisted downloadURL media extensions bypass SSRF protection and enable internal response exfiltr | avideo | 7.1 (v3.1) | High |
| CVE-2026-40526 | Volmarg Personal Management System Path Traversal via get-file Endpoint | personal-management-system | 7.1 (v4.0) | High |
| CVE-2026-42339 | New API: SSRF Filter Bypass via 0.0.0.0 | new api | 7.1 (v4.0) | High |
| CVE-2026-46555 | WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltration | whatsapp mcp server | 7.1 (v3.1) | High |
| CVE-2026-47735 | Arc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checks | arc | 7.1 (v4.0) | High |
| CVE-2026-54166 | Shelf Vulnerable to Server-Side Request Forgery (SSRF) via Asset CSV Import imageUrl Validation Bypass | shelf.nu | 7.1 (v3.1) | High |
| CVE-2026-55537 | PraisonAI: Webhook SSRF via DNS fail-open in JobSubmitRequest.validate_webhook_url() — bypass of CVE-2026-40114 | PraisonAI | 7.1 (v3.1) | High |
| CVE-2026-64826 | rConfig < 8.2.13 Path Traversal File Read via FileDownloadController | rConfig | 7.1 (v4.0) | High |
| CVE-2026-71964 | CyberPanel 2.4.3 Arbitrary File Read via File Manager ZIP Upload | cyberpanel | 7.1 (v4.0) | High |
| CVE-2026-72695 | Grav before 2.0.16 Path Traversal via MediaUploadTrait deleteFile | grav | 7.1 (v4.0) | High |
| CVE-2026-74247 | Quay: ssrf via build archive_url in quay build api | openshift update service | 7.1 (v3.1) | High |
| CVE-2026-75830 | grav-plugin-api before 1.0.15 Path Traversal via batchCopy | grav | 7.1 (v4.0) | High |
| CVE-2026-75844 | ArcadeDB before 26.8.1 SSRF via IMPORT DATABASE validator bypass | arcadedb | 7.1 (v4.0) | High |
| CVE-2026-76210 | phpMyFAQ before v4.1.6 Local File Disclosure via PDF Export | phpmyfaq | 7.1 (v4.0) | High |
| CVE-2026-77939 | Flextype CMS 1.0.0-dev RCE via POST /api/v1/query Endpoint | flextype | 7.1 (v4.0) | High |
| CVE-2026-79747 | MCPHub vulnerable to SSRF: a non-admin user can make mcphub request arbitrary URLs and read the response (OpenAPI proxy | mcphub | 7.1 (v3.1) | High |
| CVE-2026-79788 | Dradis Community Edition 5.1.0 through 5.2.0 Server-Side Request Forgery via Unrestricted AI Provider Address | dradis-ce | 7.1 (v4.0) | High |
| CVE-2026-80350 | OneUptime before 12.0.7 Server-Side Request Forgery via IPv4-Mapped IPv6 Webhook URL | OneUptime | 7.1 (v4.0) | High |
| CVE-2026-81030 | Mage AI through 0.9.79 Arbitrary File Read via Unvalidated Path in browser_items Endpoint | mage-ai | 7.1 (v4.0) | High |
| CVE-2026-82241 | Budibase backend-core SSRF via incomplete default blacklist | server | 7.1 (v4.0) | High |
| CVE-2026-82246 | Budibase Server before 3.41.3 SSRF via Query Import | server | 7.1 (v4.0) | High |
| CVE-2026-82877 | ILIAS before 9.22 Arbitrary File Read via SOAP addFile | ILIAS | 7.1 (v4.0) | High |
| CVE-2026-85163 | AVideo Server-Side Request Forgery via epg_link parameter | AVideo | 7.1 (v4.0) | High |
| CVE-2026-85164 | WWBN AVideo Server-Side Request Forgery via set_api_userImages | AVideo | 7.1 (v4.0) | High |
| CVE-2026-87821 | Lara Dashboard 0.9.2 through 1.3.1 Server-Side Request Forgery in Builder Markdown Fetch | laradashboard | 7.1 (v4.0) | High |
| CVE-2026-87999 | Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch | open-webui | 7.1 (v3.1) | High |
| CVE-2026-88938 | knowns through 0.33.0 Path Traversal via code.find MCP tool | knowns | 7.1 (v4.0) | High |
| CVE-2026-10107 | MoviePilot v2 SSRF via /api/v1/system/img/{proxy} Endpoint | MoviePilot | 7.0 (v4.0) | High |
| CVE-2026-40506 | OpenEMR Path Traversal Arbitrary Directory Deletion via standard_tables_manage.php | openemr | 7.0 (v4.0) | High |
| CVE-2026-54134 | OctoPrint: File exfiltration possible via query parameters on upload endpoints | OctoPrint | 7.0 (v4.0) | High |
| CVE-2026-73033 | Sucuri WordPress Plugin 2.7.3 Path Traversal via integrity.lib.php | sucuri-wordpress-plugin | 7.0 (v4.0) | High |
| CVE-2026-74038 | Wazuh 4.0.0 < 4.14.6 Path Traversal DoS via Agent Enrollment | wazuh-manager | 7.0 (v4.0) | High |
| CVE-2019-25760 | Joomla! Component Easy Shop 1.2.3 Local File Inclusion | easy shop | 6.9 (v4.0) | Medium |
| CVE-2022-50954 | WordPress Plugin cab-fare-calculator 1.0.3 Local File Inclusion | cab-fare-calculator | 6.9 (v4.0) | Medium |
| CVE-2022-50956 | WordPress Plugin amministrazione-aperta 3.7.3 Local File Read | amministrazione-aperta | 6.9 (v4.0) | Medium |
| CVE-2025-1743 | Pichome 2.1.0 - Arbitrary File Read | Pichome | 6.9 (v4.0) | Medium |
| CVE-2026-11450 | GL.iNet GL-MT3000 Path Normalization dlopen command injection | GL-MT3000 | 6.9 (v4.0) | Medium |
| CVE-2026-19983 | GL.iNet XE3000 NAS Command Service gl_nas_sys os command injection | A1300 | 6.9 (v4.0) | Medium |
| CVE-2026-34964 | Adminer before 5.5.0 SSRF via PDO DSN Injection | adminer | 6.9 (v4.0) | Medium |
| CVE-2026-39383 | Gotenberg unauthenticated blind SSRF via unfiltered webhook URL | gotenberg | 6.9 (v4.0) | Medium |
| CVE-2026-41917 | OpenKM 6.3.12 Local File Inclusion via Admin Scripting | OpenKM Community Edition | 6.9 (v4.0) | Medium |
| CVE-2026-44652 | SillyTavern: SSRF vulnerability in the CORS proxy middleware | SillyTavern | 6.9 (v4.0) | Medium |
| CVE-2026-45731 | WWBN AVideo: Authenticated Arbitrary File Read in view/update.php | avideo | 6.9 (v4.0) | Medium |
| CVE-2026-45774 | compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal | compliance-trestle | 6.9 (v4.0) | Medium |
| CVE-2026-46337 | WWBN AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in view/img/image404Raw.php | avideo | 6.9 (v4.0) | Medium |
| CVE-2026-53757 | Emlog: Zip Slip Path Traversal in Plugin/Template ZIP Upload Enables RCE | emlog | 6.9 (v4.0) | Medium |
| CVE-2026-54885 | Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri fetching | boruta | 6.9 (v4.0) | Medium |
| CVE-2026-5739 | PowerJob OpenAPI Endpoint addWorkflowNode GroovyEvaluator.evaluate code injection | PowerJob | 6.9 (v4.0) | Medium |
| CVE-2026-71932 | DrayTek VigorSwitch Multiple Models Path Traversal via getSyslogFile | VigorSwitch G2540xs | 6.9 (v4.0) | Medium |
| CVE-2026-73058 | stoatchat before 0.15.0 SSRF via IPv6 unspecified address bypass | stoatchat | 6.9 (v4.0) | Medium |
| CVE-2026-74235 | GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Configuration Download Handler | GFI Exinda AI | 6.9 (v4.0) | Medium |
| CVE-2026-75592 | Kirby: Access to image files outside of the site root via path traversal in the media handling | kirby | 6.9 (v4.0) | Medium |
| CVE-2026-79743 | MCPHub: Path Traversal via Malicious MCPB Manifest Name | mcphub | 6.9 (v4.0) | Medium |
| CVE-2026-79773 | Winter CMS before 1.2.13 Local File Inclusion via JavaScript | winter | 6.9 (v4.0) | Medium |
| CVE-2026-79781 | rclone serve s3 Path Traversal via dot-dot object keys | rclone | 6.9 (v4.0) | Medium |
| CVE-2026-81678 | AVideo SSRF Guard Bypass via IPv6 Transition Addresses | AVideo | 6.9 (v4.0) | Medium |
| CVE-2026-82233 | SiYuan before v3.8.1 Path Traversal via asset.upload | siyuan | 6.9 (v4.0) | Medium |
| CVE-2026-84199 | Kyverno before 1.16.2 SSRF via APICall Feature | kyverno | 6.9 (v4.0) | Medium |
| CVE-2026-85609 | Openpanel before 2.3.0 SSRF via Site Checker Endpoint | openpanel | 6.9 (v4.0) | Medium |
| CVE-2026-85662 | Marqo 2.26.0 Server-Side Request Forgery via Media URLs | marqo | 6.9 (v4.0) | Medium |
| CVE-2026-86539 | knowns through 0.33.0 Server-Side Request Forgery via embedding-models endpoint | knowns | 6.9 (v4.0) | Medium |
| CVE-2026-86806 | opengeos GeoLibre _is_within_roots server-side request forgery | GeoLibre | 6.9 (v4.0) | Medium |
| CVE-2026-8712 | Wyoming < 1.10.2 SSRF via uri Query Parameter | wyoming | 6.9 (v4.0) | Medium |
| CVE-2026-88940 | knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint | knowns | 6.9 (v4.0) | Medium |
| CVE-2007-4556 | OpenSymphony XWork/Apache Struts2 - Remote Code Execution | xwork | 6.8 (v2.0) | Medium |
| CVE-2008-2650 | CMSimple 3.1 - Local File Inclusion | cmsimple | 6.8 (v2.0) | Medium |
| CVE-2008-6172 | Joomla! Component RWCards 3.0.11 - Local File Inclusion | rwcards | 6.8 (v2.0) | Medium |
| CVE-2009-3053 | Joomla! Agora 3.0.0b - Local File Inclusion | Joomla! | 6.8 (v2.0) | Medium |
| CVE-2010-1056 | Joomla! Component com_rokdownloads - Local File Inclusion | com rokdownloads | 6.8 (v2.0) | Medium |
| CVE-2010-1219 | Joomla! Component com_janews - Local File Inclusion | com janews | 6.8 (v2.0) | Medium |
| CVE-2010-1469 | Joomla! Component JProject Manager 1.0 - Local File Inclusion | com jprojectmanager | 6.8 (v2.0) | Medium |
| CVE-2010-1473 | Joomla! Component Advertising 0.25 - Local File Inclusion | com advertising | 6.8 (v2.0) | Medium |
| CVE-2010-1474 | Joomla! Component Sweetykeeper 1.5 - Local File Inclusion | com sweetykeeper | 6.8 (v2.0) | Medium |
| CVE-2010-1475 | Joomla! Component Preventive And Reservation 1.0.5 - Local File Inclusion | com preventive | 6.8 (v2.0) | Medium |
| CVE-2010-1476 | Joomla! Component AlphaUserPoints 1.5.5 - Local File Inclusion | com alphauserpoints | 6.8 (v2.0) | Medium |
| CVE-2010-1478 | Joomla! Component Jfeedback 1.2 - Local File Inclusion | com jfeedback | 6.8 (v2.0) | Medium |
| CVE-2010-1607 | Joomla! Component WMI 1.5.0 - Local File Inclusion | com wmi | 6.8 (v2.0) | Medium |
| CVE-2010-1715 | Joomla! Component Online Exam 1.5.0 - Local File Inclusion | com onlineexam | 6.8 (v2.0) | Medium |
| CVE-2010-1718 | Joomla! Component Archery Scores 1.0.6 - Local File Inclusion | com archeryscores | 6.8 (v2.0) | Medium |
| CVE-2010-1719 | Joomla! Component MT Fire Eagle 1.2 - Local File Inclusion | com mtfireeagle | 6.8 (v2.0) | Medium |
| CVE-2010-1722 | Joomla! Component Online Market 2.x - Local File Inclusion | com market | 6.8 (v2.0) | Medium |
| CVE-2010-1723 | Joomla! Component iNetLanka Contact Us Draw Root Map 1.1 - Local File Inclusion | com drawroot | 6.8 (v2.0) | Medium |
| CVE-2010-1979 | Joomla! Component Affiliate Datafeeds 880 - Local File Inclusion | com datafeeds | 6.8 (v2.0) | Medium |
| CVE-2010-1981 | Joomla! Component Fabrik 2.0 - Local File Inclusion | fabrik | 6.8 (v2.0) | Medium |
| CVE-2010-2122 | Joomla! Component simpledownload <=0.9.5 - Arbitrary File Retrieval | com simpledownload | 6.8 (v2.0) | Medium |
| CVE-2010-2507 | Joomla! Component Picasa2Gallery 1.2.8 - Local File Inclusion | com picasa2gallery | 6.8 (v2.0) | Medium |
| CVE-2010-2680 | Joomla! Component jesectionfinder - Local File Inclusion | com jesectionfinder | 6.8 (v2.0) | Medium |
| CVE-2010-2857 | Joomla! Component Music Manager - Local File Inclusion | com music | 6.8 (v2.0) | Medium |
| CVE-2010-2920 | Joomla! Component Foobla Suggestions 1.5.1.2 - Local File Inclusion | com foobla suggestions | 6.8 (v2.0) | Medium |
| CVE-2010-4617 | Joomla! Component JotLoader 2.2.1 - Local File Inclusion | com jotloader | 6.8 (v2.0) | Medium |
| CVE-2011-2744 | Chyrp 2.x - Local File Inclusion | chyrp | 6.8 (v2.0) | Medium |
| CVE-2011-4449 | WikkaWiki 1.3.2 - Multiple Vulnerabilities | wikkawiki | 6.8 (v2.0) | Medium |
| CVE-2011-4452 | WikkaWiki 1.3.2 - Multiple Vulnerabilities | wikkawiki | 6.8 (v2.0) | Medium |
| CVE-2012-0392 | Apache Struts2 S2-008 RCE | struts | 6.8 (v2.0) | Medium |
| CVE-2014-2383 | Dompdf < v0.6.0 - Local File Inclusion | dompdf | 6.8 (v2.0) | Medium |
| CVE-2025-59709 | biztalk360 Path Traversal Vulnerability | biztalk360 | 6.8 (v3.1) | Medium |
| CVE-2026-35593 | Trilium Notes has Local File Inclusion via upload modified file API endpoint | Trilium | 6.8 (v3.1) | Medium |
| CVE-2026-55421 | Open edX Platform: SSRF in Studio Video Download Endpoint | openedx-platform | 6.8 (v3.1) | Medium |
| CVE-2026-71475 | Insights-client-rhel9: insights-client: spoke-controlled clusterid injected unencoded into insights api url path | advanced cluster management for kubernetes | 6.8 (v3.1) | Medium |
| CVE-2026-10821 | Yoast SEO Premium < 27.6.1 - Author+ Arbitrary .htaccess Directive Injection to RCE | Yoast SEO Premium | 6.6 (v3.1) | Medium |
| CVE-2026-34216 | CtrlPanel: Authenticated Remote Code Execution via Dynamic Class Instantiation in SettingsController.php | panel | 6.6 (v3.1) | Medium |
| CVE-2013-4861 | MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities | veralite firmware | 6.5 (v3.1) | Medium |
| CVE-2013-4865 | MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities | veralite firmware | 6.5 (v3.1) | Medium |
| CVE-2016-6435 | Cisco Firepower Threat Management Console 6.0.1 - Local File Inclusion | secure firewall management center | 6.5 (v3.0) | Medium |
| CVE-2017-14537 | Trixbox 2.8.0 - Path Traversal | trixbox | 6.5 (v3.1) | Medium |
| CVE-2018-15140 | OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions | openemr | 6.5 (v3.0) | Medium |
| CVE-2018-15141 | OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions | openemr | 6.5 (v3.0) | Medium |
| CVE-2018-18760 | RhinOS CMS 3.x - Arbitrary File Download | rhinos | 6.5 (v3.0) | Medium |
| CVE-2019-14312 | Aptana Jaxer 1.0.3.4547 - Local File inclusion | jaxer | 6.5 (v3.0) | Medium |
| CVE-2021-24947 | WordPress Responsive Vector Maps < 6.4.2 - Arbitrary File Read | responsive vector maps | 6.5 (v3.1) | Medium |
| CVE-2021-28149 | Hongdian H8922 3.0.5 Devices - Local File Inclusion | h8922 firmware | 6.5 (v3.1) | Medium |
| CVE-2021-29006 | rConfig 3.9.6 - Local File Inclusion | rconfig | 6.5 (v3.1) | Medium |
| CVE-2021-36749 | Apache Druid - Local File Inclusion | druid | 6.5 (v3.1) | Medium |
| CVE-2021-40651 | OS4Ed OpenSIS Community 8.0 - Local File Inclusion | opensis | 6.5 (v3.1) | Medium |
| CVE-2022-34125 | GLPI Activity v3.1.0 - Authenticated Local File Inclusion on Activity plugin | cmdb | 6.5 (v3.1) | Medium |
| CVE-2022-37299 | Shirne CMS 1.2.0 - Local File Inclusion | shirne cms | 6.5 (v3.1) | Medium |
| CVE-2024-24565 | CrateDB Database - Arbitrary File Read | cratedb | 6.5 (v3.1) | Medium |
| CVE-2024-27564 | ChatGPT个人专用版 - Server Side Request Forgery | chatgpt web | 6.5 (v3.1) | Medium |
| CVE-2024-36527 | Puppeteer Renderer - Directory Traversal | - | 6.5 (v3.1) | Medium |
| CVE-2024-55457 | MasterSAM Star Gate v11 - Local File Inclusion | - | 6.5 (v3.1) | Medium |
| CVE-2024-9765 | EKC Tournament Manager WordPress plugin - Path Traversal | ekc tournament manager | 6.5 (v3.1) | Medium |
| CVE-2025-28367 | mojoPortal <=2.9.0.1 - Directory Traversal | mojoportal | 6.5 (v3.1) | Medium |
| CVE-2025-32815 | NetMRI < 7.6.1 - Authentication Bypass via Hardcoded Credentials | netmri | 6.5 (v3.1) | Medium |
| CVE-2025-45870 | LogicalDOC Enterprise up to and for v9.1.1 Path Traversal Vulnerability | - | 6.5 (v3.1) | Medium |
| CVE-2026-11442 | Allegra exportReport Directory Traversal Information Disclosure Vulnerability | Allegra | 6.5 (v3.0) | Medium |
| CVE-2026-12898 | All-in-One WP Migration and Backup < 7.106 - Arbitrary Log File Write | all-in-one-wp-migration | 6.5 (v3.1) | Medium |
| CVE-2026-14470 | Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base compone | langflow | 6.5 (v3.1) | Medium |
| CVE-2026-15974 | sglang Server-Side Request Forgery Vulnerability | sglang | 6.5 (v3.1) | Medium |
| CVE-2026-34740 | AVideo: Stored SSRF via Video EPG Link Missing isSSRFSafeURL() Validation | avideo | 6.5 (v3.1) | Medium |
| CVE-2026-34787 | Emlog: Local File Inclusion in plugin.php via unsanitized plugin parameter | emlog | 6.5 (v3.1) | Medium |
| CVE-2026-35718 | fd8136 firmware Path Traversal Vulnerability | fd8136 firmware | 6.5 (v3.1) | Medium |
| CVE-2026-36227 | Easy Chat Server 3.1 Arbitrary Code Execution Vulnerability | Easy Chat Server 3.1 | 6.5 (v3.1) | Medium |
| CVE-2026-39368 | WWBN AVideo has a Live restream log callback flow enabling stored SSRF to internal services | avideo | 6.5 (v3.1) | Medium |
| CVE-2026-46397 | haxcms-php Local File Inclusion via saveOutline API Location Parameter v2.0 | haxcms-php | 6.5 (v3.1) | Medium |
| CVE-2026-46556 | FlaskBB: SSRF in get_image_info() via unrestricted avatar URL | flaskbb | 6.5 (v3.1) | Medium |
| CVE-2026-52371 | xxl-job v3.4.0 Server-Side Request Forgery Vulnerability | xxl-job v3.4.0 | 6.5 (v3.1) | Medium |
| CVE-2026-52607 | reportico-web <= 8.1.0 Path Traversal Vulnerability | reportico-web <= 8.1.0 | 6.5 (v3.1) | Medium |
| CVE-2026-54054 | Transmute has full-read SSRF in URL file import (POST /api/files/url) — no host/IP validation, follows redirects | transmute | 6.5 (v3.1) | Medium |
| CVE-2026-58442 | Repository migration SSRF via multi-answer DNS allow-list bypass | Gitea Open Source Git Server | 6.5 (v3.1) | Medium |
| CVE-2026-63667 | ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal | apostrophe | 6.5 (v3.1) | Medium |
| CVE-2026-72739 | Dokploy: Command Injection via Compose Shell Execution | dokploy | 6.5 (v3.1) | Medium |
| CVE-2026-73255 | Mongoose: Path traversal in SSI #include directives enables arbitrary file read | mongoose | 6.5 (v3.1) | Medium |
| CVE-2026-73573 | zimbra collaboration suite Path Traversal Vulnerability | zimbra collaboration suite | 6.5 (v3.1) | Medium |
| CVE-2026-73574 | zimbra collaboration suite Incorrect Resource Transfer Between Spheres Vulnerability | zimbra collaboration suite | 6.5 (v3.1) | Medium |
| CVE-2026-75602 | OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool | OpenList | 6.5 (v3.1) | Medium |
| CVE-2026-7646 | Langflow is affected by security vulnerabilities in Model Context Protocol features | langflow | 6.5 (v3.1) | Medium |
| CVE-2026-7658 | Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement | langflow | 6.5 (v3.1) | Medium |
| CVE-2026-9138 | Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing c | langflow | 6.5 (v3.1) | Medium |
| CVE-2009-0932 | Horde/Horde Groupware - Local File Inclusion | horde | 6.4 (v2.0) | Medium |
| CVE-2011-4450 | WikkaWiki 1.3.2 - Multiple Vulnerabilities | wikkawiki | 6.4 (v2.0) | Medium |
| CVE-2026-45573 | Decidim: Push subscriptions can be abused for server-side requests | decidim | 6.4 (v3.1) | Medium |
| CVE-2026-79717 | Galaxy_ng: galaxy_ng: blind ssrf via namespace avatar_url with no private-address restriction | Red Hat Ansible Automation Platform 2 | 6.4 (v3.1) | Medium |
| CVE-2026-82081 | wallabag Server-Side Request Forgery Vulnerability | wallabag | 6.4 (v3.1) | Medium |
| CVE-2026-34371 | LibreChat Affected by Arbitrary File Write via execute_code Artifact Filename Traversal | librechat | 6.3 (v3.1) | Medium |
| CVE-2026-39365 | Vite has a Path Traversal in Optimized Deps .map Handling | vite | 6.3 (v4.0) | Medium |
| CVE-2026-42335 | MaxKB: SSRF Bypass in MaxKB OSS URL Fetch due to URL Parsing Discrepancy | MaxKB | 6.3 (v4.0) | Medium |
| CVE-2026-42344 | FastGPT: DNS rebinding TOCTOU bypass in isInternalAddress allows SSRF on all protected endpoints | FastGPT | 6.3 (v3.1) | Medium |
| CVE-2026-44284 | FastGPT: Stored MCP tool URL SSRF in FastGPT workflow execution | FastGPT | 6.3 (v3.1) | Medium |
| CVE-2026-44287 | FastGPT: sandbox escape to RCE - code-sandbox regex /\bimport\s*(/ is bypassable | FastGPT | 6.3 (v3.1) | Medium |
| CVE-2026-45626 | Arcane: OS Command Injection in Volume Browser ListDirectory via path query parameter | arcane | 6.3 (v3.1) | Medium |
| CVE-2026-49120 | Medplum < 5.1.14 SSRF via FHIR Subscription Endpoint | medplum | 6.3 (v4.0) | Medium |
| CVE-2026-54020 | Open WebUI: DNS Rebinding SSRF Bypass | open-webui | 6.3 (v3.1) | Medium |
| CVE-2026-56722 | Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI | dompdf | 6.3 (v4.0) | Medium |
| CVE-2026-63107 | LimeSurvey SSRF via REST API Survey Template Host Header | LimeSurvey | 6.3 (v4.0) | Medium |
| CVE-2026-63643 | MagicMirror: ssrf calendar .js | MagicMirror | 6.3 (v4.0) | Medium |
| CVE-2026-63731 | HyperDX < 2.31.0 SSRF via ClickHouse Proxy Test Endpoint | hyperdx | 6.3 (v4.0) | Medium |
| CVE-2026-63769 | Huginn 2022.08.18 SSRF via ScenarioImport fetch_url Method | huginn | 6.3 (v4.0) | Medium |
| CVE-2026-65012 | InvokeAI < 6.13.7 Unauthenticated Directory Enumeration via scan_folder | InvokeAI | 6.3 (v4.0) | Medium |
| CVE-2026-65593 | n8n before 1.123.64, 2.29.8, and 2.30.1 SSRF via Dynamic Node Parameters | n8n | 6.3 (v4.0) | Medium |
| CVE-2026-67620 | Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-List | flowise | 6.3 (v4.0) | Medium |
| CVE-2026-70667 | Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fi | lemur | 6.3 (v3.1) | Medium |
| CVE-2026-72814 | actix-web before 0.6.10 Information Disclosure via Files | actix-web | 6.3 (v4.0) | Medium |
| CVE-2026-72860 | 9router Server-Side Request Forgery via /api/provider-nodes/validate Because the IPv4-Mapped IPv6 Denylist Check Is Unre | 9router | 6.3 (v4.0) | Medium |
| CVE-2026-73530 | Flyto2 Core < 2.28.0 SSRF Guard Bypass via is_private_ip() | flyto-core | 6.3 (v4.0) | Medium |
| CVE-2026-78886 | liketrek TREK Public Journey Photo Proxy journey-public.controller.ts path traversal | TREK | 6.3 (v4.0) | Medium |
| CVE-2026-86590 | Eclipse Che Server-Side Request Forgery Vulnerability | Eclipse Che | 6.3 (v4.0) | Medium |
| CVE-2014-8727 | F5 BIG-IP 10.1.0 - Directory Traversal | big-ip local traffic manager | 6.2 (v2.0) | Medium |
| CVE-2015-4668 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 6.1 (v3.0) | Medium |
| CVE-2026-70620 | Odysseus SSRF via Embedding Endpoint Configuration | odysseus | 6.1 (v4.0) | Medium |
| CVE-2026-41363 | OpenClaw 2026.2.6 < 2026.3.28 - Arbitrary File Read via Feishu upload_image Parameter | openclaw | 6.0 (v4.0) | Medium |
| CVE-2026-65698 | Void 1.3.4 Path Traversal via AI Agent File-Reading Tools | void | 6.0 (v4.0) | Medium |
| CVE-2026-66004 | BlenderMCP Path Traversal via download_polyhaven_asset API | blender-mcp | 6.0 (v4.0) | Medium |
| CVE-2026-79653 | Eclipse SW360 Path Traversal Vulnerability | Eclipse SW360 | 6.0 (v4.0) | Medium |
| CVE-2026-13693 | Bit Form < 3.1.0 - Unauthenticated Arbitrary File Read via Path Traversal | Bit Form | 5.9 (v3.1) | Medium |
| CVE-2026-49244 | SFTPGo: Path confinement bypass in public browsable share partial ZIP download | sftpgo | 5.9 (v3.1) | Medium |
| CVE-2026-82650 | SiYuan before v3.8.1 Path Traversal via /api/template/render | siyuan | 5.9 (v4.0) | Medium |
| CVE-2026-86735 | snipe-it before 8.7.0 SSRF via IPv6 transition address bypass | snipe-it | 5.9 (v4.0) | Medium |
| CVE-2010-0467 | Joomla! Component CCNewsLetter - Local File Inclusion | com ccnewsletter | 5.8 (v3.1) | Medium |
| CVE-2024-6095 | LocalAI - Partial Local File Read | localai | 5.8 (v3.1) | Medium |
| CVE-2026-10526 | EmbedPress < 4.6.1 - Unauthenticated Blind SSRF | EmbedPress | 5.8 (v3.1) | Medium |
| CVE-2026-34360 | HAPI FHIR: Unauthenticated Blind SSRF via /loadIG Endpoint Enables Internal Network Probing | hl7 fhir core | 5.8 (v3.1) | Medium |
| CVE-2026-45709 | Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filte | mailpit | 5.8 (v3.1) | Medium |
| CVE-2026-48053 | Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewset | kolibri | 5.8 (v3.1) | Medium |
| CVE-2026-73243 | kkFileView: Unauthenticated SSRF via /addTask with fullfilename type-confusion bypass | kkFileView | 5.8 (v3.1) | Medium |
| CVE-2025-1035 | KLog Server - Path Traversal | KLog Server | 5.7 (v3.1) | Medium |
| CVE-2026-40605 | Tautulli Vulnerable to Authenticated Path Traversal in Cache Deletion API | Tautulli | 5.7 (v4.0) | Medium |
| CVE-2018-13980 | Zeta Producer Desktop CMS <14.2.1 - Local File Inclusion | zeta producer | 5.5 (v3.1) | Medium |
| CVE-2018-15536 | Responsive FileManager < 9.13.4 - Directory Traversal | responsive filemanager | 5.5 (v3.0) | Medium |
| CVE-2025-13786 | taosir WTCMS index.php fetch code injection | wtcms | 5.5 (v4.0) | Medium |
| CVE-2025-13792 | Qualitor getResumo.php eval code injection | the file /html/st/stdeslocamento/request/getResumo.php | 5.5 (v4.0) | Medium |
| CVE-2025-13810 | jsnjfz WebStack-Guns KaptchaController.java renderPicture path traversal | webstack-guns | 5.5 (v4.0) | Medium |
| CVE-2025-13814 | moxi159753 Mogu Blog v2 uploadPicsByUrl LocalFileServiceImpl.uploadPictureByUrl server-side request forgery | mogublog | 5.5 (v4.0) | Medium |
| CVE-2026-10214 | zhayujie chatgpt-on-wechat Bash Tool bash.py _get_safety_warning os command injection | chatgpt-on-wechat | 5.5 (v4.0) | Medium |
| CVE-2026-10280 | horizon921 mcpilot MCP API Call Endpoint route.ts server-side request forgery | mcpilot | 5.5 (v4.0) | Medium |
| CVE-2026-10287 | SourceCodester SEO Meta Tag Extractor index.php get_headers server-side request forgery | SEO Meta Tag Extractor | 5.5 (v4.0) | Medium |
| CVE-2026-10694 | SourceCodester Online Food Ordering System index.php include file inclusion | Online Food Ordering System | 5.5 (v4.0) | Medium |
| CVE-2026-16125 | zevorn rt-claw http_request net.c claw_net_post server-side request forgery | rt-claw | 5.5 (v4.0) | Medium |
| CVE-2026-16127 | zevorn rt-claw http_request tool_net.c claw_net_post server-side request forgery | rt-claw | 5.5 (v4.0) | Medium |
| CVE-2026-16128 | zevorn rt-claw http_request swarm.c receiver_thread server-side request forgery | rt-claw | 5.5 (v4.0) | Medium |
| CVE-2026-16252 | Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System Staffshinel Ds.jsp sql injection | Multimedia Integrated Business Display System | 5.5 (v4.0) | Medium |
| CVE-2026-16910 | Quay: ssrf in red hat quay notification webhooks (slack/generic) | Red Hat OpenShift Update Service | 5.5 (v3.1) | Medium |
| CVE-2026-18641 | Sangfor Operation and Maintenance Security Management System Login Endpoint portal_login com.sbr.fort.foreignDP.DpLoginC | Operation and Maintenance Security Management System | 5.5 (v4.0) | Medium |
| CVE-2026-18646 | danpros HTMLy Author Name htmly.php path traversal | HTMLy | 5.5 (v4.0) | Medium |
| CVE-2026-18973 | heshengtao super-agent-party extension_proxy Route server.py sanitize_proxy_url server-side request forgery | super-agent-party | 5.5 (v4.0) | Medium |
| CVE-2026-19000 | JeecgBoot Anonymous Chat Attachment send server-side request forgery | JeecgBoot | 5.5 (v4.0) | Medium |
| CVE-2026-19374 | adafap api-mcp Proxy API Endpoint route.ts customAxios server-side request forgery | api-mcp | 5.5 (v4.0) | Medium |
| CVE-2026-19379 | EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injection | ipTIME AX8004M | 5.5 (v4.0) | Medium |
| CVE-2026-19753 | Model Context Protocol mcp-rdf-explorer MCP Server server.py explore_url server-side request forgery | mcp-rdf-explorer | 5.5 (v4.0) | Medium |
| CVE-2026-19758 | dromara lamp-cloud chunk-check endpoint FileChunkController.java path traversal | lamp-cloud | 5.5 (v4.0) | Medium |
| CVE-2026-19762 | DTStack Taier Chunk-Check Endpoint FileChunkController.java Paths.ge path traversal | Taier | 5.5 (v4.0) | Medium |
| CVE-2026-19827 | alldatacenter alldata logDetailCat Endpoint JobLogController.java FileInputStream path traversal | alldata | 5.5 (v4.0) | Medium |
| CVE-2026-5346 | huimeicloud hm_editor image-to-base64 Endpoint mcp-server.js client.get server-side request forgery | hm editor | 5.5 (v4.0) | Medium |
| CVE-2026-54611 | InstantCMS has Remote Code Execution in package installer | icms2 | 5.5 (v3.1) | Medium |
| CVE-2026-5631 | assafelovic gpt-researcher ws Endpoint server_utils.py extract_command_data code injection | gpt-researcher | 5.5 (v4.0) | Medium |
| CVE-2026-5677 | Totolink A7100RU cstecgi.cgi CsteSystem os command injection | A7100RU | 5.5 (v4.0) | Medium |
| CVE-2026-5678 | Totolink A7100RU cstecgi.cgi setScheduleCfg os command injection | A7100RU | 5.5 (v4.0) | Medium |
| CVE-2026-5688 | Totolink A7100RU cstecgi.cgi setDdnsCfg os command injection | A7100RU | 5.5 (v4.0) | Medium |
| CVE-2026-5689 | Totolink A7100RU cstecgi.cgi setNtpCfg os command injection | A7100RU | 5.5 (v4.0) | Medium |
| CVE-2026-5690 | Totolink A7100RU cstecgi.cgi setRemoteCfg os command injection | A7100RU | 5.5 (v4.0) | Medium |
| CVE-2026-5691 | Totolink A7100RU cstecgi.cgi setFirewallType os command injection | A7100RU | 5.5 (v4.0) | Medium |
| CVE-2026-5692 | Totolink A7100RU cstecgi.cgi setGameSpeedCfg os command injection | A7100RU | 5.5 (v4.0) | Medium |
| CVE-2026-5736 | PowerJob detailPlus Endpoint InstanceController.java sql injection | PowerJob | 5.5 (v4.0) | Medium |
| CVE-2026-5741 | suvarchal docker-mcp-server HTTP index.ts pull_image os command injection | docker-mcp-server | 5.5 (v4.0) | Medium |
| CVE-2026-5802 | idachev mcp-javadc HTTP os command injection | mcp-javadc | 5.5 (v4.0) | Medium |
| CVE-2026-5832 | atototo api-lab-mcp HTTP http-server.ts test_http_endpoint server-side request forgery | api-lab-mcp | 5.5 (v4.0) | Medium |
| CVE-2026-68922 | MobSF: Arbitrary File Read via Path Traversal in ZIP Uploads | Mobile-Security-Framework-MobSF | 5.5 (v3.1) | Medium |
| CVE-2026-7178 | ChatGPTNextWeb NextChat Artifacts Endpoint route.ts storeUrl server-side request forgery | nextchat | 5.5 (v4.0) | Medium |
| CVE-2026-7205 | duartium papers-mcp-server main.py search_papers path traversal | papers-mcp-server | 5.5 (v4.0) | Medium |
| CVE-2026-7206 | dubydu sqlite-mcp entry.py extract_to_json sql injection | sqlite-mcp | 5.5 (v4.0) | Medium |
| CVE-2026-7212 | edvardlindelof notes-mcp notes_mcp.py path traversal | notes-mcp | 5.5 (v4.0) | Medium |
| CVE-2026-7214 | eghuzefa engineer-your-data server.py file_inf path traversal | engineer-your-data | 5.5 (v4.0) | Medium |
| CVE-2026-7216 | donchelo processing-claude-mcp-bridge create_sketch Tool processing_server.py path traversal | processing-claude-mcp-bridge | 5.5 (v4.0) | Medium |
| CVE-2026-7217 | Deepractice PromptX Document File index.ts read_pdf absolute path traversal | PromptX | 5.5 (v4.0) | Medium |
| CVE-2026-7220 | jackwrichards FastlyMCP fastly_cli Tool fastly-mcp.mjs os command injection | FastlyMCP | 5.5 (v4.0) | Medium |
| CVE-2026-7221 | TencentCloudBase CloudBase-MCP open-url API Endpoint interactive-server.ts openUrl server-side request forgery | CloudBase-MCP | 5.5 (v4.0) | Medium |
| CVE-2026-7314 | eiceblue spire-doc-mcp-server base.py get_doc_path path traversal | spire-doc-mcp-server | 5.5 (v4.0) | Medium |
| CVE-2026-7315 | eiceblue spire-pdf-mcp-server PDF File server.py get_pdf_path path traversal | spire-pdf-mcp-server | 5.5 (v4.0) | Medium |
| CVE-2026-7319 | elinsky execution-system-mcp add_action Tool server.py _get_context_file_path path traversal | execution-system-mcp | 5.5 (v4.0) | Medium |
| CVE-2026-76760 | chenhg5 cc-connect webhook.go authenticate code injection | cc-connect | 5.5 (v4.0) | Medium |
| CVE-2026-76761 | chenhg5 cc-connect Management API engine.go shellExecCommand os command injection | cc-connect | 5.5 (v4.0) | Medium |
| CVE-2026-76795 | AeternaLabsHQ PullMD REST API Endpoint api server-side request forgery | PullMD | 5.5 (v4.0) | Medium |
| CVE-2026-81421 | ddfourtwo sentry-selfhosted-mcp raw_sentry_api server-side request forgery | sentry-selfhosted-mcp | 5.5 (v4.0) | Medium |
| CVE-2026-81486 | bsmi021 mcp-file-context-server Path Resolution index.ts read_context path traversal | mcp-file-context-server | 5.5 (v4.0) | Medium |
| CVE-2026-81491 | boxpositron with-context-mcp index.ts project_folder path traversal | with-context-mcp | 5.5 (v4.0) | Medium |
| CVE-2026-82598 | SeaCMS Template search.php parseIf code injection | SeaCMS | 5.5 (v4.0) | Medium |
| CVE-2026-82630 | PowerJob Transport Endpoint TestController.java MuConnectionManager.getOrCreateConnection server-side request forgery | PowerJob | 5.5 (v4.0) | Medium |
| CVE-2026-82801 | NASA earthdata-search scale Endpoint handler.js scaleImage server-side request forgery | earthdata-search | 5.5 (v4.0) | Medium |
| CVE-2026-82802 | NASA earthdata-search granules Endpoint handler.js OpenSearchGranuleSearchLambda server-side request forgery | earthdata-search | 5.5 (v4.0) | Medium |
| CVE-2026-84441 | Piwigo Image Derivative i.php path traversal | Piwigo | 5.5 (v4.0) | Medium |
| CVE-2026-85137 | SeaCMS Locoy Collector seacms_locoy_news.php parseIf code injection | SeaCMS | 5.5 (v4.0) | Medium |
| CVE-2026-85380 | light0011 cms UEditor controller.php catchimage server-side request forgery | cms | 5.5 (v4.0) | Medium |
| CVE-2026-86237 | openagents-org openagents http.py test_default_model server-side request forgery | openagents | 5.5 (v4.0) | Medium |
| CVE-2026-86273 | projeto-siga HTML-to-PDF Endpoint ExUtilController.java DownloadExterno.getUrl server-side request forgery | siga | 5.5 (v4.0) | Medium |
| CVE-2026-9372 | ItzCrazyKns Vane Model Provider API route.ts server-side request forgery | Vane | 5.5 (v4.0) | Medium |
| CVE-2026-9474 | yashpokharna2555 StudentManagementSystem studentdel.php confirm_logged_in sql injection | StudentManagementSystem | 5.5 (v4.0) | Medium |
| CVE-2023-2745 | WordPress Core <=6.2 - Directory Traversal | WordPress | 5.4 (v3.1) | Medium |
| CVE-2026-17621 | Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base compone | langflow | 5.4 (v3.1) | Medium |
| CVE-2026-34590 | Postiz: SSRF via Webhook Creation Endpoint Missing URL Safety Validation | postiz | 5.4 (v3.1) | Medium |
| CVE-2026-48483 | TypeBot's WhatsApp status forwarding uses unvalidated user-controlled URLs, allowing SSRF from the Typebot server | typebot.io | 5.4 (v3.1) | Medium |
| CVE-2026-48762 | TypeBot Vulnerable to Server-Side Request Forgery (SSRF) in OpenAI Transcription Handler | typebot.io | 5.4 (v3.1) | Medium |
| CVE-2026-54543 | Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fields | froxlor | 5.4 (v3.1) | Medium |
| CVE-2026-7798 | FluentCRM <= 2.9.87 - Unauthenticated Blind Server-Side Request Forgery via 'SubscribeURL' Parameter | FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution | 5.4 (v3.1) | Medium |
| CVE-2026-7869 | Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement | langflow | 5.4 (v3.1) | Medium |
| CVE-2014-8676 | SO Planning 1.32 - Multiple Vulnerabilities | soplanning | 5.3 (v3.0) | Medium |
| CVE-2014-9609 | Netsweeper 4.0.8 - Directory Traversal | netsweeper | 5.3 (v3.1) | Medium |
| CVE-2015-5471 | Swim Team <= v1.44.10777 - Local File Inclusion | swim team | 5.3 (v3.0) | Medium |
| CVE-2020-11798 | Mitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory Traversal | micollab audio, web & video conferencing | 5.3 (v3.1) | Medium |
| CVE-2020-13886 | Intelbras TIP 200/200 LITE/300 - Local File Inclusion | tip200 firmware | 5.3 (v3.1) | Medium |
| CVE-2021-28377 | Joomla! ChronoForums 2.0.11 - Local File Inclusion | chronoforums | 5.3 (v3.1) | Medium |
| CVE-2022-25497 | Cuppa CMS v1.0 - Local File Inclusion | cuppacms | 5.3 (v3.1) | Medium |
| CVE-2022-31062 | GLPI Glpiinventory v1.0.1 - Unauthenticated Local File Inclusion | glpi inventory | 5.3 (v3.1) | Medium |
| CVE-2023-41599 | JFinalCMS v5.0.0 - Directory Traversal | jfinalcms | 5.3 (v3.1) | Medium |
| CVE-2023-7299 | DataGear resolveSql sql injection | datagear | 5.3 (v4.0) | Medium |
| CVE-2025-4078 | Wangshen SecGate 3600 Path Traversal Vulnerability | SecGate 3600 | 5.3 (v4.0) | Medium |
| CVE-2026-14860 | Podcast Player < 8.3.1 - Unauthenticated Server-Side Request Forgery | Podcast Player | 5.3 (v3.1) | Medium |
| CVE-2026-15932 | Support Genix Lite < 1.4.48 - Unauthenticated Arbitrary File Read via Path Traversal | Support Genix | 5.3 (v3.1) | Medium |
| CVE-2026-16531 | Pcp: pcp: arbitrary file creation via path traversal in pmproxy logger servlet | Red Hat Enterprise Linux 10 | 5.3 (v3.1) | Medium |
| CVE-2026-16536 | Simple Google Calendar Outlook Events Widget < 3.1.0 - Unauthenticated SSRF via calendar_id | Simple Google Calendar Outlook Events Widget | 5.3 (v3.1) | Medium |
| CVE-2026-19785 | francoisjacquet RosarioSIS Student Medical Medical.inc.php sql injection | RosarioSIS | 5.3 (v4.0) | Medium |
| CVE-2026-19956 | gomarble-ai facebook-ads-mcp-server server.py fetch_pagination_url server-side request forgery | facebook-ads-mcp-server | 5.3 (v4.0) | Medium |
| CVE-2026-22662 | prompts.chat Blind SSRF via media-generate | prompts.chat | 5.3 (v4.0) | Medium |
| CVE-2026-34523 | SillyTavern: Path traversal allows file existence oracle | sillytavern | 5.3 (v3.1) | Medium |
| CVE-2026-34967 | Adminer sql-log Plugin 5.3.0 through 5.4.2 Arbitrary File Write | adminer | 5.3 (v4.0) | Medium |
| CVE-2026-36726 | bookcars v8.3 Path Traversal Vulnerability | bookcars v8.3 | 5.3 (v3.1) | Medium |
| CVE-2026-44583 | Paymenter: Blind Unauthenticated SSRF on the Paypal gateway module | Paymenter | 5.3 (v3.1) | Medium |
| CVE-2026-49138 | Nanobot < 0.2.1 SSRF via web_fetch Tool Redirect Following | nanobot | 5.3 (v4.0) | Medium |
| CVE-2026-53452 | Ground Station: Unauthenticated out-of-containment file read via sigmfplayback recordingPath | ground-station | 5.3 (v3.1) | Medium |
| CVE-2026-54508 | TREK: Blind SSRF via unvalidated redirect-following in Google/Naver list import and Maps URL resolution | TREK | 5.3 (v4.0) | Medium |
| CVE-2026-5538 | QingdaoU OnlineJudge judge_server_heartbeat Endpoint JudgeServer.service_url server-side request forgery | OnlineJudge | 5.3 (v4.0) | Medium |
| CVE-2026-5547 | Tenda AC10 httpd formAddMacfilterRule os command injection | ac10 firmware | 5.3 (v4.0) | Medium |
| CVE-2026-59231 | Server-Side Request Forgery in Pentestify PDF export via unvalidated image URLs | Pentestify | 5.3 (v4.0) | Medium |
| CVE-2026-63730 | HyperDX < 2.31.0 SSRF via Webhook Test Endpoint | hyperdx | 5.3 (v4.0) | Medium |
| CVE-2026-64626 | AVideo Encoder downloadURL SSRF via unpinned retry fallback | AVideo | 5.3 (v4.0) | Medium |
| CVE-2026-64870 | MaxKB: UpdateStoreTool fetches caller-supplied app-store URLs without host validation | MaxKB | 5.3 (v4.0) | Medium |
| CVE-2026-72846 | Lightdash Scheduled Delivery Webhook URLs Are Not Validated, Allowing Server-Side Request Forgery | lightdash | 5.3 (v4.0) | Medium |
| CVE-2026-73082 | Activepieces: Server-side request forgery in MCP tool validation endpoint | activepieces | 5.3 (v4.0) | Medium |
| CVE-2026-73244 | kkFileView: Unauthenticated path traversal in POST /listFiles allows arbitrary directory listing | kkFileView | 5.3 (v3.1) | Medium |
| CVE-2026-73845 | CKAN MCP Server: MQA server allowlist bypass via unanchored regex (isValidMqaServer) | ckan-mcp-server | 5.3 (v3.1) | Medium |
| CVE-2026-74858 | jae-jae fetcher-mcp URL Validation security-credentials fetch_urls server-side request forgery | fetcher-mcp | 5.3 (v4.0) | Medium |
| CVE-2026-76239 | Stigmem before 0.9.0a11 SSRF via unvalidated webhook delivery_address | stigmem-node | 5.3 (v4.0) | Medium |
| CVE-2026-76614 | OpenEMR < 8.3.0 Path Traversal Information Disclosure via EDI Archive Restore | openemr | 5.3 (v4.0) | Medium |
| CVE-2026-77067 | Omnivore Stored Server-Side Request Forgery via the setWebhook Mutation | omnivore | 5.3 (v4.0) | Medium |
| CVE-2026-84175 | Eclipse Ditto Uncontrolled Recursion Vulnerability | Eclipse Ditto | 5.3 (v4.0) | Medium |
| CVE-2026-84207 | Heym before 0.0.98 SSRF via WebSocket endpoints | heym | 5.3 (v4.0) | Medium |
| CVE-2026-85650 | Trigger.dev before 4.5.2 Server-Side Request Forgery via webhook alert-channel | trigger.dev | 5.3 (v4.0) | Medium |
| CVE-2026-88892 | OpenPanel SSRF via Unguarded Importer File URL Fetch | openpanel | 5.3 (v4.0) | Medium |
| CVE-2026-89247 | WWBN AVideo XML Injection via plugin/AD_Server/VMAP.php | AVideo | 5.3 (v4.0) | Medium |
| CVE-2026-17597 | Nexus Repository 3 - Server-Side Request Forgery via Email Configuration Verification | Nexus Repository 3 | 5.1 (v4.0) | Medium |
| CVE-2026-19761 | DTStack Taier Upload Controller UploadController.java MultipartFile.getOriginalFilename path traversal | Taier | 5.1 (v4.0) | Medium |
| CVE-2026-19763 | DTStack Taier Cluster Creation ClusterController.java FileUtils.deleteDirectory path traversal | Taier | 5.1 (v4.0) | Medium |
| CVE-2026-42336 | MaxKB: SSRF Bypass via DNS Rebinding in MaxKB OSS URL Fetch | MaxKB | 5.1 (v4.0) | Medium |
| CVE-2026-63302 | Local File Inclusion in Quick.CMS | Quick.CMS | 5.1 (v4.0) | Medium |
| CVE-2026-76203 | CSS sanitizer bypass in Pentestify report themes allows forced outbound requests | Pentestify | 5.1 (v4.0) | Medium |
| CVE-2026-79671 | Ech0 before 4.4.3 SSRF via DNS Resolution Bypass | Ech0 | 5.1 (v4.0) | Medium |
| CVE-2026-82112 | houtini-ai houtini-lm code_task_files index.ts path traversal | houtini-lm | 5.1 (v4.0) | Medium |
| CVE-2007-4504 | Joomla! RSfiles <=1.0.2 - Local File Inclusion | rsfiles | 5.0 (v2.0) | Medium |
| CVE-2008-4764 | Joomla! <=2.0.0 RC2 - Local File Inclusion | com extplorer | 5.0 (v2.0) | Medium |
| CVE-2008-6080 | Joomla! ionFiles 4.4.2 - Local File Inclusion | com ionfiles | 5.0 (v2.0) | Medium |
| CVE-2008-6222 | Joomla! ProDesk 1.0/1.2 - Local File Inclusion | pro desk support center | 5.0 (v2.0) | Medium |
| CVE-2008-6668 | nweb2fax <=0.2.7 - Local File Inclusion | nweb2fax | 5.0 (v2.0) | Medium |
| CVE-2009-1496 | Joomla! Cmimarketplace 0.1 - Local File Inclusion | Joomla! | 5.0 (v2.0) | Medium |
| CVE-2009-2100 | Joomla! JoomlaPraise Projectfork 2.0.10 - Local File Inclusion | Joomla! | 5.0 (v2.0) | Medium |
| CVE-2009-5114 | WebGlimpse 2.18.7 - Directory Traversal | webglimpse | 5.0 (v2.0) | Medium |
| CVE-2010-0696 | Joomla! Component Jw_allVideos - Arbitrary File Retrieval | jw allvideos | 5.0 (v2.0) | Medium |
| CVE-2010-0942 | Joomla! Component com_jvideodirect - Directory Traversal | com jvideodirect | 5.0 (v2.0) | Medium |
| CVE-2010-0943 | Joomla! Component com_jashowcase - Directory Traversal | com jashowcase | 5.0 (v2.0) | Medium |
| CVE-2010-0944 | Joomla! Component com_jcollection - Directory Traversal | com jcollection | 5.0 (v2.0) | Medium |
| CVE-2010-1081 | Joomla! Component com_communitypolls 1.5.2 - Local File Inclusion | com communitypolls | 5.0 (v2.0) | Medium |
| CVE-2010-1302 | Joomla! Component DW Graph - Local File Inclusion | com dwgraphs | 5.0 (v2.0) | Medium |
| CVE-2010-1304 | Joomla! Component User Status - Local File Inclusion | com userstatus | 5.0 (v2.0) | Medium |
| CVE-2010-1305 | Joomla! Component JInventory 1.23.02 - Local File Inclusion | com jinventory | 5.0 (v2.0) | Medium |
| CVE-2010-1307 | Joomla! Component Magic Updater - Local File Inclusion | com joomlaupdater | 5.0 (v2.0) | Medium |
| CVE-2010-1308 | Joomla! Component SVMap 1.1.1 - Local File Inclusion | com svmap | 5.0 (v2.0) | Medium |
| CVE-2010-1312 | Joomla! Component News Portal 1.5.x - Local File Inclusion | com news portal | 5.0 (v2.0) | Medium |
| CVE-2010-1314 | Joomla! Component Highslide 1.5 - Local File Inclusion | com hsconfig | 5.0 (v2.0) | Medium |
| CVE-2010-1315 | Joomla! Component webERPcustomer - Local File Inclusion | com weberpcustomer | 5.0 (v2.0) | Medium |
| CVE-2010-1340 | Joomla! Component com_jresearch - 'Controller' Local File Inclusion | com jresearch | 5.0 (v2.0) | Medium |
| CVE-2010-1345 | Joomla! Component Cookex Agency CKForms - Local File Inclusion | com ckforms | 5.0 (v2.0) | Medium |
| CVE-2010-1352 | Joomla! Component Juke Box 1.7 - Local File Inclusion | com jukebox | 5.0 (v2.0) | Medium |
| CVE-2010-1353 | Joomla! Component LoginBox - Local File Inclusion | com loginbox | 5.0 (v2.0) | Medium |
| CVE-2010-1354 | Joomla! Component VJDEO 1.0 - Local File Inclusion | com vjdeo | 5.0 (v2.0) | Medium |
| CVE-2010-1461 | Joomla! Component Photo Battle 1.0.1 - Local File Inclusion | com photobattle | 5.0 (v2.0) | Medium |
| CVE-2010-1491 | Joomla! Component MMS Blog 2.3.0 - Local File Inclusion | com mmsblog | 5.0 (v2.0) | Medium |
| CVE-2010-1494 | Joomla! Component AWDwall 1.5.4 - Local File Inclusion | com awdwall | 5.0 (v2.0) | Medium |
| CVE-2010-1532 | Joomla! Component PowerMail Pro 1.5.3 - Local File Inclusion | com powermail | 5.0 (v2.0) | Medium |
| CVE-2010-1534 | Joomla! Component Shoutbox Pro - Local File Inclusion | com shoutbox | 5.0 (v2.0) | Medium |
| CVE-2010-1540 | Joomla! Component com_blog - Directory Traversal | com myblog | 5.0 (v2.0) | Medium |
| CVE-2010-1601 | Joomla! Component JA Comment - Local File Inclusion | com jacomment | 5.0 (v2.0) | Medium |
| CVE-2010-1657 | Joomla! Component SmartSite 1.0.0 - Local File Inclusion | com smartsite | 5.0 (v2.0) | Medium |
| CVE-2010-1658 | Joomla! Component NoticeBoard 1.3 - Local File Inclusion | com noticeboard | 5.0 (v2.0) | Medium |
| CVE-2010-1659 | Joomla! Component Ultimate Portfolio 1.0 - Local File Inclusion | com ultimateportfolio | 5.0 (v2.0) | Medium |
| CVE-2010-1714 | Joomla! Component Arcade Games 1.0 - Local File Inclusion | com arcadegames | 5.0 (v2.0) | Medium |
| CVE-2010-1858 | Joomla! Component SMEStorage - Local File Inclusion | com smestorage | 5.0 (v2.0) | Medium |
| CVE-2010-1982 | Joomla! Component JA Voice 2.0 - Local File Inclusion | com javoice | 5.0 (v2.0) | Medium |
| CVE-2010-2018 | Lokomedia CMS - Local File Inclusion | lokomedia cms | 5.0 (v2.0) | Medium |
| CVE-2010-3203 | Joomla! Component PicSell 1.0 - Arbitrary File Retrieval | com picsell | 5.0 (v2.0) | Medium |
| CVE-2011-0049 | Majordomo2 - SMTP/HTTP Directory Traversal | majordomo 2 | 5.0 (v2.0) | Medium |
| CVE-2011-1669 | WP Custom Pages 0.5.0.1 - Local File Inclusion (LFI) | wp custom pages | 5.0 (v2.0) | Medium |
| CVE-2011-2780 | Chyrp 2.x - Local File Inclusion | chyrp | 5.0 (v2.0) | Medium |
| CVE-2011-4804 | Joomla! Component com_kp - 'Controller' Local File Inclusion | com obsuggest | 5.0 (v2.0) | Medium |
| CVE-2012-0896 | Count Per Day <= 3.1 - download.php f Parameter Traversal Arbitrary File Access | count per day | 5.0 (v2.0) | Medium |
| CVE-2012-0981 | phpShowtime 2.0 - Directory Traversal | phpshowtime | 5.0 (v2.0) | Medium |
| CVE-2012-0996 | 11in1 CMS 1.2.1 - Local File Inclusion (LFI) | 11in1 | 5.0 (v2.0) | Medium |
| CVE-2013-5979 | Xibo 1.2.2/1.4.1 - Directory Traversal | xibo | 5.0 (v2.0) | Medium |
| CVE-2013-6043 | Webuzo 2.1.3 - Multiple Vulnerabilities | webuzo | 5.0 (v2.0) | Medium |
| CVE-2013-7091 | Zimbra Collaboration Server 7.2.2/8.0.2 Local File Inclusion | zimbra collaboration suite | 5.0 (v2.0) | Medium |
| CVE-2013-7240 | WordPress Plugin Advanced Dewplayer 1.2 - Directory Traversal | advanced dewplayer | 5.0 (v2.0) | Medium |
| CVE-2014-4577 | WP AmASIN – The Amazon Affiliate Shop - Local File Inclusion | wp amasin - the amazon affiliate shop | 5.0 (v2.0) | Medium |
| CVE-2014-4940 | WordPress Plugin Tera Charts - Local File Inclusion | tera-charts | 5.0 (v2.0) | Medium |
| CVE-2014-4941 | Cross RSS 1.7 - Local File Inclusion | wp-cross-rss | 5.0 (v2.0) | Medium |
| CVE-2014-5111 | Fonality trixbox - Local File Inclusion | trixbox | 5.0 (v2.0) | Medium |
| CVE-2014-5181 | Last.fm Rotation 1.0 - Path Traversal | lastfm-rotation plugin | 5.0 (v2.0) | Medium |
| CVE-2014-5187 | Tom M8te (tom-m8te) Plugin 1.5.3 - Directory Traversal | tom-m8te plugin | 5.0 (v2.0) | Medium |
| CVE-2014-5368 | WordPress Plugin WP Content Source Control - Directory Traversal | wp content source control | 5.0 (v2.0) | Medium |
| CVE-2014-6308 | Osclass Security Advisory 3.4.1 - Local File Inclusion | osclass | 5.0 (v2.0) | Medium |
| CVE-2014-8799 | WordPress Plugin DukaPress 2.5.2 - Directory Traversal | dukapress | 5.0 (v2.0) | Medium |
| CVE-2014-9119 | WordPress DB Backup <=4.5 - Local File Inclusion | db backup | 5.0 (v2.0) | Medium |
| CVE-2015-1579 | WordPress Slider Revolution - Local File Disclosure | divi | 5.0 (v2.0) | Medium |
| CVE-2015-2067 | Magento Server MAGMI - Directory Traversal | magmi | 5.0 (v2.0) | Medium |
| CVE-2015-3897 | Bonita BPM Portal <6.5.3 - Local File Inclusion | bonita bpm portal | 5.0 (v2.0) | Medium |
| CVE-2015-4414 | WordPress SE HTML5 Album Audio Player 1.1.0 - Directory Traversal | se html5 album audio player | 5.0 (v2.0) | Medium |
| CVE-2015-4666 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 5.0 (v2.0) | Medium |
| CVE-2026-16955 | AI Engine < 3.6.6 - Subscriber+ Arbitrary File Read via Audio Transcription | AI Engine | 5.0 (v3.1) | Medium |
| CVE-2026-79723 | Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches | Langflow OSS | 5.0 (v3.1) | Medium |
| CVE-2017-7461 | Intellinet NFC-30IR Camera - Multiple Vulnerabilities | nfc-30ir firmware | 4.9 (v3.0) | Medium |
| CVE-2021-24966 | WordPress Plugin Error Log Viewer 1.1.1 - Arbitrary File Clearing (Authenticated) | error log viewer | 4.9 (v3.1) | Medium |
| CVE-2024-10708 | System Dashboard < 2.8.15 - Admin+ Path Traversal | system dashboard | 4.9 (v3.1) | Medium |
| CVE-2025-15673 | Import and export users and customers < 2.4.3 - Admin+ Arbitrary File Read | Import and export users and customers | 4.9 (v3.1) | Medium |
| CVE-2026-41412 | alf.io vulnerable to Arbitrary File Read and Exfil via simpleHttpClient Extension Script | alf.io | 4.9 (v3.1) | Medium |
| CVE-2026-52832 | Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dashboard container | nuclio | 4.9 (v3.1) | Medium |
| CVE-2026-53594 | FreeScout has Arbitrary File Read in App Logs Viewer via Forged Encrypted Path | freescout | 4.9 (v3.1) | Medium |
| CVE-2026-71283 | Fledge IoT Gateway Backup Restore Tar Path Traversal | fledge | 4.9 (v3.1) | Medium |
| CVE-2016-4807 | Web2py 2.14.5 - Multiple Vulnerabilities | web2py | 4.8 (v3.0) | Medium |
| CVE-2008-5587 | phpPgAdmin <=4.2.1 - Local File Inclusion | phppgadmin | 4.3 (v2.0) | Medium |
| CVE-2010-0982 | Joomla! Component com_cartweberp - Local File Inclusion | com cartweberp | 4.3 (v2.0) | Medium |
| CVE-2010-1217 | Joomla! Component & Plugin JE Tooltip 1.0 - Local File Inclusion | je form creator | 4.3 (v2.0) | Medium |
| CVE-2010-1313 | Joomla! Component Saber Cart 1.0.0.12 - Local File Inclusion | com sebercart | 4.3 (v2.0) | Medium |
| CVE-2011-4451 | WikkaWiki 1.3.2 - Multiple Vulnerabilities | wikkawiki | 4.3 (v2.0) | Medium |
| CVE-2012-4253 | MySQLDumper 1.24.4 - Directory Traversal | mysqldumper | 4.3 (v2.0) | Medium |
| CVE-2013-6042 | Webuzo 2.1.3 - Multiple Vulnerabilities | webuzo | 4.3 (v2.0) | Medium |
| CVE-2014-9146 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | 4.3 (v2.0) | Medium |
| CVE-2015-4665 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 4.3 (v2.0) | Medium |
| CVE-2018-18777 | Microstrategy Web 7 - Local File Inclusion | microstrategy web | 4.3 (v3.0) | Medium |
| CVE-2024-7631 | Openshift-console: openshift console: path traversal | Red Hat OpenShift Container Platform 3.11 | 4.3 (v3.1) | Medium |
| CVE-2026-26477 | dokuwiki Denial of Service Vulnerability | dokuwiki | 4.3 (v3.1) | Medium |
| CVE-2026-36239 | PbootCMS v.3.2.11 Cross-site Scripting Vulnerability | PbootCMS v.3.2.11 | 4.3 (v3.1) | Medium |
| CVE-2026-43936 | e107: Server-Side Request Forgery (SSRF) in the remote file fetcher | e107 | 4.3 (v3.1) | Medium |
| CVE-2026-49856 | @jshookmcp/jshook: ICMP probe and traceroute skip local-network SSRF authorization | jshookmcp | 4.3 (v3.1) | Medium |
| CVE-2026-55495 | Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account | cloudreve | 4.3 (v3.1) | Medium |
| CVE-2026-77352 | Wallos: Authenticated SSRF via per-user SMTP notification host (low-privilege user) | Wallos | 4.3 (v3.1) | Medium |
| CVE-2026-10052 | Quay/config-tool: quay/config-tool: ssrf via unfiltered ldap and smtp config validation endpoints | Red Hat Quay 3 | 4.1 (v3.1) | Medium |
| CVE-2026-48013 | Shopware: SSRF in Media External-Link Endpoint Bypasses IP Validation | shopware | 4.1 (v3.1) | Medium |
| CVE-2011-4640 | WebTitan < 3.60 - Local File Inclusion | webtitan | 4.0 (v2.0) | Medium |
| CVE-2013-5528 | Cisco Unified Communications Manager 7/8/9 - Directory Traversal | unified communications manager | 4.0 (v2.0) | Medium |
| CVE-2014-1222 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | vtiger crm | 4.0 (v2.0) | Medium |
| CVE-2014-5258 | webEdition 6.3.8.0 - Directory Traversal | webedition cms | 4.0 (v2.0) | Medium |
| CVE-2012-0991 | OpenEMR 4.1 - Local File Inclusion | openemr | 3.5 (v2.0) | Low |
| CVE-2025-55523 | Agent-Zero 0.8.0 - 0.9.4 - Arbitrary File Download | agent-zero | 3.5 (v3.1) | Low |
| CVE-2026-48051 | Papra: SSRF via HTTP redirect bypass in webhook delivery | papra | 3.5 (v3.1) | Low |
| CVE-2026-77351 | Wallos: SSRF via Unvalidated User-Level SMTP Host in Email Notification Settings | Wallos | 3.5 (v3.1) | Low |
| CVE-2026-9062 | Agile Store Locator < 1.6.9 - Admin+ Arbitrary File Read via Path Traversal | Store Locator WordPress | 3.4 (v3.1) | Low |
| CVE-2026-23603 | Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim | Gitea Open Source Git Server | 3.1 (v3.1) | Low |
| CVE-2026-48707 | InstantCMS vulnerable to SSRF via upload redirect bypass allows internal network service scanning | icms2 | 3.1 (v3.1) | Low |
| CVE-2026-55825 | Contao: Possible path traversal in job download URIs | contao | 3.1 (v3.1) | Low |
| CVE-2026-49262 | Aimeos Pagible CMS vulnerable to Server Side Request Forgery (SSRF) via DNS rebinding in admin proxy | pagible | 3.0 (v3.1) | Low |
| CVE-2026-68927 | MobSF: SSRF port restriction bypass in assetlinks_check | Mobile-Security-Framework-MobSF | 3.0 (v3.1) | Low |
| CVE-2023-2252 | Directorist < 7.5.4 - Local File Inclusion | directorist | 2.7 (v3.1) | Low |
| CVE-2024-55550 | Mitel MiCollab - Arbitary File Read | cmg suite | 2.7 (v3.1) | Low |
| CVE-2026-16434 | Adminer before 5.5.1 X-Forwarded-Prefix Backslash Bypass | adminer | 2.3 (v4.0) | Low |
| CVE-2026-44286 | FastGPT: SSRF Vulnerability in Laf Workflow Node via Missing Internal Address Validation | FastGPT | 2.3 (v4.0) | Low |
| CVE-2026-55554 | Dompdf: Chroot Validation Bypass | dompdf | 2.3 (v4.0) | Low |
| CVE-2026-73087 | Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher | dozzle | 2.3 (v4.0) | Low |
| CVE-2026-77648 | Glance Server-Side Request Forgery Vulnerability | Glance | 2.2 (v3.1) | Low |
| CVE-2025-13789 | ZenTao model.php makeRequest server-side request forgery | zentao | 2.1 (v4.0) | Low |
| CVE-2025-13809 | orionsec orion-ops SSH Connection MachineInfoController.java server-side request forgery | orion-ops | 2.1 (v4.0) | Low |
| CVE-2025-13816 | moxi159753 Mogu Blog v2 ZIP File unzipFile FileOperation.unzip path traversal | mogublog | 2.1 (v4.0) | Low |
| CVE-2025-13875 | Yohann0617 oci-helper OCI Configuration Upload OciServiceImpl.java addCfg path traversal | oci-helper | 2.1 (v4.0) | Low |
| CVE-2025-15098 | YunaiV yudao-cloud Business Process Management BpmSyncHttpRequestTrigger server-side request forgery | yudao-cloud | 2.1 (v4.0) | Low |
| CVE-2026-10172 | Bdtask Multi-Store Inventory Management System Component Module.php upload unrestricted upload | Multi-Store Inventory Management System | 2.1 (v4.0) | Low |
| CVE-2026-10213 | AstrBotDevs AstrBot API Endpoint delete path traversal | AstrBot | 2.1 (v4.0) | Low |
| CVE-2026-10239 | JeecgBoot edit WordUtil.addImage server-side request forgery | JeecgBoot | 2.1 (v4.0) | Low |
| CVE-2026-10240 | JeecgBoot test server-side request forgery | the file /airag/airagModel/test | 2.1 (v4.0) | Low |
| CVE-2026-10241 | jeecgboot The server processes these URLs Cloud Instance Metadata Endpoint debug FileDownloadUtils.download2DiskFromNet | The server processes these URLs | 2.1 (v4.0) | Low |
| CVE-2026-10274 | indrasishbanerjee aem-mcp-server Axios Request Flow mcp-server.ts getAssetMetadata server-side request forgery | aem-mcp-server | 2.1 (v4.0) | Low |
| CVE-2026-10276 | hekmon8 Jenkins-server-mcp get_build_status/get_build_log/trigger_build index.ts jobPath server-side request forgery | Jenkins-server-mcp | 2.1 (v4.0) | Low |
| CVE-2026-10278 | ishayoyo excel-mcp read_file/write_file index.ts path traversal | excel-mcp | 2.1 (v4.0) | Low |
| CVE-2026-10279 | hiraishikentaro wezterm-mcp switch_pane/write_to_specific_pane wezterm_executor.ts os command injection | wezterm-mcp | 2.1 (v4.0) | Low |
| CVE-2026-10558 | SourceCodester Pizzafy Ecommerce System index.php file inclusion | Pizzafy Ecommerce System | 2.1 (v4.0) | Low |
| CVE-2026-10559 | SourceCodester Pizzafy Ecommerce System index.php file inclusion | Pizzafy Ecommerce System | 2.1 (v4.0) | Low |
| CVE-2026-10662 | ahujasid blender-mcp ZIP File server.py requests.get server-side request forgery | blender-mcp | 2.1 (v4.0) | Low |
| CVE-2026-10690 | wonderwhy-er DesktopCommanderMCP read_file filesystem.ts readFileFromUrl server-side request forgery | DesktopCommanderMCP | 2.1 (v4.0) | Low |
| CVE-2026-11408 | vertex-app vertex Log Viewer Endpoint LogMod.js os command injection | vertex | 2.1 (v4.0) | Low |
| CVE-2026-11467 | jishenghua jshERP addAccountHeadAndDetail Endpoint AccountHeadService.java path traversal | jshERP | 2.1 (v4.0) | Low |
| CVE-2026-12210 | universal-tool-calling-protocol python-utcp utcp-gql/utcp-websocket server-side request forgery | python-utcp | 2.1 (v4.0) | Low |
| CVE-2026-16074 | AstrBotDevs AstrBot Plugin Update plugin.py update_all_plugins server-side request forgery | AstrBot | 2.1 (v4.0) | Low |
| CVE-2026-16194 | zhayujie CowAgent web_fetch.py WebFetch.execute server-side request forgery | CowAgent | 2.1 (v4.0) | Low |
| CVE-2026-16219 | Croogo CMS Admin File Manager FileManager.php isEditable path traversal | CMS | 2.1 (v4.0) | Low |
| CVE-2026-16222 | 1Panel-dev CordysCRM Third Party Endpoint TokenService.java server-side request forgery | CordysCRM | 2.1 (v4.0) | Low |
| CVE-2026-16223 | 1Panel-dev CordysCRM Third Party Edit Endpoint IntegrationConfigService.java getSqlBotSrc server-side request forgery | CordysCRM | 2.1 (v4.0) | Low |
| CVE-2026-17458 | mf-yang openclaw-cn Browser Control HTTP API agent.act.ts clickViaPlaywright server-side request forgery | openclaw-cn | 2.1 (v4.0) | Low |
| CVE-2026-18644 | danpros HTMLy Delete Username Endpoint htmly.php unlink path traversal | HTMLy | 2.1 (v4.0) | Low |
| CVE-2026-18645 | danpros HTMLy Admin Content Endpoint admin.php add_content path traversal | HTMLy | 2.1 (v4.0) | Low |
| CVE-2026-18774 | NousResearch hermes-agent xAI Image Generation Provider image_gen_provider.py save_url_image server-side request forgery | hermes-agent | 2.1 (v4.0) | Low |
| CVE-2026-18959 | yushine InnoShop Files Endpoint panel-api.php destroyFiles path traversal | InnoShop | 2.1 (v4.0) | Low |
| CVE-2026-19040 | MissionSquad mcp-api dcrClients.ts server-side request forgery | mcp-api | 2.1 (v4.0) | Low |
| CVE-2026-19246 | HKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url server-side request forgery | nanobot | 2.1 (v4.0) | Low |
| CVE-2026-19340 | anubissbe ProjectHub-Mcp Webhooks API complete_backend.js server-side request forgery | ProjectHub-Mcp | 2.1 (v4.0) | Low |
| CVE-2026-19375 | dmitriiweb article-scraper-mcp server.py fetch_article server-side request forgery | article-scraper-mcp | 2.1 (v4.0) | Low |
| CVE-2026-19752 | EnzoVezzaro mcp-dominican-layer PDF Parsing index.ts parse-pdf server-side request forgery | mcp-dominican-layer | 2.1 (v4.0) | Low |
| CVE-2026-19756 | Dromara lamp-cloud Code Generator DefGenProjectController.java path traversal | lamp-cloud | 2.1 (v4.0) | Low |
| CVE-2026-19828 | 648540858 wvp-GB28181-pro Snapshot Endpoint PlayController.java path traversal | wvp-GB28181-pro | 2.1 (v4.0) | Low |
| CVE-2026-19829 | 648540858 wvp-GB28181-pro Log File Download Endpoint LogController.java path traversal | wvp-GB28181-pro | 2.1 (v4.0) | Low |
| CVE-2026-19927 | OpenBoxes Product Upload Endpoint ProductController.groovy upload server-side request forgery | OpenBoxes | 2.1 (v4.0) | Low |
| CVE-2026-19932 | DefaultFuction Notice-System-Managent NoticeController execute GroovyShell.evaluate code injection | Notice-System-Managent | 2.1 (v4.0) | Low |
| CVE-2026-19958 | iatsiuk pptr-mcp execute Tool vm-executor.ts executeCode code injection | pptr-mcp | 2.1 (v4.0) | Low |
| CVE-2026-19984 | jkawamoto mcp-florence2 init.py get_images server-side request forgery | mcp-florence2 | 2.1 (v4.0) | Low |
| CVE-2026-5351 | Trendnet TEW-657BRM setup.cgi add_wps_client os command injection | tew-657brm firmware | 2.1 (v4.0) | Low |
| CVE-2026-5352 | Trendnet TEW-657BRM setup.cgi edit os command injection | tew-657brm firmware | 2.1 (v4.0) | Low |
| CVE-2026-5353 | Trendnet TEW-657BRM setup.cgi ping_test os command injection | tew-657brm firmware | 2.1 (v4.0) | Low |
| CVE-2026-5354 | Trendnet TEW-657BRM setup.cgi vpn_connect os command injection | tew-657brm firmware | 2.1 (v4.0) | Low |
| CVE-2026-5355 | Trendnet TEW-657BRM setup.cgi vpn_drop os command injection | tew-657brm firmware | 2.1 (v4.0) | Low |
| CVE-2026-5470 | mixelpixx Google-Research-MCP Model Context Protocol content-extractor.service.ts extractContent server-side request for | Google-Research-MCP | 2.1 (v4.0) | Low |
| CVE-2026-5607 | imprvhub mcp-browser-agent URL Parameter handlers.ts CallToolRequestSchema server-side request forgery | mcp-browser-agent | 2.1 (v4.0) | Low |
| CVE-2026-74842 | Kira-Pgr PromptShopMCP Image-Toolkit-MCP-Server server.py download_image server-side request forgery | PromptShopMCP | 2.1 (v4.0) | Low |
| CVE-2026-76576 | yangzongzhuan RuoYi-Vue Common Download Endpoint CommonController.java resourceDownload path traversal | RuoYi-Vue | 2.1 (v4.0) | Low |
| CVE-2026-78166 | provectus kafka-ui Groovy Code MessagesController.java executeSmartFilterTest code injection | kafka-ui | 2.1 (v4.0) | Low |
| CVE-2026-7890 | Concrete CMS 9.5.0 is vulnerable to SSRF via RSS Displayer Block | concrete cms | 2.1 (v4.0) | Low |
| CVE-2026-81845 | arben-adm mcp-sequential-thinking Import Session/Export Session server.py export_session path traversal | mcp-sequential-thinking | 2.1 (v4.0) | Low |
| CVE-2026-8188 | Wavlink NU516U1 adm.cgi change_wifi_password os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-8189 | Wavlink NU516U1 adm.cgi wzdrepeater os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-8190 | Wavlink NU516U1 adm.cgi wan os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-8191 | Wavlink NU516U1 adm.cgi wifi_region os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-8192 | Wavlink NU516U1 adm.cgi wzdap os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-8227 | Wavlink NU516U1 adm.cgi wzdapMesh os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-8228 | Wavlink NU516U1 wireless.cgi advance os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-8229 | Wavlink NU516U1 wireless.cgi WifiBasic os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-8230 | Wavlink NU516U1 login.cgi sys_login1 os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-82599 | SeaCMS Avatar Upload member.php unlink path traversal | SeaCMS | 2.1 (v4.0) | Low |
| CVE-2026-82603 | SeaCMS Comment Cache member.php del_pl path traversal | SeaCMS | 2.1 (v4.0) | Low |
| CVE-2026-8264 | Tenda AC6 httpd WifiApScan formWifiApScan os command injection | ac6 firmware | 2.1 (v4.0) | Low |
| CVE-2026-82656 | Admidio before 5.0.12 Path Traversal via Photo ZIP Download | admidio | 2.1 (v4.0) | Low |
| CVE-2026-82905 | sdcb chats fetch-tools Endpoint McpController.cs McpController server-side request forgery | chats | 2.1 (v4.0) | Low |
| CVE-2026-83744 | invoiceninja Invoice Ninja invoices Endpoint Purify.php isHostSafe server-side request forgery | Invoice Ninja | 2.1 (v4.0) | Low |
| CVE-2026-9302 | 546669204 vps-inventory-monitoring VpsTest Console VpsTest.php eval code injection | vps-inventory-monitoring | 2.1 (v4.0) | Low |
| CVE-2026-9343 | Edimax EW-7438RPn webs formWpsStart os command injection | EW-7438RPn | 2.1 (v4.0) | Low |
| CVE-2026-9347 | Edimax EW-7438RPn webs formWizSurvey os command injection | EW-7438RPn | 2.1 (v4.0) | Low |
| CVE-2026-9424 | Edimax EW-7438RPn Content-Type formWlanMP os command injection | EW-7438RPn | 2.1 (v4.0) | Low |
| CVE-2026-9473 | c-rick jimeng-mcp api.ts generateVideo path traversal | jimeng-mcp | 2.1 (v4.0) | Low |
| CVE-2026-9511 | Totolink CA750-PoE Setting cstecgi.cgi setWebWlanIdx os command injection | CA750-PoE | 2.1 (v4.0) | Low |
| CVE-2026-9512 | Totolink CA750-PoE Setting cstecgi.cgi setPasswordCfg os command injection | CA750-PoE | 2.1 (v4.0) | Low |
| CVE-2026-9514 | Totolink CA750-PoE Setting cstecgi.cgi setNetworkDiag os command injection | CA750-PoE | 2.1 (v4.0) | Low |
| CVE-2026-9515 | Totolink CA750-PoE Setting cstecgi.cgi setUnloadUserData os command injection | CA750-PoE | 2.1 (v4.0) | Low |
| CVE-2026-9531 | Totolink CA750-PoE Setting cstecgi.cgi setUpgradeUboot os command injection | CA750-PoE | 2.1 (v4.0) | Low |
| CVE-2026-9532 | Totolink CA750-PoE Setting cstecgi.cgi setUploadUserData os command injection | CA750-PoE | 2.1 (v4.0) | Low |
| CVE-2026-9533 | Totolink CA750-PoE Setting cstecgi.cgi recvUpgradeNewFw os command injection | CA750-PoE | 2.1 (v4.0) | Low |
| CVE-2026-9534 | Totolink CA750-PoE Setting cstecgi.cgi setWiFiWpsConfig os command injection | CA750-PoE | 2.1 (v4.0) | Low |
| CVE-2026-12211 | Intelbras iNVU 7016 FT Web syslog path traversal | iNVU 7016 FT | 2.0 (v4.0) | Low |
| CVE-2026-16088 | halo-dev halo Files Backup Endpoint MigrationEndpoint.java download path traversal | halo | 2.0 (v4.0) | Low |
| CVE-2026-18856 | Poesis Rhymix CMS Data Import importer.admin.controller.php procImporterAdminCheckXmlFile server-side request forgery | Rhymix CMS | 2.0 (v4.0) | Low |
| CVE-2026-19964 | Jij-Inc Jij-MCP-Server jm_check python_repr.py PythonREPL.run code injection | Jij-MCP-Server | 2.0 (v4.0) | Low |
| CVE-2026-78140 | Dromara UJCMS web-file-template Endpoint WebFileTemplateController.java update special elements in template engine | UJCMS | 2.0 (v4.0) | Low |
| CVE-2026-78435 | Faveo Helpdesk Logo SettingsController.php unlink path traversal | Helpdesk | 2.0 (v4.0) | Low |
| CVE-2026-81835 | RooCodeInc Roo-Code MCP Integration Trust Model malicious_mcp_server.py fetch_instructions code injection | Roo-Code | 2.0 (v4.0) | Low |
| CVE-2026-81847 | MAA-AI MaaMCP pipeline_tools.py load_pipeline path traversal | MaaMCP | 2.0 (v4.0) | Low |
| CVE-2026-8259 | Tenda AC6 httpd telnet os command injection | ac6 firmware | 2.0 (v4.0) | Low |
| CVE-2026-8265 | Tenda AC6 httpd getLogFile get_log_file os command injection | ac6 firmware | 2.0 (v4.0) | Low |
| CVE-2026-82678 | diem-project diem Administrative Console actions.class.php executeCommand os command injection | diem | 2.0 (v4.0) | Low |
| CVE-2026-82702 | Edimax BR-6214K asp_WlanMP Endpoint wlanMP.asp system os command injection | BR-6214K | 2.0 (v4.0) | Low |
| CVE-2026-82703 | Edimax BR-6214K asp_setPing Endpoint ping.asp system os command injection | BR-6214K | 2.0 (v4.0) | Low |
| CVE-2026-85040 | ZhongBangKeJi CRMEB Custom Scheduled Task Feature save eval os command injection | CRMEB | 2.0 (v4.0) | Low |
| CVE-2026-86240 | liufee FeehiCMS UEditor Uploader.php catchImage server-side request forgery | FeehiCMS | 2.0 (v4.0) | Low |
| CVE-2026-9464 | YunaiV yudao-cloud Admin API Endpoint create IotDataSinkHttpConfig server-side request forgery | yudao-cloud | 2.0 (v4.0) | Low |
| CVE-2026-16129 | princezuda SafestClaw Built-in Web shell.py ShellAction._validate_command incomplete blacklist | SafestClaw | 1.9 (v4.0) | Low |
| CVE-2026-19369 | KS-GEN-AI jira-mcp-server add_attachment_from_public_url index.ts axios.get server-side request forgery | jira-mcp-server | 1.9 (v4.0) | Low |
| CVE-2026-19373 | PhialsBasement KoboldCPP-MCP-Server BaseConfigSchema index.ts makeRequest server-side request forgery | KoboldCPP-MCP-Server | 1.9 (v4.0) | Low |
| CVE-2026-5621 | ChrisChinchilla Vale-MCP HTTP index.ts os command injection | Vale-MCP | 1.9 (v4.0) | Low |
| CVE-2026-19353 | DedeCMS Installation Wizard index.php _4_Setup file inclusion | DedeCMS | 1.3 (v4.0) | Low |
| CVE-2013-5759 | Yealink VoIP Phone SIP-T38G - Privilege Escalation | - | N/A | N/A |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.