On this page
Atomicorp WAF Rule 347009
Rule Summary
- Rule ID: 347009
- Status: Active
- Alert message: Atomicorp.com WAF Rules: Protected File access denied
- Observed CWEs: CWE-20 (13), CWE-22 (461), CWE-23 (5), CWE-24 (2), CWE-29 (2), CWE-35 (1), CWE-36 (2), CWE-59 (1), CWE-73 (16), CWE-74 (9), CWE-77 (16), CWE-78 (77), CWE-79 (1), CWE-88 (1), CWE-89 (9), CWE-91 (1), CWE-93 (3), CWE-94 (31), CWE-95 (5), CWE-98 (9), CWE-120 (1), CWE-121 (1), CWE-180 (1), CWE-184 (1), CWE-200 (19), CWE-201 (1), CWE-284 (9), CWE-285 (3), CWE-287 (5), CWE-288 (1), CWE-306 (8), CWE-345 (1), CWE-346 (1), CWE-352 (3), CWE-367 (4), CWE-400 (2), CWE-434 (11), CWE-441 (3), CWE-444 (1), CWE-470 (2), CWE-472 (1), CWE-501 (1), CWE-502 (1), CWE-552 (5), CWE-639 (3), CWE-641 (1), CWE-644 (1), CWE-665 (1), CWE-668 (2), CWE-669 (1), CWE-704 (1), CWE-706 (1), CWE-732 (1), CWE-770 (1), CWE-798 (1), CWE-824 (1), CWE-829 (3), CWE-835 (1), CWE-862 (8), CWE-863 (3), CWE-913 (1), CWE-915 (1), CWE-917 (1), CWE-918 (108), CWE-1188 (2), CWE-1220 (1), CWE-1336 (1), CWE-1392 (1)
- Revision: 1
- Rule severity: Critical (2)
- Phase: 1 (request headers)
- Request surfaces: Request URI
- Rule action: deny
- HTTP status: 403
- Logging: log, auditlog
Description
This rule detects behavior identified by its current alert as “Protected File access denied” in the request URI. It evaluates during the request headers phase and denies matching traffic with HTTP status 403.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2009-0545 | ZeroShell <= 1.0beta11 Remote Code Execution | zeroshell | 10.0 (v2.0) | High |
| CVE-2010-5286 | Joomla! Component Jstore - 'Controller' Local File Inclusion | com jstore | 10.0 (v2.0) | High |
| CVE-2019-11510 | Pulse Connect Secure SSL VPN Arbitrary File Read | connect secure | 10.0 (v3.1) | Critical |
| CVE-2025-34037 | Linksys Routers E/WAG/WAP/WES/WET/WRT-Series | E4200 | 10.0 (v4.0) | Critical |
| CVE-2026-33712 | TypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint bypasses SSRF controls | typebot.io | 10.0 (v3.1) | Critical |
| CVE-2026-49869 | Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in AuthenticationFilter | kestra | 10.0 (v3.1) | Critical |
| CVE-2026-54745 | Kubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENAB | pipelines | 10.0 (v3.1) | Critical |
| CVE-2026-31818 | Budibase: Server-Side Request Forgery via REST Connector with Empty Default Blacklist | budibase | 9.9 (v3.1) | Critical |
| CVE-2026-42454 | Termix: OS Command Injection in Docker Container Management Endpoints | Termix | 9.9 (v3.1) | Critical |
| CVE-2026-43986 | Tautulli vulnerable to unauthenticated SSRF in /image/<hash> via attacker-seeded image hash replay | Tautulli | 9.9 (v3.1) | Critical |
| CVE-2026-45629 | Dokploy: Authenticated Remote Code Execution via Command Injection in /listen-deployment WebSocket Endpoint | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-55565 | Yamcs: Authenticated remote code execution via unescaped StreamSQL LIKE pattern compiled by Janino (LikeExpression) | yamcs | 9.9 (v3.1) | Critical |
| CVE-2026-72738 | Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search Parameter | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-72869 | Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCE | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-72876 | Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.* | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-73294 | Semaphore U: OS Command Injection | semaphore | 9.9 (v3.1) | Critical |
| CVE-2010-2861 | Adobe ColdFusion - Directory Traversal | coldfusion | 9.8 (v3.1) | Critical |
| CVE-2017-12611 | Apache Struts2 S2-053 - Remote Code Execution | struts | 9.8 (v3.0) | Critical |
| CVE-2017-7462 | Intellinet NFC-30IR Camera - Multiple Vulnerabilities | nfc-30ir firmware | 9.8 (v3.0) | Critical |
| CVE-2018-12031 | Eaton Intelligent Power Manager 1.6 - Directory Traversal | intelligent power manager | 9.8 (v3.0) | Critical |
| CVE-2018-14064 | VelotiSmart Wifi - Directory Traversal | velotismart wifi firmware | 9.8 (v3.0) | Critical |
| CVE-2018-16283 | WordPress Plugin Wechat Broadcast 1.2.0 - Local File Inclusion | wechat brodcast | 9.8 (v3.0) | Critical |
| CVE-2018-16763 | FUEL CMS 1.4.1 - Remote Code Execution | fuel cms | 9.8 (v3.1) | Critical |
| CVE-2018-16836 | Rubedo CMS <=3.4.0 - Directory Traversal | rubedo | 9.8 (v3.1) | Critical |
| CVE-2018-17246 | Kibana - Local File Inclusion | kibana | 9.8 (v3.0) | Critical |
| CVE-2019-12314 | Deltek Maconomy 2.2.5 - Local File Inclusion | maconomy | 9.8 (v3.0) | Critical |
| CVE-2019-12725 | Zeroshell 3.9.0 - Remote Command Execution | zeroshell | 9.8 (v3.0) | Critical |
| CVE-2019-16662 | rConfig 3.9.2 - Remote Code Execution | rconfig | 9.8 (v3.1) | Critical |
| CVE-2019-17270 | Yachtcontrol Webapplication 1.0 - Remote Command Injection | yachtcontrol | 9.8 (v3.1) | Critical |
| CVE-2019-7256 | eMerge E3 1.00-06 - Remote Code Execution | linear emerge essential firmware | 9.8 (v3.1) | Critical |
| CVE-2019-9618 | WordPress GraceMedia Media Player 1.0 - Local File Inclusion | gracemedia media player | 9.8 (v3.0) | Critical |
| CVE-2020-11455 | LimeSurvey 4.1.11 - Local File Inclusion | limesurvey | 9.8 (v3.1) | Critical |
| CVE-2020-15568 | TerraMaster TOS <.1.29 - Remote Code Execution | tos | 9.8 (v3.1) | Critical |
| CVE-2020-15920 | Mida eFramework <=2.9.0 - Remote Command Execution | eframework | 9.8 (v3.1) | Critical |
| CVE-2020-17530 | Apache Struts 2.0.0-2.5.25 - Remote Code Execution | struts | 9.8 (v3.1) | Critical |
| CVE-2020-29227 | Car Rental Management System 1.0 - Local File Inclusion | car rental management system | 9.8 (v3.1) | Critical |
| CVE-2020-29390 | Zeroshell 3.9.3 - Command Injection | zeroshell | 9.8 (v3.1) | Critical |
| CVE-2020-5902 | F5 BIG-IP TMUI - Remote Code Execution | big-ip access policy manager | 9.8 (v3.1) | Critical |
| CVE-2020-7209 | LinuxKI Toolset <= 6.01 - Remote Command Execution | linuxki | 9.8 (v3.1) | Critical |
| CVE-2020-9054 | Zyxel NAS Firmware 5.21- Remote Code Execution | nas326 firmware | 9.8 (v3.1) | Critical |
| CVE-2021-40960 | Galera WebTemplate 1.0 Directory Traversal | galera webtemplate | 9.8 (v3.1) | Critical |
| CVE-2021-41773 | Apache 2.4.49 - Path Traversal and Remote Code Execution | http server | 9.8 (v3.1) | Critical |
| CVE-2021-42013 | Apache 2.4.49/2.4.50 - Path Traversal and Remote Code Execution | http server | 9.8 (v3.1) | Critical |
| CVE-2022-1390 | WordPress Admin Word Count Column 2.2 - Local File Inclusion | admin word count column | 9.8 (v3.1) | Critical |
| CVE-2022-1391 | WordPress Cab fare calculator < 1.0.4 - Local File Inclusion | cab fare calculator | 9.8 (v3.1) | Critical |
| CVE-2022-32409 | Portal do Software Publico Brasileiro i3geo 7.0.5 - Local File Inclusion | i3geo | 9.8 (v3.1) | Critical |
| CVE-2022-36553 | Hytec Inter HWL-2511-SS - Remote Command Execution | hwl-2511-ss firmware | 9.8 (v3.1) | Critical |
| CVE-2022-36642 | Omnia MPX 1.5.0+r1 - Local File Inclusion | omnia mpx node firmware | 9.8 (v3.1) | Critical |
| CVE-2022-4060 | WordPress User Post Gallery <=2.19 - Remote Code Execution | user post gallery | 9.8 (v3.1) | Critical |
| CVE-2022-41840 | Welcart eCommerce <=2.7.7 - Local File Inclusion | welcart e-commerce | 9.8 (v3.1) | Critical |
| CVE-2022-47615 | LearnPress Plugin < 4.2.0 - Local File Inclusion | learnpress | 9.8 (v3.1) | Critical |
| CVE-2023-5991 | Hotel Booking Lite < 4.8.5 - Arbitrary File Download & Deletion | hotel booking lite | 9.8 (v3.1) | Critical |
| CVE-2023-6623 | Essential Blocks < 4.4.3 - Local File Inclusion | essential blocks | 9.8 (v3.1) | Critical |
| CVE-2024-12209 | WP Umbrella Update Backup Restore & Monitoring <= 2.17.0 - Local File Inclusion | wp-umbrella | 9.8 (v3.1) | Critical |
| CVE-2024-5827 | Vanna - SQL injection | vanna-ai/vanna | 9.8 (v3.0) | Critical |
| CVE-2025-2294 | Kubio AI Page Builder <= 2.5.1 - Local File Inclusion | Kubio AI Page Builder | 9.8 (v3.1) | Critical |
| CVE-2025-24893 | XWiki Platform - Remote Code Execution | xwiki | 9.8 (v3.1) | Critical |
| CVE-2025-29306 | FoxCMS v.1.2.5 - Remote Code Execution | foxcms | 9.8 (v3.1) | Critical |
| CVE-2025-47445 | WordPress Eventin (Themewinter) ≤ 4.0.26 - Arbitrary File Download | eventin | 9.8 (v3.1) | Critical |
| CVE-2026-12940 | Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoint | langflow | 9.8 (v3.1) | Critical |
| CVE-2026-30118 | scalar/astro v0.1.13 was discovered to Server-Side Request Forgery Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2026-3296 | Everest Forms <= 3.4.3 - Unauthenticated PHP Object Injection via Form Entry Metadata | Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder | 9.8 (v3.1) | Critical |
| CVE-2026-35471 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs | goshs | 9.8 (v3.0) | Critical |
| CVE-2026-35847 | the CheckUils.php file Arbitrary Code Execution Vulnerability | the CheckUils.php file | 9.8 (v3.1) | Critical |
| CVE-2026-37281 | the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 Command Injection Vulnerability | the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 | 9.8 (v3.1) | Critical |
| CVE-2026-38428 | kestra SQL Injection Vulnerability | kestra | 9.8 (v3.1) | Critical |
| CVE-2026-39394 | CI4MS has an .env CRLF Injection via Unvalidated host Parameter in Install Controller | ci4ms | 9.8 (v3.1) | Critical |
| CVE-2026-46562 | Yamcs: Remote Code Execution via Mission Database algorithm override | yamcs | 9.8 (v3.1) | Critical |
| CVE-2026-53545 | Termix: Remote Code Execution via Tunnel Disconnect pkill Command Injection | Termix | 9.8 (v3.1) | Critical |
| CVE-2026-75337 | Yu AI Code Mother v4.3 is vulnerable to path traversal Vulnerability | Yu AI Code Mother v4.3 is vulnerable to path traversal | 9.8 (v3.1) | Critical |
| CVE-2026-84372 | Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections | predis | 9.8 (v3.1) | Critical |
| CVE-2019-8982 | Wavemaker Studio 6.6 - Local File Inclusion/Server-Side Request Forgery | wavemarker studio | 9.6 (v3.0) | Critical |
| CVE-2026-12564 | Automation-controller: automation-controller: kubernetes service account token exfiltration via hashicorp vault credenti | Red Hat Ansible Automation Platform 2 | 9.6 (v3.1) | Critical |
| CVE-2026-12605 | glassfish Server-Side Request Forgery Vulnerability | glassfish | 9.6 (v3.1) | Critical |
| CVE-2026-35906 | An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 OS Command Injection Vulnerability | - | 9.6 (v3.1) | Critical |
| CVE-2026-39932 | OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection | openemr | 9.4 (v4.0) | Critical |
| CVE-2026-69256 | Flowise: Remote Code Execution Vulnerability in CSVAgent | Flowise | 9.4 (v4.0) | Critical |
| CVE-2026-72850 | Budibase before 3.40.0 Arbitrary File Write via Path Traversal | server | 9.4 (v4.0) | Critical |
| CVE-2026-77086 | SiYuan before v3.7.4 Path Traversal via packageName | siyuan | 9.4 (v4.0) | Critical |
| CVE-2018-25357 | Dolibarr ERP CRM 7.0.3 Remote Code Execution via install/step1.php | dolibarr erp/crm | 9.3 (v4.0) | Critical |
| CVE-2019-25727 | WordPress Plugin ad manager wd 1.0.11 Arbitrary File Download | Ad Manager WD | 9.3 (v4.0) | Critical |
| CVE-2024-27954 | WordPress Automatic Plugin <3.92.1 - Arbitrary File Download and SSRF | Automatic | 9.3 (v3.1) | Critical |
| CVE-2026-23734 | XWiki Platform: Path traversal via resources parameter in ssx and jsx endpoints when using leading slash | xwiki-commons | 9.3 (v4.0) | Critical |
| CVE-2026-27174 | MajorDoMo - Unauthenticated RCE | majordomo | 9.3 (v4.0) | Critical |
| CVE-2026-41939 | Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly | Care Everywhere Gateway | 9.3 (v4.0) | Critical |
| CVE-2026-44343 | WGDashboard < 4.3.2 - Unauthenticated File Read | wgdashboard | 9.3 (v4.0) | Critical |
| CVE-2026-44402 | Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi | SNMP Web Pro | 9.3 (v4.0) | Critical |
| CVE-2026-45668 | Trilium Notes : Note Import to RCE via #docName Path Traversal (Safe Import Enabled) | Trilium | 9.3 (v4.0) | Critical |
| CVE-2026-47754 | unauthenticated path traversal in Metacat 2.x | metacat | 9.3 (v3.1) | Critical |
| CVE-2026-53975 | OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/exec | OpenChamber | 9.3 (v4.0) | Critical |
| CVE-2026-53976 | OpenChamber <1.13.0 - Unauthenticated Arbitrary File Read | OpenChamber | 9.3 (v4.0) | Critical |
| CVE-2026-59111 | Command Injection vulnerability in eObčanka-Identifikace | eObčanka-Identifikace | 9.3 (v3.1) | Critical |
| CVE-2026-61498 | Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via gen_graphs.php | flamingo | 9.3 (v4.0) | Critical |
| CVE-2026-61511 | vBulletin 6.x - Remote Code Execution | vBulletin | 9.3 (v4.0) | Critical |
| CVE-2026-63766 | GPT-SoVITS 20250606v2pro OS Command Injection via webui.py | GPT-SoVITS | 9.3 (v4.0) | Critical |
| CVE-2026-64849 | MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirect | mlflow | 9.3 (v3.1) | Critical |
| CVE-2026-65700 | h2oGPT 0.2.1 Path Traversal via OpenAI-compatible Files API | h2ogpt | 9.3 (v4.0) | Critical |
| CVE-2026-66794 | Cluster-proxy-addon: cluster-proxy-addon: unauthenticated ssrf to arbitrary managed-cluster services via public route | multicluster engine for Kubernetes 2.1 | 9.3 (v3.1) | Critical |
| CVE-2026-69110 | OpenCode Studio < 2.4.4 Unauthenticated File Read via /api/tmp and /api/music | opencode-studio | 9.3 (v4.0) | Critical |
| CVE-2026-71921 | DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection via setget.cgi | VigorSwitch G2540xs | 9.3 (v4.0) | Critical |
| CVE-2026-71946 | D-Link DWR-M961 Command Injection via /boafrm/formPingDiagnosticRun | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71947 | D-Link DWR-M961 Command Injection via /boafrm/formTracerouteDiagnosticRun | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71948 | D-Link DWR-M961 Command Injection via /boafrm/formDebugDiagnosticRun | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71955 | D-Link DWR-M961 Command Injection via /boafrm/formWsc | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71984 | MSI Radix AXE6600 v781521 Command Injection via urlfilter | Radix AXE6600 | 9.3 (v4.0) | Critical |
| CVE-2026-71992 | MSI Radix AXE6600 v781521 Command Injection via macfilter | Radix AXE6600 | 9.3 (v4.0) | Critical |
| CVE-2026-72710 | SPIP < 4.4.18 Remote Code Execution via editer_objet.php Job Queue Injection | SPIP | 9.3 (v4.0) | Critical |
| CVE-2026-65317 | Verba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware Bypass | Verba | 9.2 (v4.0) | Critical |
| CVE-2026-65760 | Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0 | Easy Store extension for Joomla | 9.2 (v4.0) | Critical |
| CVE-2026-85614 | OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checker | openpanel | 9.2 (v4.0) | Critical |
| CVE-2026-86119 | Webstudio through 0.296.0 SSRF via /cgi proxy routes | webstudio | 9.2 (v4.0) | Critical |
| CVE-2018-14916 | Loytec LGATE-902 <6.4.2 - Local File Inclusion | lgate-902 | 9.1 (v3.0) | Critical |
| CVE-2018-16716 | NCBI ToolBox - Directory Traversal | ncbi toolbox | 9.1 (v3.0) | Critical |
| CVE-2018-19365 | Wowza Streaming Engine Manager 4.7.4.01 - Directory Traversal | streaming engine | 9.1 (v3.1) | Critical |
| CVE-2021-28918 | Netmask NPM Package - Server-Side Request Forgery | netmask | 9.1 (v3.1) | Critical |
| CVE-2022-26960 | elFinder <=2.1.60 - Local File Inclusion | elfinder | 9.1 (v3.1) | Critical |
| CVE-2024-40422 | Devika v1 - Path Traversal | devika | 9.1 (v3.1) | Critical |
| CVE-2025-55526 | n8n workflow collection Path Traversal Vulnerability | n8n workflow collection | 9.1 (v3.1) | Critical |
| CVE-2026-13147 | WordPress Kirki < 6.0.12 - Server-Side Request Forgery | kirki | 9.1 (v3.1) | Critical |
| CVE-2026-44313 | LinkWarden: Server-Side Request Forgery (SSRF) in Link Creation via fetchTitleAndHeaders Function | linkwarden | 9.1 (v3.1) | Critical |
| CVE-2026-46621 | Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection | yamcs | 9.1 (v3.1) | Critical |
| CVE-2026-52610 | reportico-web <= 8.1.0 Path Traversal Vulnerability | reportico-web <= 8.1.0 | 9.1 (v3.1) | Critical |
| CVE-2026-55511 | Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs executeSql | yamcs | 9.1 (v3.1) | Critical |
| CVE-2026-58400 | GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configuration in formatter | core-geonetwork | 9.1 (v3.1) | Critical |
| CVE-2026-75332 | Zyplayer-Doc <=1.0.0 Server-Side Request Forgery Vulnerability | - | 9.1 (v3.1) | Critical |
| CVE-2008-4668 | Joomla! Image Browser 0.1.5 rc2 - Local File Inclusion | com imagebrowser | 9.0 (v2.0) | High |
| CVE-2026-34612 | Kestra: Remote Code Execution via SQL Injection | kestra | 9.0 (v3.1) | Critical |
| CVE-2026-62674 | Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE | omnigent | 9.0 (v3.1) | Critical |
| CVE-2026-69251 | Flowise RCE via TypeORM DataSource | Flowise | 9.0 (v4.0) | Critical |
| CVE-2026-43945 | FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection | FUXA | 8.9 (v4.0) | High |
| CVE-2026-73570 | zimbra collaboration suite Arbitrary Code Execution Vulnerability | zimbra collaboration suite | 8.9 (v3.1) | High |
| CVE-2016-6277 | NETGEAR Routers - Remote Code Execution | d6220 firmware | 8.8 (v3.1) | High |
| CVE-2017-14535 | Trixbox - 2.8.0.4 OS Command Injection | trixbox | 8.8 (v3.1) | High |
| CVE-2017-6884 | Zyxel_ EMG2926 < V1.00(AAQT.4)b8 - OS Command Injection | emg2926 firmware | 8.8 (v3.1) | High |
| CVE-2018-10093 | AudioCodes 420HD - Remote Code Execution | 420hd ip phone firmware | 8.8 (v3.0) | High |
| CVE-2018-10823 | D-Link Routers - Remote Command Injection | dwr-116 firmware | 8.8 (v3.1) | High |
| CVE-2018-12613 | PhpMyAdmin <4.8.2 - Local File Inclusion | phpmyadmin | 8.8 (v3.1) | High |
| CVE-2019-14530 | OpenEMR <5.0.2 - Local File Inclusion | openemr | 8.8 (v3.1) | High |
| CVE-2020-13851 | Artica Pandora FMS 7.44 - Remote Code Execution | pandora fms | 8.8 (v3.1) | High |
| CVE-2020-15874 | Command Injection | - | 8.8 (v3.1) | High |
| CVE-2020-24579 | D-Link DSL 2888a - Authentication Bypass/Remote Command Execution | dsl2888a firmware | 8.8 (v3.1) | High |
| CVE-2020-8163 | Ruby on Rails <5.0.1 - Remote Code Execution | rails | 8.8 (v3.1) | High |
| CVE-2020-8641 | Lotus Core CMS 1.0.1 - Local File Inclusion | lotus core cms | 8.8 (v3.1) | High |
| CVE-2023-39108 | rConfig 3.9.4 - Server-Side Request Forgery | rconfig | 8.8 (v3.1) | High |
| CVE-2023-39109 | rConfig 3.9.4 - Server-Side Request Forgery | rconfig | 8.8 (v3.1) | High |
| CVE-2023-39110 | rConfig 3.9.4 - Server-Side Request Forgery | rconfig | 8.8 (v3.1) | High |
| CVE-2024-7340 | W&B Weave Server - Remote Arbitrary File Leak | - | 8.8 (v3.1) | High |
| CVE-2026-17623 | Langflow is affected OS Command Injection in Model Context Protocol features | langflow | 8.8 (v3.1) | High |
| CVE-2026-17625 | Langflow is affected by OS Command Injection in Model Context Protocol features | langflow | 8.8 (v3.1) | High |
| CVE-2026-34197 | Apache ActiveMQ - Remote Code Execution | activemq | 8.8 (v3.1) | High |
| CVE-2026-35196 | Chamilo LMS has OS Command Injection via export_all_certificates action | chamilo lms | 8.8 (v3.1) | High |
| CVE-2026-42605 | AzuraCast: Path Traversal in currentDirectory Parameter Enables Remote Code Execution via Media Upload | azuracast | 8.8 (v3.1) | High |
| CVE-2026-50186 | 4gaBoards: Path Traversal leading to Arbitrary File Read and Deletion in Board Export | 4gaBoards | 8.8 (v3.1) | High |
| CVE-2026-72875 | Dokploy: Remote Code Execution (RCE) via Command Injection in settings.readTraefikFile | dokploy | 8.8 (v3.1) | High |
| CVE-2026-76842 | Mercado Pago Node.js SDK through 3.4.0 Path Injection via Unencoded Identifiers in Payment Clients | mercadopago | 8.8 (v4.0) | High |
| CVE-2026-87927 | MaxSite CMS through 109.6 Local File Inclusion via ajax dispatcher | MaxSite CMS | 8.8 (v4.0) | High |
| CVE-2017-20248 | WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File Download | Apptha Slider Gallery | 8.7 (v4.0) | High |
| CVE-2017-20250 | WordPress Plugin Mac Photo Gallery 3.0 Arbitrary File Download | Mac Photo Gallery | 8.7 (v4.0) | High |
| CVE-2018-25374 | Softneta MedDream PACS Server Premium 6.7.1.1 Directory Traversal | MedDream PACS Server Premium | 8.7 (v4.0) | High |
| CVE-2021-4463 | Longjing Technology BEMS API 1.21 - Unauthenticated Arbitrary File Download | BEMS API | 8.7 (v4.0) | High |
| CVE-2021-47943 | TextPattern CMS 4.8.7 Remote Code Execution via File Upload | TextPattern CMS | 8.7 (v4.0) | High |
| CVE-2022-50944 | Aero CMS 0.0.1 PHP Code Injection via posts.php | Aero CMS | 8.7 (v4.0) | High |
| CVE-2024-11303 | Korenix JetPort 5601v3 - Path Traversal | JetPort 5601 | 8.7 (v4.0) | High |
| CVE-2024-26291 | Avid NEXIS Agent - Arbitrary File Read | nexis | 8.7 (v4.0) | High |
| CVE-2025-34031 | Moodle Jmol Filter 6.1 - Local File Inclusion | jmol | 8.7 (v4.0) | High |
| CVE-2025-34115 | OP5 Monitor <= 7.1.9 Authenticated Command Execution via command_test.php | OP5 Monitor | 8.7 (v4.0) | High |
| CVE-2026-10108 | xiaomusic 0.5.7 Path Traversal via GET /music endpoint | xiaomusic | 8.7 (v4.0) | High |
| CVE-2026-17524 | zip-lib Path Traversal Vulnerability | zip-lib | 8.7 (v4.0) | High |
| CVE-2026-25559 | OpenBullet2 0.3.2 Path Traversal via Wordlist Endpoint | openbullet2 | 8.7 (v4.0) | High |
| CVE-2026-25855 | OpenBullet2 0.3.2 Authenticated RCE via FileProxySource Script Upload | openbullet2 | 8.7 (v4.0) | High |
| CVE-2026-25856 | OpenBullet2 0.3.2 Authenticated RCE via Job Configuration Interface | openbullet2 | 8.7 (v4.0) | High |
| CVE-2026-34228 | Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File Write | emlog | 8.7 (v4.0) | High |
| CVE-2026-34367 | InvoiceShelf: SSRF in Invoice PDF Rendering via Unsanitised HTML in Notes Field | invoiceshelf | 8.7 (v3.1) | High |
| CVE-2026-34735 | Hytale Modding Vulnerable to Remote Code Execution via File Upload Bypass in FileController | wiki | 8.7 (v4.0) | High |
| CVE-2026-34792 | Endian Firewall /cgi-bin/logs_clamav.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-34793 | Endian Firewall /cgi-bin/logs_firewall.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-34794 | Endian Firewall /cgi-bin/logs_ids.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-34795 | Endian Firewall /cgi-bin/logs_log.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-34796 | Endian Firewall /cgi-bin/logs_openvpn.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-34797 | Endian Firewall /cgi-bin/logs_smtp.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-47659 | Pathling has path traversal in $import-pnp manifest that enables read-capable SSRF via /jobs/{jobId}/{filename} | pathling | 8.7 (v4.0) | High |
| CVE-2026-47661 | Pathling has path traversal in $result endpoint that allows arbitrary warehouse file read | pathling | 8.7 (v4.0) | High |
| CVE-2026-64837 | ICEcoder through 8.1 OS Command Injection via lib/properties.php | ICEcoder | 8.7 (v4.0) | High |
| CVE-2026-64838 | ICEcoder through 8.1 Path Traversal via oldFileName Parameter | ICEcoder | 8.7 (v4.0) | High |
| CVE-2026-65694 | Microweber CMS <= 2.0.20 - Unauthenticated Arbitrary File Read | microweber | 8.7 (v4.0) | High |
| CVE-2026-65759 | Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 | Easy Store extension for Joomla | 8.7 (v4.0) | High |
| CVE-2026-65919 | Meshery < 1.0.57 Unauthenticated Arbitrary File Read via fileView and fileDownload | meshery | 8.7 (v4.0) | High |
| CVE-2026-67200 | Perspective 5.0.0 Path Traversal via cwd_static_file_handler | perspective | 8.7 (v4.0) | High |
| CVE-2026-67206 | Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload | wolfcms | 8.7 (v4.0) | High |
| CVE-2026-67281 | Unauthenticated file read in Mikrotik RouterOS | RouterOS | 8.7 (v4.0) | High |
| CVE-2026-69089 | Grav CMS before 2.0.11 Path Traversal via watermark | grav | 8.7 (v4.0) | High |
| CVE-2026-69095 | OpenWrt luci-app-bmx7 Path Traversal via bmx7-info | luci | 8.7 (v4.0) | High |
| CVE-2026-75111 | Evidently UI Path Traversal via Dataset Materialization Filename | evidently | 8.7 (v4.0) | High |
| CVE-2026-75482 | SWE-agent Trajectory Inspector Path Traversal File Disclosure | SWE-agent | 8.7 (v4.0) | High |
| CVE-2026-76060 | OS Command Injection in PayRange API | Zoneminder | 8.7 (v4.0) | High |
| CVE-2026-76836 | AzuraCast through 0.23.8 Liquidsoap Configuration Write via Profile Edit Serialization Group Bypass | AzuraCast | 8.7 (v4.0) | High |
| CVE-2026-79756 | Nuclio: Unauthenticated OS command injection via namespace header in list-all resource path on local platform | nuclio | 8.7 (v4.0) | High |
| CVE-2026-81093 | Apify Actors MCP Server before 0.9.12 Server-Side Request Forgery via get-html-skeleton | actors-mcp-server | 8.7 (v4.0) | High |
| CVE-2026-82270 | Portkey AI Gateway Server-Side Request Forgery via /v1/proxy/* | gateway | 8.7 (v4.0) | High |
| CVE-2026-82638 | jina-ai reader Server-Side Request Forgery via disabled private-address guard | reader | 8.7 (v4.0) | High |
| CVE-2026-85608 | Douyin_TikTok_Download_API 4.1.2 SSRF via url parameter | Douyin TikTok Download API | 8.7 (v4.0) | High |
| CVE-2026-85610 | OpenPanel before 2.3.0 Remote Code Execution via chart formulas | openpanel | 8.7 (v4.0) | High |
| CVE-2026-85612 | OpenPanel before 2.3.0 SSRF via favicon and og endpoints | openpanel | 8.7 (v4.0) | High |
| CVE-2026-85673 | LLaMA-Factory SSRF Guard Bypass via Redirect and DNS Rebinding | LlamaFactory | 8.7 (v4.0) | High |
| CVE-2026-85685 | AgentScope through 2.0.7.post1 Arbitrary Directory Copy via add_skill | agentscope | 8.7 (v4.0) | High |
| CVE-2026-89250 | WWBN AVideo Unauthenticated File Read via getRecordedFile.php | AVideo | 8.7 (v4.0) | High |
| CVE-2026-9506 | Path Traversal Vulnerability in Bagisto | Bagisto | 8.7 (v4.0) | High |
| CVE-2015-4694 | WordPress Zip Attachments <= 1.1.4 - Arbitrary File Retrieval | zip attachments | 8.6 (v3.0) | High |
| CVE-2018-16288 | LG SuperSign EZ CMS 2.5 - Local File Inclusion | supersign cms | 8.6 (v3.0) | High |
| CVE-2021-32820 | Express-handlebars - Local File Inclusion | express handlebars | 8.6 (v3.1) | High |
| CVE-2022-24900 | Piano LED Visualizer 1.3 - Local File Inclusion | piano led visualizer | 8.6 (v3.1) | High |
| CVE-2024-20353 | adaptive security appliance software Denial of Service Vulnerability | adaptive security appliance software | 8.6 (v3.1) | High |
| CVE-2024-34470 | HSC Mailinspector 5.2.17-3 through 5.2.18 - Local File Inclusion | mailinspector | 8.6 (v3.1) | High |
| CVE-2025-2558 | WordPress The Wound Theme <= 0.0.1 - Local File Inclusion | the wound | 8.6 (v3.1) | High |
| CVE-2026-30958 | OneUptime < 10.0.21 - Path Traversal | oneuptime | 8.6 (v3.1) | High |
| CVE-2026-34160 | Chamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata ser | chamilo lms | 8.6 (v3.1) | High |
| CVE-2026-34577 | Postiz: Unauthenticated Full-Read SSRF via /public/stream Endpoint with Trivially Bypassable Extension Check | postiz | 8.6 (v3.1) | High |
| CVE-2026-40187 | Authenticated RCE via Malicious eTemplate Upload in EGroupware | egroupware | 8.6 (v4.0) | High |
| CVE-2026-42785 | OpenKM 6.3.12 Remote Code Execution via Administrative Scripting | OpenKM Community Edition | 8.6 (v4.0) | High |
| CVE-2026-46491 | SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditi | simplesamlphp-module-casserver | 8.6 (v3.1) | High |
| CVE-2026-53804 | OTRS Community Edition OS Command Injection via PGP Configuration | OTRS Community Edition | 8.6 (v4.0) | High |
| CVE-2026-54650 | openhole-server vulnerable to path traversal via URL-decoded request path | openhole | 8.6 (v3.1) | High |
| CVE-2026-56703 | Adminer before 5.4.3 Remote Code Execution via SQLite VACUUM INTO | adminer | 8.6 (v4.0) | High |
| CVE-2026-5917 | libgit2 Shell Command Injection via ssh_libssh2 Backend | libgit2 | 8.6 (v4.0) | High |
| CVE-2026-67599 | ClearOS 7.9 OS Command Injection via Log Viewer filter parameter | ClearOS | 8.6 (v4.0) | High |
| CVE-2026-67608 | Telenia TVox 26.5.3 OS Command Injection via action_audio.php | TVox | 8.6 (v4.0) | High |
| CVE-2026-71908 | DrayTek VigorAP Multiple Models OS Command Injection via mesh_start_speed_test | VigorAP 918R | 8.6 (v4.0) | High |
| CVE-2026-71913 | DrayTek VigorAP Multiple Models OS Command Injection via upload_settings.cgi | VigorAP 918R | 8.6 (v4.0) | High |
| CVE-2026-71918 | DrayTek VigorSwitch Multiple Models OS Command Injection via webBackupAction | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71919 | DrayTek VigorSwitch Multiple Models OS Command Injection via sysreboot | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71931 | DrayTek VigorSwitch Multiple Models OS Command Injection via tftp_upgrade | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-7412 | Eclipse BaSyx SSRF Vulnerability | Eclipse BaSyx | 8.6 (v3.1) | High |
| CVE-2026-75123 | PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_smtp_test_post | PLANET GS-4210-16P2S V3 | 8.6 (v4.0) | High |
| CVE-2026-80214 | LibreNMS Virtualisation Discovery Module RCE | librenms | 8.6 (v4.0) | High |
| CVE-2026-81889 | elFinder: SSRF protection bypass via DNS rebinding in the fsock_get_contents() fallback | elFinder | 8.6 (v3.1) | High |
| CVE-2026-82692 | D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injection | DNS-340L | 8.6 (v4.0) | High |
| CVE-2026-86733 | Snipe-IT before 8.7.0 Remote Code Execution via Backup Restore | snipe-it | 8.6 (v4.0) | High |
| CVE-2015-2996 | SysAid Help Desk <15.2 - Local File Inclusion | sysaid | 8.5 (v2.0) | High |
| CVE-2025-34023 | Karel IP Phone IP1211 Web Management Panel - Local File Inclusion | Karel IP Phone IP1211 | 8.5 (v4.0) | High |
| CVE-2026-22244 | OpenMetadata Server-Side Template Injection (SSTI) in FreeMarker email templates that leads to RCE | openmetadata | 8.5 (v4.0) | High |
| CVE-2026-44881 | Portainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-Update | portainer | 8.5 (v4.0) | High |
| CVE-2026-61640 | Wallos: SSRF via OIDC Token/UserInfo URL Configuration | Wallos | 8.5 (v4.0) | High |
| CVE-2026-67424 | Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation | flyto-core | 8.5 (v3.1) | High |
| CVE-2026-69250 | Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration | Flowise | 8.5 (v4.0) | High |
| CVE-2026-73079 | Sub2API: Path traversal in the Responses subpath routes lets an authenticated tenant relay requests to arbitrary upstrea | sub2api | 8.5 (v3.1) | High |
| CVE-2026-82690 | D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injection | DNS-327L | 8.5 (v4.0) | High |
| CVE-2026-85222 | D-Link DNS-340L Add-On Center addon_center.cgi os command injection | DNS-340L | 8.5 (v4.0) | High |
| CVE-2026-85224 | D-Link DNS-320 ShareCenter File Sharing file_sharing.cgi os command injection | DNS-320 ShareCenter | 8.5 (v4.0) | High |
| CVE-2026-72855 | Budibase before 3.40.0 DNS Rebinding SSRF via OpenAPI and REST | server | 8.4 (v4.0) | High |
| CVE-2026-52769 | YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub Signature.keyId | yeswiki | 8.3 (v3.1) | High |
| CVE-2026-76844 | webpack-dev-middleware Path Traversal via Offset Slice on a Non-Slash-Terminated publicPath | webpack-dev-middleware | 8.3 (v4.0) | High |
| CVE-2024-40348 | Bazarr < 1.4.3 - Arbitrary File Read | bazarr | 8.2 (v3.1) | High |
| CVE-2025-44137 | MapTiler Tileserver-php v2.0 - Unauthenticated File Read | tileserver php | 8.2 (v3.1) | High |
| CVE-2025-44177 | White Star Software Protop 4.4.2-2024-11-27 - Local File Inclusion (LFI) | protop | 8.2 (v3.1) | High |
| CVE-2026-16268 | Newsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Bounce Handler | Newsletters | 8.2 (v3.1) | High |
| CVE-2026-23482 | Blinko < 1.8.4 - Path Traversal | blinko | 8.2 (v4.0) | High |
| CVE-2026-39363 | Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket | vite | 8.2 (v4.0) | High |
| CVE-2026-39364 | Vite Dev Server - Directory Traversal | vite | 8.2 (v4.0) | High |
| CVE-2026-40075 | OpenMRS Core arbitrary file read via path traversal in ModuleResourcesServlet | openmrs | 8.2 (v4.0) | High |
| CVE-2026-43910 | Appium java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor | java-client | 8.2 (v3.1) | High |
| CVE-2026-48126 | Algernon: Host header path traversal in –domain mode reads files and runs Lua from parent dir | algernon | 8.2 (v3.1) | High |
| CVE-2026-54691 | datamodel-code-generator vulnerable to SSRF via –url: no host/IP validation, follows redirects | datamodel-code-generator | 8.2 (v3.1) | High |
| CVE-2026-73658 | Trigger.dev: Cross-tenant object store read and write via URL path traversal | trigger.dev | 8.2 (v3.1) | High |
| CVE-2026-74907 | Grav before 2.0.15 Path Traversal via plugin-asset-map.php | grav | 8.2 (v4.0) | High |
| CVE-2026-77348 | Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.ph | Wallos | 8.2 (v3.1) | High |
| CVE-2026-82262 | Logto Server-Side Request Forgery via webhook test endpoint | logto | 8.2 (v4.0) | High |
| CVE-2016-3081 | Apache S2-032 Struts - Remote Code Execution | struts | 8.1 (v3.0) | High |
| CVE-2017-12615 | Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (1) | tomcat | 8.1 (v3.1) | High |
| CVE-2018-11776 | Apache Struts2 S2-057 - Remote Code Execution | struts | 8.1 (v3.1) | High |
| CVE-2024-30188 | Apache DolphinScheduler >= 3.1.0, < 3.2.2 Resource File Read And Write | dolphinscheduler | 8.1 (v3.1) | High |
| CVE-2025-48157 | WordPress Formality Plugin <= 1.5.9 - Local File Inclusion | Formality | 8.1 (v3.1) | High |
| CVE-2026-19303 | Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing c | langflow | 8.1 (v3.1) | High |
| CVE-2026-33236 | NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite | nltk | 8.1 (v3.1) | High |
| CVE-2026-34365 | InvoiceShelf: SSRF in Estimate PDF Rendering via Unsanitised HTML in Notes Field | invoiceshelf | 8.1 (v3.1) | High |
| CVE-2026-34366 | InvoiceShelf: SSRF in Payment Receipt PDF Rendering via Unsanitised HTML in Notes Field | invoiceshelf | 8.1 (v3.1) | High |
| CVE-2026-46484 | Headplane: Path Traversal + RBAC Bypass in renameNode allows authenticated OIDC users to expire or rename any node/user | headplane | 8.1 (v3.1) | High |
| CVE-2026-53580 | Trilium arbitrary file read and denial of service via file:// URLs in the automatic image-download feature | Trilium | 8.1 (v3.1) | High |
| CVE-2026-73659 | Trigger.dev: Cross-tenant object read/write via path traversal in packet presign API | trigger.dev | 8.1 (v3.1) | High |
| CVE-2009-1558 | Cisco Linksys WVC54GCA 1.00R22/1.00R24 - Local File Inclusion | wvc54gca | 7.8 (v2.0) | High |
| CVE-2010-4231 | Camtron CMNC-200 IP Camera - Directory Traversal | cmnc-200 firmware | 7.8 (v2.0) | High |
| CVE-2011-3315 | Cisco CUCM, UCCX, and Unified IP-IVR- Directory Traversal | unified ip interactive voice response | 7.8 (v2.0) | High |
| CVE-2014-2962 | Belkin N150 Router 1.00.08/1.00.09 - Path Traversal | n150 f9k1009 firmware | 7.8 (v2.0) | High |
| CVE-2021-21315 | Node.JS System Information Library <5.3.1 - Remote Command Injection | systeminformation | 7.8 (v3.1) | High |
| CVE-2026-65600 | Traefik before v2.11.52 Authentication Bypass via ReplacePathRegex | traefik | 7.8 (v4.0) | High |
| CVE-2026-67309 | Traefik v3.7.0 Path Traversal via RewriteTarget Authentication Bypass | traefik | 7.8 (v4.0) | High |
| CVE-2020-35749 | WordPress Simple Job Board <2.9.4 - Local File Inclusion | simple board job | 7.7 (v3.1) | High |
| CVE-2021-21234 | Spring Boot Actuator Logview Directory Traversal | spring-boot-actuator-logview | 7.7 (v3.1) | High |
| CVE-2021-43831 | Gradio < 2.5.0 - Arbitrary File Read | gradio | 7.7 (v3.1) | High |
| CVE-2025-46822 | Java-springboot-codebase 1.1 - Arbitrary File Read | Java-springboot-codebase | 7.7 (v4.0) | High |
| CVE-2025-59341 | esm.sh <= v136 - Local File Inclusion | esm.sh | 7.7 (v4.0) | High |
| CVE-2026-34936 | PraisonAI: SSRF via Unvalidated api_base in passthrough() Fallback | praisonai | 7.7 (v3.1) | High |
| CVE-2026-42345 | FastGPT: Cloud metadata endpoint SSRF protection bypass via port specification, IPv6 mapping, hex/decimal IP encoding, a | FastGPT | 7.7 (v3.1) | High |
| CVE-2026-47179 | Arcane: Authenticated Arbitrary Host File Read via Docker Compose Include Directives in Arcane | arcane | 7.7 (v3.1) | High |
| CVE-2026-53549 | Termix: Server-Side Request Forgery via Proxy Connectivity Test | Termix | 7.7 (v3.1) | High |
| CVE-2026-54910 | FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files | filebrowser | 7.7 (v3.1) | High |
| CVE-2026-61835 | Directus: SSRF Protection Bypass via 0.0.0.0 in File Import | directus | 7.7 (v3.1) | High |
| CVE-2026-63764 | LMDeploy Server-Side Request Forgery via HTTP Redirect Bypass | lmdeploy | 7.7 (v4.0) | High |
| CVE-2026-66738 | SPIP < 4.4.18 Code Injection via Navigation Endpoint on SQLite | SPIP | 7.7 (v4.0) | High |
| CVE-2026-67346 | Swarms 6.8.1 Server-Side Request Forgery via DNS Rebinding Bypass | swarms | 7.7 (v4.0) | High |
| CVE-2026-69192 | ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trus | ip-address | 7.7 (v4.0) | High |
| CVE-2026-73498 | MCP Atlassian is a Model Context Protocol (MCP): Arbitrary file read via missing path validation in confluence_upload_at | mcp-atlassian | 7.7 (v3.1) | High |
| CVE-2026-77775 | Headroom Proxy Sends Upstream Requests to a Client-Supplied Base URL Without Address Validation | Headroom | 7.7 (v4.0) | High |
| CVE-2026-8183 | Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement | langflow | 7.7 (v3.1) | High |
| CVE-2026-44239 | FreePBX: Authenticated Local File Inclusion in Dashboard Module | freepbx | 7.6 (v4.0) | High |
| CVE-2026-79749 | MCPHub: SSRF Guard Bypass via IPv6 Transition Addresses in URL Validation | mcphub | 7.6 (v4.0) | High |
| CVE-2006-2842 | Squirrelmail <=1.4.6 - Local File Inclusion | squirrelmail | 7.5 (v2.0) | High |
| CVE-2009-2015 | Joomla! MooFAQ 1.0 - Local File Inclusion | Joomla! | 7.5 (v2.0) | High |
| CVE-2009-3318 | Joomla! Roland Breedveld Album 1.14 - Local File Inclusion | Joomla! | 7.5 (v2.0) | High |
| CVE-2009-4202 | Joomla! Omilen Photo Gallery 0.5b - Local File Inclusion | joomla! | 7.5 (v2.0) | High |
| CVE-2009-4679 | Joomla! Portfolio Nexus - Remote File Inclusion | com if nexus | 7.5 (v2.0) | High |
| CVE-2010-0157 | Joomla! Component com_biblestudy - Local File Inclusion | joomla! | 7.5 (v2.0) | High |
| CVE-2010-0759 | Joomla! Plugin Core Design Scriptegrator - Local File Inclusion | scriptegrator plugin | 7.5 (v2.0) | High |
| CVE-2010-0972 | Joomla! Component com_gcalendar Suite 2.1.5 - Local File Inclusion | com gcalendar | 7.5 (v2.0) | High |
| CVE-2010-0985 | Joomla! Component com_abbrev - Local File Inclusion | com abbrev | 7.5 (v2.0) | High |
| CVE-2010-1306 | Joomla! Component Picasa 2.0 - Local File Inclusion | com joomlapicasa2 | 7.5 (v2.0) | High |
| CVE-2010-1470 | Joomla! Component Web TV 1.0 - Local File Inclusion | com webtv | 7.5 (v2.0) | High |
| CVE-2010-1471 | Joomla! Component Address Book 1.5.0 - Local File Inclusion | com addressbook | 7.5 (v2.0) | High |
| CVE-2010-1472 | Joomla! Component Horoscope 1.5.0 - Local File Inclusion | com horoscope | 7.5 (v2.0) | High |
| CVE-2010-1495 | Joomla! Component Matamko 1.01 - Local File Inclusion | com matamko | 7.5 (v2.0) | High |
| CVE-2010-1531 | Joomla! Component redSHOP 1.0 - Local File Inclusion | com redshop | 7.5 (v2.0) | High |
| CVE-2010-1533 | Joomla! Component TweetLA 1.0.1 - Local File Inclusion | com tweetla | 7.5 (v2.0) | High |
| CVE-2010-1535 | Joomla! Component TRAVELbook 1.0.1 - Local File Inclusion | com travelbook | 7.5 (v2.0) | High |
| CVE-2010-1602 | Joomla! Component ZiMB Comment 0.8.1 - Local File Inclusion | com zimbcomment | 7.5 (v2.0) | High |
| CVE-2010-1603 | Joomla! Component ZiMBCore 0.1 - Local File Inclusion | com zimbcore | 7.5 (v2.0) | High |
| CVE-2010-1653 | Joomla! Component Graphics 1.0.6 - Local File Inclusion | com graphics | 7.5 (v2.0) | High |
| CVE-2010-1717 | Joomla! Component iF surfALERT 1.2 - Local File Inclusion | if surfalert | 7.5 (v2.0) | High |
| CVE-2010-1875 | Joomla! Component Property - Local File Inclusion | com properties | 7.5 (v2.0) | High |
| CVE-2010-1878 | Joomla! Component OrgChart 1.0.0 - Local File Inclusion | com orgchart | 7.5 (v2.0) | High |
| CVE-2010-1952 | Joomla! Component BeeHeard 1.0 - Local File Inclusion | com beeheard | 7.5 (v2.0) | High |
| CVE-2010-1953 | Joomla! Component iNetLanka Multiple Map 1.0 - Local File Inclusion | com multimap | 7.5 (v2.0) | High |
| CVE-2010-1954 | Joomla! Component iNetLanka Multiple root 1.0 - Local File Inclusion | com multiroot | 7.5 (v2.0) | High |
| CVE-2010-1955 | Joomla! Component Deluxe Blog Factory 1.1.2 - Local File Inclusion | com blogfactory | 7.5 (v2.0) | High |
| CVE-2010-1956 | Joomla! Component Gadget Factory 1.0.0 - Local File Inclusion | com gadgetfactory | 7.5 (v2.0) | High |
| CVE-2010-1957 | Joomla! Component Love Factory 1.3.4 - Local File Inclusion | com lovefactory | 7.5 (v2.0) | High |
| CVE-2010-1977 | Joomla! Component J!WHMCS Integrator 1.5.0 - Local File Inclusion | com jwhmcs | 7.5 (v2.0) | High |
| CVE-2010-1980 | Joomla! Component Joomla! Flickr 1.0 - Local File Inclusion | com joomlaflickr | 7.5 (v2.0) | High |
| CVE-2010-1983 | Joomla! Component redTWITTER 1.0 - Local File Inclusion | com redtwitter | 7.5 (v2.0) | High |
| CVE-2010-2033 | Joomla! Percha Categories Tree 0.6 - Local File Inclusion | com perchacategoriestree | 7.5 (v2.0) | High |
| CVE-2010-2034 | Joomla! Component Percha Image Attach 1.1 - Directory Traversal | com perchaimageattach | 7.5 (v2.0) | High |
| CVE-2010-2035 | Joomla! Component Percha Gallery 1.6 Beta - Directory Traversal | com perchagallery | 7.5 (v2.0) | High |
| CVE-2010-2036 | Joomla! Component Percha Fields Attach 1.0 - Directory Traversal | com perchafieldsattach | 7.5 (v2.0) | High |
| CVE-2010-2037 | Joomla! Component Percha Downloads Attach 1.1 - Directory Traversal | com perchadownloadsattach | 7.5 (v2.0) | High |
| CVE-2010-2045 | Joomla! Component FDione Form Wizard 1.0.2 - Local File Inclusion | com dioneformwizard | 7.5 (v2.0) | High |
| CVE-2010-2050 | Joomla! Component MS Comment 0.8.0b - Local File Inclusion | com mscomment | 7.5 (v2.0) | High |
| CVE-2010-2128 | Joomla! Component JE Quotation Form 1.0b1 - Local File Inclusion | com jequoteform | 7.5 (v2.0) | High |
| CVE-2010-2259 | Joomla! Component com_bfsurvey - Local File Inclusion | com bfsurvey profree | 7.5 (v2.0) | High |
| CVE-2010-2682 | Joomla! Component Realtyna Translator 1.0.15 - Local File Inclusion | com realtyna | 7.5 (v2.0) | High |
| CVE-2010-2918 | Joomla! Component Visites 1.1 - MosConfig_absolute_path Remote File Inclusion | com joomla visites | 7.5 (v2.0) | High |
| CVE-2010-3426 | Joomla! Component Jphone 1.0 Alpha 3 - Local File Inclusion | com jphone | 7.5 (v2.0) | High |
| CVE-2010-4282 | Pandora Fms < 3.1.1 - Directory Traversal | pandora fms | 7.5 (v2.0) | High |
| CVE-2010-4719 | Joomla! Component JRadio - Local File Inclusion | com jradio | 7.5 (v2.0) | High |
| CVE-2010-4769 | Joomla! Component Jimtawl 1.0.2 - Local File Inclusion | com jimtawl | 7.5 (v2.0) | High |
| CVE-2010-4977 | Joomla! Component Canteen 1.0 - Local File Inclusion | com canteen | 7.5 (v2.0) | High |
| CVE-2010-5028 | Joomla! Component JE Job 1.0 - Local File Inclusion | com jejob | 7.5 (v2.0) | High |
| CVE-2012-1226 | Dolibarr ERP/CRM 3.2 Alpha - Multiple Directory Traversal Vulnerabilities | dolibarr erp/crm | 7.5 (v2.0) | High |
| CVE-2014-10037 | DomPHP 0.83 - Directory Traversal | domphp | 7.5 (v2.0) | High |
| CVE-2014-3744 | Node.js st module Directory Traversal | node.js | 7.5 (v3.0) | High |
| CVE-2015-1000005 | WordPress Candidate Application Form <= 1.3 - Local File Inclusion | candidate-application-form | 7.5 (v3.0) | High |
| CVE-2015-1000010 | WordPress Simple Image Manipulator < 1.0 - Local File Inclusion | simple-image-manipulator | 7.5 (v3.0) | High |
| CVE-2015-1000012 | WordPress MyPixs <=0.3 - Local File Inclusion | mypixs | 7.5 (v3.0) | High |
| CVE-2015-1503 | IceWarp Mail Server < 11.1.1 - Directory Traversal | mail server | 7.5 (v3.0) | High |
| CVE-2015-3035 | TP-LINK - Local File Inclusion | tl-wr841n (9.0) firmware | 7.5 (v3.1) | High |
| CVE-2015-3648 | ResourceSpace - Local File inclusion | resourcespace | 7.5 (v2.0) | High |
| CVE-2015-4074 | Joomla! Helpdesk Pro plugin <1.4.0 - Local File Inclusion | helpdesk pro | 7.5 (v3.0) | High |
| CVE-2015-4632 | Koha 3.20.1 - Directory Traversal | koha | 7.5 (v3.0) | High |
| CVE-2015-5469 | WordPress MDC YouTube Downloader 2.1.0 - Local File Inclusion | mdc youtube downloader | 7.5 (v3.0) | High |
| CVE-2016-10956 | WordPress Mail Masta 1.0 - Local File Inclusion | mail-masta | 7.5 (v3.1) | High |
| CVE-2016-2389 | SAP xMII 15.0 for SAP NetWeaver 7.4 - Local File Inclusion | netweaver | 7.5 (v3.0) | High |
| CVE-2016-6601 | WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities | webnms framework | 7.5 (v3.0) | High |
| CVE-2017-1000028 | Oracle GlassFish Server Open Source Edition 4.1 - Local File Inclusion | glassfish server | 7.5 (v3.0) | High |
| CVE-2017-1000029 | Oracle GlassFish Server Open Source Edition 3.0.1 - Local File Inclusion | glassfish server | 7.5 (v3.0) | High |
| CVE-2017-14849 | Node.js <8.6.0 - Directory Traversal | node.js | 7.5 (v3.0) | High |
| CVE-2017-15647 | FiberHome Routers - Local File Inclusion | routerfiberhome firmware | 7.5 (v3.0) | High |
| CVE-2017-16806 | Ulterius Server < 1.9.5.0 - Directory Traversal | ulterius server | 7.5 (v3.0) | High |
| CVE-2017-16877 | Nextjs <2.4.1 - Local File Inclusion | next.js | 7.5 (v3.0) | High |
| CVE-2017-6190 | D-Link DWR-116 / DWR-116A1 - Arbitrary File Download | dwr-116 firmware | 7.5 (v3.0) | High |
| CVE-2017-9833 | BOA Web Server 0.94.14 - Arbitrary File Access | boa | 7.5 (v3.1) | High |
| CVE-2018-10822 | D-Link Routers - Local File Inclusion | dwr-116 firmware | 7.5 (v3.1) | High |
| CVE-2018-10956 | IPConfigure Orchid Core VMS 2.0.5 - Local File Inclusion | orchid core vms | 7.5 (v3.0) | High |
| CVE-2018-12909 | Webgrind <= 1.5 - Local File Inclusion | webgrind | 7.5 (v3.0) | High |
| CVE-2018-14912 | cgit < 1.2.1 - Directory Traversal | cgit | 7.5 (v3.0) | High |
| CVE-2018-14918 | LOYTEC LGATE-902 6.3.2 - Local File Inclusion | lgate-902 firmware | 7.5 (v3.0) | High |
| CVE-2018-15138 | LG-Ericsson iPECS NMS 30M - Local File Inclusion | ipecs nms | 7.5 (v3.0) | High |
| CVE-2018-15535 | Responsive FileManager < 9.13.4 - Directory Traversal | responsive filemanager | 7.5 (v3.0) | High |
| CVE-2018-16299 | WordPress Localize My Post 1.0 - Local File Inclusion | localize my post | 7.5 (v3.0) | High |
| CVE-2018-18323 | Centos Web Panel 0.9.8.480 - Local File Inclusion | webpanel | 7.5 (v3.0) | High |
| CVE-2018-19326 | Zyxel VMG1312-B10D 5.13AAXA.8 - Local File Inclusion | vmg1312-b10d firmware | 7.5 (v3.0) | High |
| CVE-2018-19458 | PHP Proxy 3.0.3 - Local File Inclusion | php-proxy | 7.5 (v3.0) | High |
| CVE-2018-19753 | Tarantella Enterprise <3.11 - Local File Inclusion | tarantella enterprise | 7.5 (v3.0) | High |
| CVE-2018-3760 | Ruby On Rails - Local File Inclusion | cloudforms | 7.5 (v3.0) | High |
| CVE-2018-6008 | Joomla! Jtag Members Directory 5.3.7 - Local File Inclusion | jtag members directory | 7.5 (v3.0) | High |
| CVE-2018-6184 | Zeit Next.js < 4.2.3 - Local File Inclusion | next.js | 7.5 (v3.0) | High |
| CVE-2018-7422 | WordPress Site Editor <=1.1.1 - Local File Inclusion | site editor | 7.5 (v3.0) | High |
| CVE-2018-7490 | uWSGI PHP Plugin Local File Inclusion | uwsgi | 7.5 (v3.0) | High |
| CVE-2018-9205 | Drupal avatar_uploader v7.x-1.0-beta8 - Local File Inclusion | avatar uploader | 7.5 (v3.0) | High |
| CVE-2019-12276 | GrandNode 4.40 - Local File Inclusion | grandnode | 7.5 (v3.0) | High |
| CVE-2019-14251 | T24 Web Server - Local File Inclusion | t24 | 7.5 (v3.1) | High |
| CVE-2019-16123 | PilusCart <=1.4.1 - Local File Inclusion | piluscart | 7.5 (v3.1) | High |
| CVE-2019-17538 | Jiangnan Online Judge 0.8.0 - Local File Inclusion | jiangnan online judge | 7.5 (v3.1) | High |
| CVE-2019-18371 | Xiaomi Mi WiFi R3G Routers - Local file Inclusion | millet router 3g firmware | 7.5 (v3.1) | High |
| CVE-2019-18665 | DOMOS 5.5 - Local File Inclusion | domos | 7.5 (v3.1) | High |
| CVE-2019-18922 | Allied Telesis AT-GS950/8 - Local File Inclusion | at-gs950/8 firmware | 7.5 (v3.1) | High |
| CVE-2019-7254 | eMerge E3 1.00-06 - Local File Inclusion | linear emerge essential firmware | 7.5 (v3.1) | High |
| CVE-2019-7315 | Genie Access WIP3BVAF IP Camera - Local File Inclusion | wip3bvaf | 7.5 (v3.0) | High |
| CVE-2019-9922 | Joomla! Harmis Messenger 1.2.2 - Local File Inclusion | je messenger | 7.5 (v3.1) | High |
| CVE-2020-11738 | WordPress Duplicator 1.3.24 & 1.3.26 - Local File Inclusion | duplicator | 7.5 (v3.1) | High |
| CVE-2020-12447 | Onkyo TX-NR585 Web Interface - Directory Traversal | tx-nr585 firmware | 7.5 (v3.1) | High |
| CVE-2020-13158 | Artica Proxy Community Edition <4.30.000000 - Local File Inclusion | artica proxy | 7.5 (v3.1) | High |
| CVE-2020-14864 | Oracle Fusion - Directory Traversal/Local File Inclusion | business intelligence | 7.5 (v3.1) | High |
| CVE-2020-19360 | FHEM 6.0 - Local File Inclusion | fhem | 7.5 (v3.1) | High |
| CVE-2020-23575 | Kyocera Printer d-COPIA253MF - Directory Traversal | d-copia253mf plus firmware | 7.5 (v3.1) | High |
| CVE-2020-24285 | INTELBRAS TELEFONE IP TIP200 60.61.75.22 - Local File Inclusion | tip200 | 7.5 (v3.1) | High |
| CVE-2020-26073 | Cisco SD-WAN vManage Software - Local File Inclusion | catalyst sd-wan manager | 7.5 (v3.1) | High |
| CVE-2020-27191 | LionWiki <3.2.12 - Local File Inclusion | lionwiki | 7.5 (v3.1) | High |
| CVE-2020-27467 | Processwire CMS <2.7.1 - Local File Inclusion | processwire | 7.5 (v3.1) | High |
| CVE-2020-35580 | SearchBlox <9.2.2 - Local File Inclusion | searchblox | 7.5 (v3.1) | High |
| CVE-2020-35598 | Advanced Comment System 1.0 - Local File Inclusion | advanced comment system | 7.5 (v3.1) | High |
| CVE-2020-35736 | GateOne 1.1 - Local File Inclusion | gateone | 7.5 (v3.1) | High |
| CVE-2020-8209 | Citrix XenMobile Server - Local File Inclusion | xenmobile server | 7.5 (v3.1) | High |
| CVE-2021-20123 | Draytek VigorConnect 1.6.0-B - Local File Inclusion | vigorconnect | 7.5 (v3.1) | High |
| CVE-2021-20124 | Draytek VigorConnect 6.0-B3 - Local File Inclusion | vigorconnect | 7.5 (v3.1) | High |
| CVE-2021-24227 | Patreon WordPress <1.7.0 - Unauthenticated Local File Inclusion | patreon wordpress | 7.5 (v3.1) | High |
| CVE-2021-25864 | Hue Magic 3.0.0 - Local File Inclusion | huemagic | 7.5 (v3.1) | High |
| CVE-2021-3223 | Node RED Dashboard <2.26.2 - Local File Inclusion | node-red-dashboard | 7.5 (v3.1) | High |
| CVE-2021-39316 | WordPress DZS Zoomsounds <=6.50 - Local File Inclusion | zoomsounds | 7.5 (v3.1) | High |
| CVE-2021-39433 | BIQS IT Biqs-drive v1.83 Local File Inclusion | biqsdrive | 7.5 (v3.1) | High |
| CVE-2021-40978 | MKdocs 1.2.2 - Directory Traversal | mkdocs | 7.5 (v3.1) | High |
| CVE-2021-41277 | Metabase - Local File Inclusion | metabase | 7.5 (v3.1) | High |
| CVE-2021-41291 | ECOA Building Automation System - Directory Traversal Content Disclosure | ecs router controller-ecs firmware | 7.5 (v3.1) | High |
| CVE-2021-41569 | SAS/Internet 9.4 1520 - Local File Inclusion | sas/intrnet | 7.5 (v3.1) | High |
| CVE-2021-43287 | Pre-Auth Takeover of Build Pipelines in GoCD | gocd | 7.5 (v3.1) | High |
| CVE-2021-43495 | AlquistManager Local File Inclusion | alquist | 7.5 (v3.1) | High |
| CVE-2021-43496 | Clustering Local File Inclusion | clustering | 7.5 (v3.1) | High |
| CVE-2021-43734 | kkFileview v4.0.0 - Local File Inclusion | kkfileview | 7.5 (v3.1) | High |
| CVE-2021-43778 | GLPI plugin Barcode < 2.6.1 - Path Traversal Vulnerability. | barcode | 7.5 (v3.1) | High |
| CVE-2021-43798 | Grafana v8.x - Arbitrary File Read | grafana | 7.5 (v3.1) | High |
| CVE-2021-46107 | Ligeo Archives Ligeo Basics - Server Side Request Forgery | ligeo basics | 7.5 (v3.1) | High |
| CVE-2021-46417 | Franklin Fueling Systems Colibri Controller Module 1.8.19.8580 - Local File Inclusion (LFI) | colibri firmware | 7.5 (v3.1) | High |
| CVE-2022-24716 | Icinga Web 2 - Arbitrary File Disclosure | icinga web 2 | 7.5 (v3.1) | High |
| CVE-2022-27043 | Yearning - Directory Traversal | yearning | 7.5 (v3.1) | High |
| CVE-2022-29298 | SolarView Compact 6.00 - Local File Inclusion | sv-cpt-mc310 firmware | 7.5 (v3.1) | High |
| CVE-2022-31474 | BackupBuddy - Local File Inclusion | backupbuddy | 7.5 (v3.1) | High |
| CVE-2022-33901 | WordPress MultiSafepay for WooCommerce <=4.13.1 - Arbitrary File Read | multisafepay plugin for woocommerce | 7.5 (v3.1) | High |
| CVE-2022-37122 | Carel pCOWeb HVAC BACnet Gateway 2.1.0 - Path Traversal | pcoweb hvac bacnet gateway | 7.5 (v3.1) | High |
| CVE-2022-38794 | Zaver - Local File Inclusion | zaver | 7.5 (v3.1) | High |
| CVE-2022-4140 | WordPress Welcart e-Commerce <2.8.5 - Arbitrary File Access | welcart e-commerce | 7.5 (v3.1) | High |
| CVE-2022-47501 | Apache OFBiz < 18.12.07 - Local File Inclusion | ofbiz | 7.5 (v3.1) | High |
| CVE-2023-0126 | SonicWall SMA1000 LFI | sma1000 | 7.5 (v3.1) | High |
| CVE-2023-22047 | Oracle Peoplesoft - Unauthenticated File Read | peoplesoft enterprise | 7.5 (v3.1) | High |
| CVE-2023-23063 | Cellinx NVT Web Server - Local File Disclosure | nvt web server | 7.5 (v3.1) | High |
| CVE-2023-26256 | STAGIL Navigation for Jira Menu & Themes <2.0.52 - Local File Inclusion | stagil navigation | 7.5 (v3.1) | High |
| CVE-2023-29887 | Nuovo Spreadsheet Reader 0.5.11 - Local File Inclusion | spreadsheet-reader | 7.5 (v3.1) | High |
| CVE-2023-33510 | Jeecg P3 Biz Chat - Local File Inclusion | jeecg p3 biz chat | 7.5 (v3.1) | High |
| CVE-2023-35843 | NocoDB version <= 0.106.1 - Arbitrary File Read | nocodb | 7.5 (v3.1) | High |
| CVE-2023-35844 | Lightdash version <= 0.510.3 Arbitrary File Read | lightdash | 7.5 (v3.1) | High |
| CVE-2023-37474 | Copyparty <= 1.8.2 - Directory Traversal | copyparty | 7.5 (v3.1) | High |
| CVE-2023-38879 | openSIS v9.0 - Path Traversal | opensis | 7.5 (v3.1) | High |
| CVE-2023-39141 | Aria2 WebUI - Path traversal | webui-aria2 | 7.5 (v3.1) | High |
| CVE-2023-40924 | SolarView Compact < 6.00 - Directory Traversal | solarview compact firmware | 7.5 (v3.1) | High |
| CVE-2023-6020 | Ray Static File - Local File Inclusion | ray | 7.5 (v3.1) | High |
| CVE-2023-6023 | VertaAI ModelDB - Path Traversal | modeldb | 7.5 (v3.1) | High |
| CVE-2023-6038 | H2O ImportFiles - Local File Inclusion | h2o | 7.5 (v3.1) | High |
| CVE-2024-23334 | aiohttp - Directory Traversal | aiohttp | 7.5 (v3.1) | High |
| CVE-2024-27292 | Docassemble - Local File Inclusion | docassemble | 7.5 (v3.1) | High |
| CVE-2024-38816 | WebMvc.fn/WebFlux.fn - Path Traversal | Spring | 7.5 (v3.1) | High |
| CVE-2024-38819 | Spring Framework Path Traversal in Functional Web Frameworks | spring framework | 7.5 (v3.1) | High |
| CVE-2024-41628 | Cluster Control CMON API - Directory Traversal | cluster control | 7.5 (v3.1) | High |
| CVE-2024-4956 | Sonatype Nexus Repository Manager 3 - Local File Inclusion | nexus | 7.5 (v3.1) | High |
| CVE-2024-5334 | Devika - Local File Inclusion | devika | 7.5 (v3.0) | High |
| CVE-2024-9362 | Polyaxon - Unauthenticated Directory Traversal | polyaxon/polyaxon | 7.5 (v3.0) | High |
| CVE-2024-9935 | PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Arbitrary File Download | pdf-generator-addon-for-elementor-page-builder | 7.5 (v3.1) | High |
| CVE-2025-13339 | Hippoo Mobile App for WooCommerce <= 1.7.1 - Unauthenticated Arbitrary File Read | Hippoo Mobile App for WooCommerce | 7.5 (v3.1) | High |
| CVE-2025-13801 | Yoco Payments <= 3.8.8 - Path Traversal | Yoco Payments | 7.5 (v3.1) | High |
| CVE-2025-24963 | Vitest Browser Mode - Local File Read | vitest | 7.5 (v3.1) | High |
| CVE-2025-30208 | Vite - Arbitrary File Read | vite | 7.5 (v3.1) | High |
| CVE-2025-31125 | Vite Development Server - Path Traversal | vite | 7.5 (v3.1) | High |
| CVE-2025-31131 | Yeswiki < 4.5.2 - Unauthenticated Path Traversal | yeswiki | 7.5 (v3.1) | High |
| CVE-2025-45145 | Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 Path Traversal Vulnerability | - | 7.5 (v3.1) | High |
| CVE-2025-57231 | Path Traversal in avatar attachments in Docmost v0.21.0 Vulnerability | - | 7.5 (v3.1) | High |
| CVE-2025-59049 | Mockoon < 9.2.0 - Path Traversal | mockoon | 7.5 (v3.1) | High |
| CVE-2025-61884 | Oracle E-Business Suite - Server-Side Request Forgery | configurator | 7.5 (v3.1) | High |
| CVE-2025-69411 | ionCube Tester Plus <= 1.3 - Local File Inclusion | ionCube tester plus | 7.5 (v3.1) | High |
| CVE-2026-29962 | HSC MailInspector - Local File Inclusion | mailinspector | 7.5 (v3.1) | High |
| CVE-2026-32820 | dataCycle Public Markdown Path Traversal Via /docs/*path | dataCycle-CORE | 7.5 (v3.1) | High |
| CVE-2026-34239 | Chamilo Authenticated Remote Code Execution | chamilo-lms | 7.5 (v4.0) | High |
| CVE-2026-36783 | Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to Denial of Service Vulnerability | - | 7.5 (v3.1) | High |
| CVE-2026-36796 | Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to Denial of Service Vulnerability | - | 7.5 (v3.1) | High |
| CVE-2026-39847 | Emmett has a path traversal in internal assets handler | emmett | 7.5 (v3.1) | High |
| CVE-2026-46581 | mojarra Path Traversal Vulnerability | mojarra | 7.5 (v3.1) | High |
| CVE-2026-50776 | Pronis Loisirs Billetterie CSE - < 04/2026 Arbitrary Code Execution Vulnerability | Pronis Loisirs Billetterie CSE - < 04/2026 | 7.5 (v3.1) | High |
| CVE-2026-53599 | Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mo | core | 7.5 (v3.1) | High |
| CVE-2026-54293 | NLTK: URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Read | nltk | 7.5 (v3.1) | High |
| CVE-2026-5487 | DriveLock Directory Traversal Information Disclosure Vulnerability | DriveLock | 7.5 (v3.0) | High |
| CVE-2026-5491 | DriveLock Directory Traversal Information Disclosure Vulnerability | DriveLock | 7.5 (v3.0) | High |
| CVE-2026-55552 | Yamcs: Unauthenticated Directory Traversal | yamcs | 7.5 (v3.1) | High |
| CVE-2026-56671 | ComfyUI: Path traversal in /experiment/models/preview allows arbitrary image file read | ComfyUI | 7.5 (v3.1) | High |
| CVE-2026-61891 | theia Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | theia | 7.5 (v3.1) | High |
| CVE-2026-71209 | audiobookshelf - %2F Encoding Discrepancy Bypasses Cover/Image Auth Exemption Regex, Enabling Unauthenticated Path Trave | audiobookshelf | 7.5 (v3.1) | High |
| CVE-2026-75328 | In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java Path Traversal Vulnerability | In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java | 7.5 (v3.1) | High |
| CVE-2026-75333 | yx-image-recognition v1.0 Path Traversal Vulnerability | - | 7.5 (v3.1) | High |
| CVE-2026-19771 | Baicells EG3661M LuCI Web luci os command injection | EG3661M | 7.3 (v4.0) | High |
| CVE-2026-20297 | Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise | splunk | 7.2 (v3.1) | High |
| CVE-2026-27891 | Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanism | facturascripts | 7.2 (v3.1) | High |
| CVE-2026-34607 | Emlog: Path Traversal in emUnZip() allows arbitrary file write leading to RCE | emlog | 7.2 (v3.1) | High |
| CVE-2026-35174 | Chyrp Lite has a Path Traversal to Remote Code Execution | chyrp lite | 7.2 (v3.1) | High |
| CVE-2026-3576 | Planyo Online Reservation System <= 3.0 - Arbitrary File Read | Planyo online reservation system | 7.2 (v3.1) | High |
| CVE-2026-39387 | BoidCMS: Local File Inclusion (LFI) leads to Remote Code Execution (RCE) via tpl parameter | boidcms | 7.2 (v3.1) | High |
| CVE-2026-85160 | AVideo through c91b5975d CSRF and Path Traversal via stopLive.php | AVideo | 7.2 (v4.0) | High |
| CVE-2018-25393 | Navigate CMS 2.8.5 Path Traversal via navigate_download.php | Navigate CMS | 7.1 (v4.0) | High |
| CVE-2018-25421 | Open STA Manager 2.3 Arbitrary File Download via Path Traversal | Open STA Manager | 7.1 (v4.0) | High |
| CVE-2019-25246 | BEWARD N100 H.264 VGA IP Camera M2.1.6 - Arbitrary File Disclosure | N100 H.264 VGA IP Camera | 7.1 (v4.0) | High |
| CVE-2026-22664 | prompts.chat SSRF via Fal.ai Media Status Polling | prompts.chat | 7.1 (v4.0) | High |
| CVE-2026-40526 | Volmarg Personal Management System Path Traversal via get-file Endpoint | personal-management-system | 7.1 (v4.0) | High |
| CVE-2026-45725 | compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal | compliance-trestle | 7.1 (v4.0) | High |
| CVE-2026-46555 | WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltration | whatsapp mcp server | 7.1 (v3.1) | High |
| CVE-2026-64826 | rConfig < 8.2.13 Path Traversal File Read via FileDownloadController | rConfig | 7.1 (v4.0) | High |
| CVE-2026-75844 | ArcadeDB before 26.8.1 SSRF via IMPORT DATABASE validator bypass | arcadedb | 7.1 (v4.0) | High |
| CVE-2026-76210 | phpMyFAQ before v4.1.6 Local File Disclosure via PDF Export | phpmyfaq | 7.1 (v4.0) | High |
| CVE-2026-79747 | MCPHub vulnerable to SSRF: a non-admin user can make mcphub request arbitrary URLs and read the response (OpenAPI proxy | mcphub | 7.1 (v3.1) | High |
| CVE-2026-81030 | Mage AI through 0.9.79 Arbitrary File Read via Unvalidated Path in browser_items Endpoint | mage-ai | 7.1 (v4.0) | High |
| CVE-2026-85164 | WWBN AVideo Server-Side Request Forgery via set_api_userImages | AVideo | 7.1 (v4.0) | High |
| CVE-2026-10107 | MoviePilot v2 SSRF via /api/v1/system/img/{proxy} Endpoint | MoviePilot | 7.0 (v4.0) | High |
| CVE-2026-40506 | OpenEMR Path Traversal Arbitrary Directory Deletion via standard_tables_manage.php | openemr | 7.0 (v4.0) | High |
| CVE-2026-54134 | OctoPrint: File exfiltration possible via query parameters on upload endpoints | OctoPrint | 7.0 (v4.0) | High |
| CVE-2026-73033 | Sucuri WordPress Plugin 2.7.3 Path Traversal via integrity.lib.php | sucuri-wordpress-plugin | 7.0 (v4.0) | High |
| CVE-2019-25760 | Joomla! Component Easy Shop 1.2.3 Local File Inclusion | easy shop | 6.9 (v4.0) | Medium |
| CVE-2022-50954 | WordPress Plugin cab-fare-calculator 1.0.3 Local File Inclusion | cab-fare-calculator | 6.9 (v4.0) | Medium |
| CVE-2022-50956 | WordPress Plugin amministrazione-aperta 3.7.3 Local File Read | amministrazione-aperta | 6.9 (v4.0) | Medium |
| CVE-2024-12987 | DrayTek Vigor - Command Injection | Vigor300B | 6.9 (v4.0) | Medium |
| CVE-2025-1743 | Pichome 2.1.0 - Arbitrary File Read | Pichome | 6.9 (v4.0) | Medium |
| CVE-2026-19983 | GL.iNet XE3000 NAS Command Service gl_nas_sys os command injection | A1300 | 6.9 (v4.0) | Medium |
| CVE-2026-23483 | Blinko <= 1.8.3 - Path Traversal via /plugins | blinko | 6.9 (v4.0) | Medium |
| CVE-2026-29059 | Windmill/Nextcloud Flow < 1.603.3 - Unauthenticated Path Traversal | windmill | 6.9 (v4.0) | Medium |
| CVE-2026-34964 | Adminer before 5.5.0 SSRF via PDO DSN Injection | adminer | 6.9 (v4.0) | Medium |
| CVE-2026-41917 | OpenKM 6.3.12 Local File Inclusion via Admin Scripting | OpenKM Community Edition | 6.9 (v4.0) | Medium |
| CVE-2026-44652 | SillyTavern: SSRF vulnerability in the CORS proxy middleware | SillyTavern | 6.9 (v4.0) | Medium |
| CVE-2026-45774 | compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal | compliance-trestle | 6.9 (v4.0) | Medium |
| CVE-2026-46337 | WWBN AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in view/img/image404Raw.php | avideo | 6.9 (v4.0) | Medium |
| CVE-2026-54885 | Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri fetching | boruta | 6.9 (v4.0) | Medium |
| CVE-2026-59809 | SiYuan before v3.8.0 Secret Exfiltration via http_request URL | siyuan | 6.9 (v4.0) | Medium |
| CVE-2026-71932 | DrayTek VigorSwitch Multiple Models Path Traversal via getSyslogFile | VigorSwitch G2540xs | 6.9 (v4.0) | Medium |
| CVE-2026-73058 | stoatchat before 0.15.0 SSRF via IPv6 unspecified address bypass | stoatchat | 6.9 (v4.0) | Medium |
| CVE-2026-74235 | GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Configuration Download Handler | GFI Exinda AI | 6.9 (v4.0) | Medium |
| CVE-2026-75592 | Kirby: Access to image files outside of the site root via path traversal in the media handling | kirby | 6.9 (v4.0) | Medium |
| CVE-2026-79743 | MCPHub: Path Traversal via Malicious MCPB Manifest Name | mcphub | 6.9 (v4.0) | Medium |
| CVE-2026-79773 | Winter CMS before 1.2.13 Local File Inclusion via JavaScript | winter | 6.9 (v4.0) | Medium |
| CVE-2026-79781 | rclone serve s3 Path Traversal via dot-dot object keys | rclone | 6.9 (v4.0) | Medium |
| CVE-2026-81678 | AVideo SSRF Guard Bypass via IPv6 Transition Addresses | AVideo | 6.9 (v4.0) | Medium |
| CVE-2026-85609 | Openpanel before 2.3.0 SSRF via Site Checker Endpoint | openpanel | 6.9 (v4.0) | Medium |
| CVE-2026-86806 | opengeos GeoLibre _is_within_roots server-side request forgery | GeoLibre | 6.9 (v4.0) | Medium |
| CVE-2026-8712 | Wyoming < 1.10.2 SSRF via uri Query Parameter | wyoming | 6.9 (v4.0) | Medium |
| CVE-2026-88940 | knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint | knowns | 6.9 (v4.0) | Medium |
| CVE-2008-2650 | CMSimple 3.1 - Local File Inclusion | cmsimple | 6.8 (v2.0) | Medium |
| CVE-2008-6172 | Joomla! Component RWCards 3.0.11 - Local File Inclusion | rwcards | 6.8 (v2.0) | Medium |
| CVE-2009-3053 | Joomla! Agora 3.0.0b - Local File Inclusion | Joomla! | 6.8 (v2.0) | Medium |
| CVE-2010-1056 | Joomla! Component com_rokdownloads - Local File Inclusion | com rokdownloads | 6.8 (v2.0) | Medium |
| CVE-2010-1219 | Joomla! Component com_janews - Local File Inclusion | com janews | 6.8 (v2.0) | Medium |
| CVE-2010-1469 | Joomla! Component JProject Manager 1.0 - Local File Inclusion | com jprojectmanager | 6.8 (v2.0) | Medium |
| CVE-2010-1473 | Joomla! Component Advertising 0.25 - Local File Inclusion | com advertising | 6.8 (v2.0) | Medium |
| CVE-2010-1474 | Joomla! Component Sweetykeeper 1.5 - Local File Inclusion | com sweetykeeper | 6.8 (v2.0) | Medium |
| CVE-2010-1475 | Joomla! Component Preventive And Reservation 1.0.5 - Local File Inclusion | com preventive | 6.8 (v2.0) | Medium |
| CVE-2010-1476 | Joomla! Component AlphaUserPoints 1.5.5 - Local File Inclusion | com alphauserpoints | 6.8 (v2.0) | Medium |
| CVE-2010-1478 | Joomla! Component Jfeedback 1.2 - Local File Inclusion | com jfeedback | 6.8 (v2.0) | Medium |
| CVE-2010-1607 | Joomla! Component WMI 1.5.0 - Local File Inclusion | com wmi | 6.8 (v2.0) | Medium |
| CVE-2010-1715 | Joomla! Component Online Exam 1.5.0 - Local File Inclusion | com onlineexam | 6.8 (v2.0) | Medium |
| CVE-2010-1718 | Joomla! Component Archery Scores 1.0.6 - Local File Inclusion | com archeryscores | 6.8 (v2.0) | Medium |
| CVE-2010-1719 | Joomla! Component MT Fire Eagle 1.2 - Local File Inclusion | com mtfireeagle | 6.8 (v2.0) | Medium |
| CVE-2010-1722 | Joomla! Component Online Market 2.x - Local File Inclusion | com market | 6.8 (v2.0) | Medium |
| CVE-2010-1723 | Joomla! Component iNetLanka Contact Us Draw Root Map 1.1 - Local File Inclusion | com drawroot | 6.8 (v2.0) | Medium |
| CVE-2010-1979 | Joomla! Component Affiliate Datafeeds 880 - Local File Inclusion | com datafeeds | 6.8 (v2.0) | Medium |
| CVE-2010-1981 | Joomla! Component Fabrik 2.0 - Local File Inclusion | fabrik | 6.8 (v2.0) | Medium |
| CVE-2010-2122 | Joomla! Component simpledownload <=0.9.5 - Arbitrary File Retrieval | com simpledownload | 6.8 (v2.0) | Medium |
| CVE-2010-2507 | Joomla! Component Picasa2Gallery 1.2.8 - Local File Inclusion | com picasa2gallery | 6.8 (v2.0) | Medium |
| CVE-2010-2680 | Joomla! Component jesectionfinder - Local File Inclusion | com jesectionfinder | 6.8 (v2.0) | Medium |
| CVE-2010-2857 | Joomla! Component Music Manager - Local File Inclusion | com music | 6.8 (v2.0) | Medium |
| CVE-2010-2920 | Joomla! Component Foobla Suggestions 1.5.1.2 - Local File Inclusion | com foobla suggestions | 6.8 (v2.0) | Medium |
| CVE-2010-4617 | Joomla! Component JotLoader 2.2.1 - Local File Inclusion | com jotloader | 6.8 (v2.0) | Medium |
| CVE-2011-2744 | Chyrp 2.x - Local File Inclusion | chyrp | 6.8 (v2.0) | Medium |
| CVE-2012-0392 | Apache Struts2 S2-008 RCE | struts | 6.8 (v2.0) | Medium |
| CVE-2014-2383 | Dompdf < v0.6.0 - Local File Inclusion | dompdf | 6.8 (v2.0) | Medium |
| CVE-2026-71475 | Insights-client-rhel9: insights-client: spoke-controlled clusterid injected unencoded into insights api url path | advanced cluster management for kubernetes | 6.8 (v3.1) | Medium |
| CVE-2016-6435 | Cisco Firepower Threat Management Console 6.0.1 - Local File Inclusion | secure firewall management center | 6.5 (v3.0) | Medium |
| CVE-2017-14537 | Trixbox 2.8.0 - Path Traversal | trixbox | 6.5 (v3.1) | Medium |
| CVE-2017-9416 | Odoo 8.0/9.0/10.0 - Local File Inclusion | odoo | 6.5 (v3.0) | Medium |
| CVE-2018-3714 | node-srv - Local File Inclusion | node-srv | 6.5 (v3.1) | Medium |
| CVE-2019-11013 | Nimble Streamer <=3.5.4-9 - Local File Inclusion | nimble streamer | 6.5 (v3.0) | Medium |
| CVE-2019-14312 | Aptana Jaxer 1.0.3.4547 - Local File inclusion | jaxer | 6.5 (v3.0) | Medium |
| CVE-2019-3799 | Spring Cloud Config Server - Local File Inclusion | spring cloud config | 6.5 (v3.1) | Medium |
| CVE-2021-24947 | WordPress Responsive Vector Maps < 6.4.2 - Arbitrary File Read | responsive vector maps | 6.5 (v3.1) | Medium |
| CVE-2021-28149 | Hongdian H8922 3.0.5 Devices - Local File Inclusion | h8922 firmware | 6.5 (v3.1) | Medium |
| CVE-2021-29006 | rConfig 3.9.6 - Local File Inclusion | rconfig | 6.5 (v3.1) | Medium |
| CVE-2021-40651 | OS4Ed OpenSIS Community 8.0 - Local File Inclusion | opensis | 6.5 (v3.1) | Medium |
| CVE-2022-37299 | Shirne CMS 1.2.0 - Local File Inclusion | shirne cms | 6.5 (v3.1) | Medium |
| CVE-2024-27564 | ChatGPT个人专用版 - Server Side Request Forgery | chatgpt web | 6.5 (v3.1) | Medium |
| CVE-2024-36527 | Puppeteer Renderer - Directory Traversal | - | 6.5 (v3.1) | Medium |
| CVE-2024-55457 | MasterSAM Star Gate v11 - Local File Inclusion | - | 6.5 (v3.1) | Medium |
| CVE-2024-9765 | EKC Tournament Manager WordPress plugin - Path Traversal | ekc tournament manager | 6.5 (v3.1) | Medium |
| CVE-2025-45870 | LogicalDOC Enterprise up to and for v9.1.1 Path Traversal Vulnerability | - | 6.5 (v3.1) | Medium |
| CVE-2026-11442 | Allegra exportReport Directory Traversal Information Disclosure Vulnerability | Allegra | 6.5 (v3.0) | Medium |
| CVE-2026-14470 | Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base compone | langflow | 6.5 (v3.1) | Medium |
| CVE-2026-15974 | sglang Server-Side Request Forgery Vulnerability | sglang | 6.5 (v3.1) | Medium |
| CVE-2026-34787 | Emlog: Local File Inclusion in plugin.php via unsanitized plugin parameter | emlog | 6.5 (v3.1) | Medium |
| CVE-2026-35718 | fd8136 firmware Path Traversal Vulnerability | fd8136 firmware | 6.5 (v3.1) | Medium |
| CVE-2026-52607 | reportico-web <= 8.1.0 Path Traversal Vulnerability | reportico-web <= 8.1.0 | 6.5 (v3.1) | Medium |
| CVE-2026-73255 | Mongoose: Path traversal in SSI #include directives enables arbitrary file read | mongoose | 6.5 (v3.1) | Medium |
| CVE-2026-73573 | zimbra collaboration suite Path Traversal Vulnerability | zimbra collaboration suite | 6.5 (v3.1) | Medium |
| CVE-2026-73574 | zimbra collaboration suite Incorrect Resource Transfer Between Spheres Vulnerability | zimbra collaboration suite | 6.5 (v3.1) | Medium |
| CVE-2026-7646 | Langflow is affected by security vulnerabilities in Model Context Protocol features | langflow | 6.5 (v3.1) | Medium |
| CVE-2026-39365 | Vite has a Path Traversal in Optimized Deps .map Handling | vite | 6.3 (v4.0) | Medium |
| CVE-2026-42335 | MaxKB: SSRF Bypass in MaxKB OSS URL Fetch due to URL Parsing Discrepancy | MaxKB | 6.3 (v4.0) | Medium |
| CVE-2026-42344 | FastGPT: DNS rebinding TOCTOU bypass in isInternalAddress allows SSRF on all protected endpoints | FastGPT | 6.3 (v3.1) | Medium |
| CVE-2026-45626 | Arcane: OS Command Injection in Volume Browser ListDirectory via path query parameter | arcane | 6.3 (v3.1) | Medium |
| CVE-2026-54020 | Open WebUI: DNS Rebinding SSRF Bypass | open-webui | 6.3 (v3.1) | Medium |
| CVE-2026-63107 | LimeSurvey SSRF via REST API Survey Template Host Header | LimeSurvey | 6.3 (v4.0) | Medium |
| CVE-2026-65012 | InvokeAI < 6.13.7 Unauthenticated Directory Enumeration via scan_folder | InvokeAI | 6.3 (v4.0) | Medium |
| CVE-2026-67620 | Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-List | flowise | 6.3 (v4.0) | Medium |
| CVE-2026-72814 | actix-web before 0.6.10 Information Disclosure via Files | actix-web | 6.3 (v4.0) | Medium |
| CVE-2026-73530 | Flyto2 Core < 2.28.0 SSRF Guard Bypass via is_private_ip() | flyto-core | 6.3 (v4.0) | Medium |
| CVE-2026-78886 | liketrek TREK Public Journey Photo Proxy journey-public.controller.ts path traversal | TREK | 6.3 (v4.0) | Medium |
| CVE-2026-29066 | TinaCMS - Path Traversal | tinacms | 6.2 (v3.1) | Medium |
| CVE-2026-41363 | OpenClaw 2026.2.6 < 2026.3.28 - Arbitrary File Read via Feishu upload_image Parameter | openclaw | 6.0 (v4.0) | Medium |
| CVE-2026-65698 | Void 1.3.4 Path Traversal via AI Agent File-Reading Tools | void | 6.0 (v4.0) | Medium |
| CVE-2026-66004 | BlenderMCP Path Traversal via download_polyhaven_asset API | blender-mcp | 6.0 (v4.0) | Medium |
| CVE-2025-41242 | Spring Framework - Path Traversal | Spring Framework | 5.9 (v3.1) | Medium |
| CVE-2026-49244 | SFTPGo: Path confinement bypass in public browsable share partial ZIP download | sftpgo | 5.9 (v3.1) | Medium |
| CVE-2010-0467 | Joomla! Component CCNewsLetter - Local File Inclusion | com ccnewsletter | 5.8 (v3.1) | Medium |
| CVE-2026-10526 | EmbedPress < 4.6.1 - Unauthenticated Blind SSRF | EmbedPress | 5.8 (v3.1) | Medium |
| CVE-2026-45709 | Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filte | mailpit | 5.8 (v3.1) | Medium |
| CVE-2026-48053 | Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewset | kolibri | 5.8 (v3.1) | Medium |
| CVE-2026-73243 | kkFileView: Unauthenticated SSRF via /addTask with fullfilename type-confusion bypass | kkFileView | 5.8 (v3.1) | Medium |
| CVE-2025-1035 | KLog Server - Path Traversal | KLog Server | 5.7 (v3.1) | Medium |
| CVE-2026-40605 | Tautulli Vulnerable to Authenticated Path Traversal in Cache Deletion API | Tautulli | 5.7 (v4.0) | Medium |
| CVE-2018-13980 | Zeta Producer Desktop CMS <14.2.1 - Local File Inclusion | zeta producer | 5.5 (v3.1) | Medium |
| CVE-2018-15536 | Responsive FileManager < 9.13.4 - Directory Traversal | responsive filemanager | 5.5 (v3.0) | Medium |
| CVE-2025-13786 | taosir WTCMS index.php fetch code injection | wtcms | 5.5 (v4.0) | Medium |
| CVE-2025-13792 | Qualitor getResumo.php eval code injection | the file /html/st/stdeslocamento/request/getResumo.php | 5.5 (v4.0) | Medium |
| CVE-2025-13810 | jsnjfz WebStack-Guns KaptchaController.java renderPicture path traversal | webstack-guns | 5.5 (v4.0) | Medium |
| CVE-2026-10694 | SourceCodester Online Food Ordering System index.php include file inclusion | Online Food Ordering System | 5.5 (v4.0) | Medium |
| CVE-2026-16252 | Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System Staffshinel Ds.jsp sql injection | Multimedia Integrated Business Display System | 5.5 (v4.0) | Medium |
| CVE-2026-18646 | danpros HTMLy Author Name htmly.php path traversal | HTMLy | 5.5 (v4.0) | Medium |
| CVE-2026-18973 | heshengtao super-agent-party extension_proxy Route server.py sanitize_proxy_url server-side request forgery | super-agent-party | 5.5 (v4.0) | Medium |
| CVE-2026-19379 | EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injection | ipTIME AX8004M | 5.5 (v4.0) | Medium |
| CVE-2026-19753 | Model Context Protocol mcp-rdf-explorer MCP Server server.py explore_url server-side request forgery | mcp-rdf-explorer | 5.5 (v4.0) | Medium |
| CVE-2026-19827 | alldatacenter alldata logDetailCat Endpoint JobLogController.java FileInputStream path traversal | alldata | 5.5 (v4.0) | Medium |
| CVE-2026-54611 | InstantCMS has Remote Code Execution in package installer | icms2 | 5.5 (v3.1) | Medium |
| CVE-2026-68922 | MobSF: Arbitrary File Read via Path Traversal in ZIP Uploads | Mobile-Security-Framework-MobSF | 5.5 (v3.1) | Medium |
| CVE-2026-7178 | ChatGPTNextWeb NextChat Artifacts Endpoint route.ts storeUrl server-side request forgery | nextchat | 5.5 (v4.0) | Medium |
| CVE-2026-7221 | TencentCloudBase CloudBase-MCP open-url API Endpoint interactive-server.ts openUrl server-side request forgery | CloudBase-MCP | 5.5 (v4.0) | Medium |
| CVE-2026-76795 | AeternaLabsHQ PullMD REST API Endpoint api server-side request forgery | PullMD | 5.5 (v4.0) | Medium |
| CVE-2026-82598 | SeaCMS Template search.php parseIf code injection | SeaCMS | 5.5 (v4.0) | Medium |
| CVE-2026-82801 | NASA earthdata-search scale Endpoint handler.js scaleImage server-side request forgery | earthdata-search | 5.5 (v4.0) | Medium |
| CVE-2026-84441 | Piwigo Image Derivative i.php path traversal | Piwigo | 5.5 (v4.0) | Medium |
| CVE-2026-85380 | light0011 cms UEditor controller.php catchimage server-side request forgery | cms | 5.5 (v4.0) | Medium |
| CVE-2026-9474 | yashpokharna2555 StudentManagementSystem studentdel.php confirm_logged_in sql injection | StudentManagementSystem | 5.5 (v4.0) | Medium |
| CVE-2026-17621 | Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base compone | langflow | 5.4 (v3.1) | Medium |
| CVE-2026-48483 | TypeBot's WhatsApp status forwarding uses unvalidated user-controlled URLs, allowing SSRF from the Typebot server | typebot.io | 5.4 (v3.1) | Medium |
| CVE-2026-7798 | FluentCRM <= 2.9.87 - Unauthenticated Blind Server-Side Request Forgery via 'SubscribeURL' Parameter | FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution | 5.4 (v3.1) | Medium |
| CVE-2014-8676 | SO Planning 1.32 - Multiple Vulnerabilities | soplanning | 5.3 (v3.0) | Medium |
| CVE-2014-9609 | Netsweeper 4.0.8 - Directory Traversal | netsweeper | 5.3 (v3.1) | Medium |
| CVE-2015-5471 | Swim Team <= v1.44.10777 - Local File Inclusion | swim team | 5.3 (v3.0) | Medium |
| CVE-2020-11798 | Mitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory Traversal | micollab audio, web & video conferencing | 5.3 (v3.1) | Medium |
| CVE-2020-13886 | Intelbras TIP 200/200 LITE/300 - Local File Inclusion | tip200 firmware | 5.3 (v3.1) | Medium |
| CVE-2021-23241 | MERCUSYS Mercury X18G 1.0.5 Router - Local File Inclusion | mercury x18g firmware | 5.3 (v3.1) | Medium |
| CVE-2021-28377 | Joomla! ChronoForums 2.0.11 - Local File Inclusion | chronoforums | 5.3 (v3.1) | Medium |
| CVE-2023-41599 | JFinalCMS v5.0.0 - Directory Traversal | jfinalcms | 5.3 (v3.1) | Medium |
| CVE-2023-7299 | DataGear resolveSql sql injection | datagear | 5.3 (v4.0) | Medium |
| CVE-2025-31486 | Vite server.fs.deny Bypass - Local File Inclusion | vite | 5.3 (v3.1) | Medium |
| CVE-2025-4078 | Wangshen SecGate 3600 Path Traversal Vulnerability | SecGate 3600 | 5.3 (v4.0) | Medium |
| CVE-2026-15932 | Support Genix Lite < 1.4.48 - Unauthenticated Arbitrary File Read via Path Traversal | Support Genix | 5.3 (v3.1) | Medium |
| CVE-2026-16536 | Simple Google Calendar Outlook Events Widget < 3.1.0 - Unauthenticated SSRF via calendar_id | Simple Google Calendar Outlook Events Widget | 5.3 (v3.1) | Medium |
| CVE-2026-19785 | francoisjacquet RosarioSIS Student Medical Medical.inc.php sql injection | RosarioSIS | 5.3 (v4.0) | Medium |
| CVE-2026-34523 | SillyTavern: Path traversal allows file existence oracle | sillytavern | 5.3 (v3.1) | Medium |
| CVE-2026-34967 | Adminer sql-log Plugin 5.3.0 through 5.4.2 Arbitrary File Write | adminer | 5.3 (v4.0) | Medium |
| CVE-2026-36726 | bookcars v8.3 Path Traversal Vulnerability | bookcars v8.3 | 5.3 (v3.1) | Medium |
| CVE-2026-44583 | Paymenter: Blind Unauthenticated SSRF on the Paypal gateway module | Paymenter | 5.3 (v3.1) | Medium |
| CVE-2026-49138 | Nanobot < 0.2.1 SSRF via web_fetch Tool Redirect Following | nanobot | 5.3 (v4.0) | Medium |
| CVE-2026-54508 | TREK: Blind SSRF via unvalidated redirect-following in Google/Naver list import and Maps URL resolution | TREK | 5.3 (v4.0) | Medium |
| CVE-2026-59231 | Server-Side Request Forgery in Pentestify PDF export via unvalidated image URLs | Pentestify | 5.3 (v4.0) | Medium |
| CVE-2026-63730 | HyperDX < 2.31.0 SSRF via Webhook Test Endpoint | hyperdx | 5.3 (v4.0) | Medium |
| CVE-2026-64626 | AVideo Encoder downloadURL SSRF via unpinned retry fallback | AVideo | 5.3 (v4.0) | Medium |
| CVE-2026-74858 | jae-jae fetcher-mcp URL Validation security-credentials fetch_urls server-side request forgery | fetcher-mcp | 5.3 (v4.0) | Medium |
| CVE-2026-89247 | WWBN AVideo XML Injection via plugin/AD_Server/VMAP.php | AVideo | 5.3 (v4.0) | Medium |
| CVE-2026-19761 | DTStack Taier Upload Controller UploadController.java MultipartFile.getOriginalFilename path traversal | Taier | 5.1 (v4.0) | Medium |
| CVE-2026-19763 | DTStack Taier Cluster Creation ClusterController.java FileUtils.deleteDirectory path traversal | Taier | 5.1 (v4.0) | Medium |
| CVE-2026-42336 | MaxKB: SSRF Bypass via DNS Rebinding in MaxKB OSS URL Fetch | MaxKB | 5.1 (v4.0) | Medium |
| CVE-2026-63302 | Local File Inclusion in Quick.CMS | Quick.CMS | 5.1 (v4.0) | Medium |
| CVE-2006-3392 | Webmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosure | webmin | 5.0 (v2.0) | Medium |
| CVE-2007-4504 | Joomla! RSfiles <=1.0.2 - Local File Inclusion | rsfiles | 5.0 (v2.0) | Medium |
| CVE-2008-4764 | Joomla! <=2.0.0 RC2 - Local File Inclusion | com extplorer | 5.0 (v2.0) | Medium |
| CVE-2008-6080 | Joomla! ionFiles 4.4.2 - Local File Inclusion | com ionfiles | 5.0 (v2.0) | Medium |
| CVE-2008-6222 | Joomla! ProDesk 1.0/1.2 - Local File Inclusion | pro desk support center | 5.0 (v2.0) | Medium |
| CVE-2008-6668 | nweb2fax <=0.2.7 - Local File Inclusion | nweb2fax | 5.0 (v2.0) | Medium |
| CVE-2009-1496 | Joomla! Cmimarketplace 0.1 - Local File Inclusion | Joomla! | 5.0 (v2.0) | Medium |
| CVE-2009-2100 | Joomla! JoomlaPraise Projectfork 2.0.10 - Local File Inclusion | Joomla! | 5.0 (v2.0) | Medium |
| CVE-2009-5114 | WebGlimpse 2.18.7 - Directory Traversal | webglimpse | 5.0 (v2.0) | Medium |
| CVE-2010-0696 | Joomla! Component Jw_allVideos - Arbitrary File Retrieval | jw allvideos | 5.0 (v2.0) | Medium |
| CVE-2010-0942 | Joomla! Component com_jvideodirect - Directory Traversal | com jvideodirect | 5.0 (v2.0) | Medium |
| CVE-2010-0943 | Joomla! Component com_jashowcase - Directory Traversal | com jashowcase | 5.0 (v2.0) | Medium |
| CVE-2010-0944 | Joomla! Component com_jcollection - Directory Traversal | com jcollection | 5.0 (v2.0) | Medium |
| CVE-2010-1081 | Joomla! Component com_communitypolls 1.5.2 - Local File Inclusion | com communitypolls | 5.0 (v2.0) | Medium |
| CVE-2010-1302 | Joomla! Component DW Graph - Local File Inclusion | com dwgraphs | 5.0 (v2.0) | Medium |
| CVE-2010-1304 | Joomla! Component User Status - Local File Inclusion | com userstatus | 5.0 (v2.0) | Medium |
| CVE-2010-1305 | Joomla! Component JInventory 1.23.02 - Local File Inclusion | com jinventory | 5.0 (v2.0) | Medium |
| CVE-2010-1307 | Joomla! Component Magic Updater - Local File Inclusion | com joomlaupdater | 5.0 (v2.0) | Medium |
| CVE-2010-1308 | Joomla! Component SVMap 1.1.1 - Local File Inclusion | com svmap | 5.0 (v2.0) | Medium |
| CVE-2010-1312 | Joomla! Component News Portal 1.5.x - Local File Inclusion | com news portal | 5.0 (v2.0) | Medium |
| CVE-2010-1314 | Joomla! Component Highslide 1.5 - Local File Inclusion | com hsconfig | 5.0 (v2.0) | Medium |
| CVE-2010-1315 | Joomla! Component webERPcustomer - Local File Inclusion | com weberpcustomer | 5.0 (v2.0) | Medium |
| CVE-2010-1340 | Joomla! Component com_jresearch - 'Controller' Local File Inclusion | com jresearch | 5.0 (v2.0) | Medium |
| CVE-2010-1345 | Joomla! Component Cookex Agency CKForms - Local File Inclusion | com ckforms | 5.0 (v2.0) | Medium |
| CVE-2010-1352 | Joomla! Component Juke Box 1.7 - Local File Inclusion | com jukebox | 5.0 (v2.0) | Medium |
| CVE-2010-1353 | Joomla! Component LoginBox - Local File Inclusion | com loginbox | 5.0 (v2.0) | Medium |
| CVE-2010-1354 | Joomla! Component VJDEO 1.0 - Local File Inclusion | com vjdeo | 5.0 (v2.0) | Medium |
| CVE-2010-1461 | Joomla! Component Photo Battle 1.0.1 - Local File Inclusion | com photobattle | 5.0 (v2.0) | Medium |
| CVE-2010-1491 | Joomla! Component MMS Blog 2.3.0 - Local File Inclusion | com mmsblog | 5.0 (v2.0) | Medium |
| CVE-2010-1494 | Joomla! Component AWDwall 1.5.4 - Local File Inclusion | com awdwall | 5.0 (v2.0) | Medium |
| CVE-2010-1532 | Joomla! Component PowerMail Pro 1.5.3 - Local File Inclusion | com powermail | 5.0 (v2.0) | Medium |
| CVE-2010-1534 | Joomla! Component Shoutbox Pro - Local File Inclusion | com shoutbox | 5.0 (v2.0) | Medium |
| CVE-2010-1540 | Joomla! Component com_blog - Directory Traversal | com myblog | 5.0 (v2.0) | Medium |
| CVE-2010-1601 | Joomla! Component JA Comment - Local File Inclusion | com jacomment | 5.0 (v2.0) | Medium |
| CVE-2010-1657 | Joomla! Component SmartSite 1.0.0 - Local File Inclusion | com smartsite | 5.0 (v2.0) | Medium |
| CVE-2010-1658 | Joomla! Component NoticeBoard 1.3 - Local File Inclusion | com noticeboard | 5.0 (v2.0) | Medium |
| CVE-2010-1659 | Joomla! Component Ultimate Portfolio 1.0 - Local File Inclusion | com ultimateportfolio | 5.0 (v2.0) | Medium |
| CVE-2010-1714 | Joomla! Component Arcade Games 1.0 - Local File Inclusion | com arcadegames | 5.0 (v2.0) | Medium |
| CVE-2010-1858 | Joomla! Component SMEStorage - Local File Inclusion | com smestorage | 5.0 (v2.0) | Medium |
| CVE-2010-1982 | Joomla! Component JA Voice 2.0 - Local File Inclusion | com javoice | 5.0 (v2.0) | Medium |
| CVE-2010-2018 | Lokomedia CMS - Local File Inclusion | lokomedia cms | 5.0 (v2.0) | Medium |
| CVE-2010-2307 | Motorola SBV6120E SURFboard Digital Voice Modem SBV6X2X-1.0.0.5-SCM - Directory Traversal | surfboard sbv6120e | 5.0 (v2.0) | Medium |
| CVE-2011-0049 | Majordomo2 - SMTP/HTTP Directory Traversal | majordomo 2 | 5.0 (v2.0) | Medium |
| CVE-2011-1669 | WP Custom Pages 0.5.0.1 - Local File Inclusion (LFI) | wp custom pages | 5.0 (v2.0) | Medium |
| CVE-2011-2780 | Chyrp 2.x - Local File Inclusion | chyrp | 5.0 (v2.0) | Medium |
| CVE-2011-4804 | Joomla! Component com_kp - 'Controller' Local File Inclusion | com obsuggest | 5.0 (v2.0) | Medium |
| CVE-2012-0896 | Count Per Day <= 3.1 - download.php f Parameter Traversal Arbitrary File Access | count per day | 5.0 (v2.0) | Medium |
| CVE-2012-0981 | phpShowtime 2.0 - Directory Traversal | phpshowtime | 5.0 (v2.0) | Medium |
| CVE-2012-0996 | 11in1 CMS 1.2.1 - Local File Inclusion (LFI) | 11in1 | 5.0 (v2.0) | Medium |
| CVE-2013-5979 | Xibo 1.2.2/1.4.1 - Directory Traversal | xibo | 5.0 (v2.0) | Medium |
| CVE-2013-7091 | Zimbra Collaboration Server 7.2.2/8.0.2 Local File Inclusion | zimbra collaboration suite | 5.0 (v2.0) | Medium |
| CVE-2014-4577 | WP AmASIN – The Amazon Affiliate Shop - Local File Inclusion | wp amasin - the amazon affiliate shop | 5.0 (v2.0) | Medium |
| CVE-2014-4940 | WordPress Plugin Tera Charts - Local File Inclusion | tera-charts | 5.0 (v2.0) | Medium |
| CVE-2014-4941 | Cross RSS 1.7 - Local File Inclusion | wp-cross-rss | 5.0 (v2.0) | Medium |
| CVE-2014-5111 | Fonality trixbox - Local File Inclusion | trixbox | 5.0 (v2.0) | Medium |
| CVE-2014-5181 | Last.fm Rotation 1.0 - Path Traversal | lastfm-rotation plugin | 5.0 (v2.0) | Medium |
| CVE-2014-5187 | Tom M8te (tom-m8te) Plugin 1.5.3 - Directory Traversal | tom-m8te plugin | 5.0 (v2.0) | Medium |
| CVE-2014-6308 | Osclass Security Advisory 3.4.1 - Local File Inclusion | osclass | 5.0 (v2.0) | Medium |
| CVE-2015-2067 | Magento Server MAGMI - Directory Traversal | magmi | 5.0 (v2.0) | Medium |
| CVE-2015-2166 | Ericsson Drutt MSDP - Local File Inclusion | drutt mobile service delivery platform | 5.0 (v2.0) | Medium |
| CVE-2015-4414 | WordPress SE HTML5 Album Audio Player 1.1.0 - Directory Traversal | se html5 album audio player | 5.0 (v2.0) | Medium |
| CVE-2015-4666 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 5.0 (v2.0) | Medium |
| CVE-2015-5531 | ElasticSearch <1.6.1 - Local File Inclusion | elasticsearch | 5.0 (v2.0) | Medium |
| CVE-2015-5688 | Geddy <13.0.8 - Local File Inclusion | geddy | 5.0 (v2.0) | Medium |
| CVE-2017-7461 | Intellinet NFC-30IR Camera - Multiple Vulnerabilities | nfc-30ir firmware | 4.9 (v3.0) | Medium |
| CVE-2023-34259 | Kyocera TASKalfa printer - Path Traversal | d-copia253mf plus firmware | 4.9 (v3.1) | Medium |
| CVE-2026-53594 | FreeScout has Arbitrary File Read in App Logs Viewer via Forged Encrypted Path | freescout | 4.9 (v3.1) | Medium |
| CVE-2008-5587 | phpPgAdmin <=4.2.1 - Local File Inclusion | phppgadmin | 4.3 (v2.0) | Medium |
| CVE-2010-0982 | Joomla! Component com_cartweberp - Local File Inclusion | com cartweberp | 4.3 (v2.0) | Medium |
| CVE-2010-1217 | Joomla! Component & Plugin JE Tooltip 1.0 - Local File Inclusion | je form creator | 4.3 (v2.0) | Medium |
| CVE-2010-1313 | Joomla! Component Saber Cart 1.0.0.12 - Local File Inclusion | com sebercart | 4.3 (v2.0) | Medium |
| CVE-2012-4253 | MySQLDumper 1.24.4 - Directory Traversal | mysqldumper | 4.3 (v2.0) | Medium |
| CVE-2015-3337 | Elasticsearch - Local File Inclusion | elasticsearch | 4.3 (v2.0) | Medium |
| CVE-2018-18777 | Microstrategy Web 7 - Local File Inclusion | microstrategy web | 4.3 (v3.0) | Medium |
| CVE-2024-7631 | Openshift-console: openshift console: path traversal | Red Hat OpenShift Container Platform 3.11 | 4.3 (v3.1) | Medium |
| CVE-2026-26477 | dokuwiki Denial of Service Vulnerability | dokuwiki | 4.3 (v3.1) | Medium |
| CVE-2026-55495 | Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account | cloudreve | 4.3 (v3.1) | Medium |
| CVE-2026-73657 | Trigger.dev: Cross-tenant payload poisoning via packet write + replay | trigger.dev | 4.2 (v3.1) | Medium |
| CVE-2011-4640 | WebTitan < 3.60 - Local File Inclusion | webtitan | 4.0 (v2.0) | Medium |
| CVE-2013-5528 | Cisco Unified Communications Manager 7/8/9 - Directory Traversal | unified communications manager | 4.0 (v2.0) | Medium |
| CVE-2014-5258 | webEdition 6.3.8.0 - Directory Traversal | webedition cms | 4.0 (v2.0) | Medium |
| CVE-2019-19411 | Huawei Firewall - Local File Inclusion | usg9500 | 3.7 (v3.1) | Low |
| CVE-2012-0991 | OpenEMR 4.1 - Local File Inclusion | openemr | 3.5 (v2.0) | Low |
| CVE-2025-55523 | Agent-Zero 0.8.0 - 0.9.4 - Arbitrary File Download | agent-zero | 3.5 (v3.1) | Low |
| CVE-2026-55825 | Contao: Possible path traversal in job download URIs | contao | 3.1 (v3.1) | Low |
| CVE-2026-49262 | Aimeos Pagible CMS vulnerable to Server Side Request Forgery (SSRF) via DNS rebinding in admin proxy | pagible | 3.0 (v3.1) | Low |
| CVE-2026-68927 | MobSF: SSRF port restriction bypass in assetlinks_check | Mobile-Security-Framework-MobSF | 3.0 (v3.1) | Low |
| CVE-2023-2252 | Directorist < 7.5.4 - Local File Inclusion | directorist | 2.7 (v3.1) | Low |
| CVE-2026-16434 | Adminer before 5.5.1 X-Forwarded-Prefix Backslash Bypass | adminer | 2.3 (v4.0) | Low |
| CVE-2026-73087 | Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher | dozzle | 2.3 (v4.0) | Low |
| CVE-2026-10239 | JeecgBoot edit WordUtil.addImage server-side request forgery | JeecgBoot | 2.1 (v4.0) | Low |
| CVE-2026-10558 | SourceCodester Pizzafy Ecommerce System index.php file inclusion | Pizzafy Ecommerce System | 2.1 (v4.0) | Low |
| CVE-2026-10559 | SourceCodester Pizzafy Ecommerce System index.php file inclusion | Pizzafy Ecommerce System | 2.1 (v4.0) | Low |
| CVE-2026-11408 | vertex-app vertex Log Viewer Endpoint LogMod.js os command injection | vertex | 2.1 (v4.0) | Low |
| CVE-2026-12210 | universal-tool-calling-protocol python-utcp utcp-gql/utcp-websocket server-side request forgery | python-utcp | 2.1 (v4.0) | Low |
| CVE-2026-16194 | zhayujie CowAgent web_fetch.py WebFetch.execute server-side request forgery | CowAgent | 2.1 (v4.0) | Low |
| CVE-2026-16219 | Croogo CMS Admin File Manager FileManager.php isEditable path traversal | CMS | 2.1 (v4.0) | Low |
| CVE-2026-17458 | mf-yang openclaw-cn Browser Control HTTP API agent.act.ts clickViaPlaywright server-side request forgery | openclaw-cn | 2.1 (v4.0) | Low |
| CVE-2026-19828 | 648540858 wvp-GB28181-pro Snapshot Endpoint PlayController.java path traversal | wvp-GB28181-pro | 2.1 (v4.0) | Low |
| CVE-2026-19829 | 648540858 wvp-GB28181-pro Log File Download Endpoint LogController.java path traversal | wvp-GB28181-pro | 2.1 (v4.0) | Low |
| CVE-2026-19927 | OpenBoxes Product Upload Endpoint ProductController.groovy upload server-side request forgery | OpenBoxes | 2.1 (v4.0) | Low |
| CVE-2026-5803 | bigsk1 openai-realtime-ui API Proxy Endpoint server.js server-side request forgery | openai-realtime-ui | 2.1 (v4.0) | Low |
| CVE-2026-74842 | Kira-Pgr PromptShopMCP Image-Toolkit-MCP-Server server.py download_image server-side request forgery | PromptShopMCP | 2.1 (v4.0) | Low |
| CVE-2026-76576 | yangzongzhuan RuoYi-Vue Common Download Endpoint CommonController.java resourceDownload path traversal | RuoYi-Vue | 2.1 (v4.0) | Low |
| CVE-2026-8191 | Wavlink NU516U1 adm.cgi wifi_region os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-82599 | SeaCMS Avatar Upload member.php unlink path traversal | SeaCMS | 2.1 (v4.0) | Low |
| CVE-2026-82603 | SeaCMS Comment Cache member.php del_pl path traversal | SeaCMS | 2.1 (v4.0) | Low |
| CVE-2026-83744 | invoiceninja Invoice Ninja invoices Endpoint Purify.php isHostSafe server-side request forgery | Invoice Ninja | 2.1 (v4.0) | Low |
| CVE-2026-12211 | Intelbras iNVU 7016 FT Web syslog path traversal | iNVU 7016 FT | 2.0 (v4.0) | Low |
| CVE-2026-16088 | halo-dev halo Files Backup Endpoint MigrationEndpoint.java download path traversal | halo | 2.0 (v4.0) | Low |
| CVE-2026-18856 | Poesis Rhymix CMS Data Import importer.admin.controller.php procImporterAdminCheckXmlFile server-side request forgery | Rhymix CMS | 2.0 (v4.0) | Low |
| CVE-2026-78435 | Faveo Helpdesk Logo SettingsController.php unlink path traversal | Helpdesk | 2.0 (v4.0) | Low |
| CVE-2026-81835 | RooCodeInc Roo-Code MCP Integration Trust Model malicious_mcp_server.py fetch_instructions code injection | Roo-Code | 2.0 (v4.0) | Low |
| CVE-2026-82678 | diem-project diem Administrative Console actions.class.php executeCommand os command injection | diem | 2.0 (v4.0) | Low |
| CVE-2026-86240 | liufee FeehiCMS UEditor Uploader.php catchImage server-side request forgery | FeehiCMS | 2.0 (v4.0) | Low |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.