On this page

Atomicorp WAF Rule 347009

Rule Summary

Description

This rule detects behavior identified by its current alert as “Protected File access denied” in the request URI. It evaluates during the request headers phase and denies matching traffic with HTTP status 403.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

CVEVulnerabilityProductCVSSSeverity
CVE-2009-0545ZeroShell <= 1.0beta11 Remote Code Executionzeroshell10.0 (v2.0)High
CVE-2010-5286Joomla! Component Jstore - 'Controller' Local File Inclusioncom jstore10.0 (v2.0)High
CVE-2019-11510Pulse Connect Secure SSL VPN Arbitrary File Readconnect secure10.0 (v3.1)Critical
CVE-2025-34037Linksys Routers E/WAG/WAP/WES/WET/WRT-SeriesE420010.0 (v4.0)Critical
CVE-2026-33712TypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint bypasses SSRF controlstypebot.io10.0 (v3.1)Critical
CVE-2026-49869Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in AuthenticationFilterkestra10.0 (v3.1)Critical
CVE-2026-54745Kubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENABpipelines10.0 (v3.1)Critical
CVE-2026-31818Budibase: Server-Side Request Forgery via REST Connector with Empty Default Blacklistbudibase9.9 (v3.1)Critical
CVE-2026-42454Termix: OS Command Injection in Docker Container Management EndpointsTermix9.9 (v3.1)Critical
CVE-2026-43986Tautulli vulnerable to unauthenticated SSRF in /image/<hash> via attacker-seeded image hash replayTautulli9.9 (v3.1)Critical
CVE-2026-45629Dokploy: Authenticated Remote Code Execution via Command Injection in /listen-deployment WebSocket Endpointdokploy9.9 (v3.1)Critical
CVE-2026-55565Yamcs: Authenticated remote code execution via unescaped StreamSQL LIKE pattern compiled by Janino (LikeExpression)yamcs9.9 (v3.1)Critical
CVE-2026-72738Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search Parameterdokploy9.9 (v3.1)Critical
CVE-2026-72869Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCEdokploy9.9 (v3.1)Critical
CVE-2026-72876Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.*dokploy9.9 (v3.1)Critical
CVE-2026-73294Semaphore U: OS Command Injectionsemaphore9.9 (v3.1)Critical
CVE-2010-2861Adobe ColdFusion - Directory Traversalcoldfusion9.8 (v3.1)Critical
CVE-2017-12611Apache Struts2 S2-053 - Remote Code Executionstruts9.8 (v3.0)Critical
CVE-2017-7462Intellinet NFC-30IR Camera - Multiple Vulnerabilitiesnfc-30ir firmware9.8 (v3.0)Critical
CVE-2018-12031Eaton Intelligent Power Manager 1.6 - Directory Traversalintelligent power manager9.8 (v3.0)Critical
CVE-2018-14064VelotiSmart Wifi - Directory Traversalvelotismart wifi firmware9.8 (v3.0)Critical
CVE-2018-16283WordPress Plugin Wechat Broadcast 1.2.0 - Local File Inclusionwechat brodcast9.8 (v3.0)Critical
CVE-2018-16763FUEL CMS 1.4.1 - Remote Code Executionfuel cms9.8 (v3.1)Critical
CVE-2018-16836Rubedo CMS <=3.4.0 - Directory Traversalrubedo9.8 (v3.1)Critical
CVE-2018-17246Kibana - Local File Inclusionkibana9.8 (v3.0)Critical
CVE-2019-12314Deltek Maconomy 2.2.5 - Local File Inclusionmaconomy9.8 (v3.0)Critical
CVE-2019-12725Zeroshell 3.9.0 - Remote Command Executionzeroshell9.8 (v3.0)Critical
CVE-2019-16662rConfig 3.9.2 - Remote Code Executionrconfig9.8 (v3.1)Critical
CVE-2019-17270Yachtcontrol Webapplication 1.0 - Remote Command Injectionyachtcontrol9.8 (v3.1)Critical
CVE-2019-7256eMerge E3 1.00-06 - Remote Code Executionlinear emerge essential firmware9.8 (v3.1)Critical
CVE-2019-9618WordPress GraceMedia Media Player 1.0 - Local File Inclusiongracemedia media player9.8 (v3.0)Critical
CVE-2020-11455LimeSurvey 4.1.11 - Local File Inclusionlimesurvey9.8 (v3.1)Critical
CVE-2020-15568TerraMaster TOS <.1.29 - Remote Code Executiontos9.8 (v3.1)Critical
CVE-2020-15920Mida eFramework <=2.9.0 - Remote Command Executioneframework9.8 (v3.1)Critical
CVE-2020-17530Apache Struts 2.0.0-2.5.25 - Remote Code Executionstruts9.8 (v3.1)Critical
CVE-2020-29227Car Rental Management System 1.0 - Local File Inclusioncar rental management system9.8 (v3.1)Critical
CVE-2020-29390Zeroshell 3.9.3 - Command Injectionzeroshell9.8 (v3.1)Critical
CVE-2020-5902F5 BIG-IP TMUI - Remote Code Executionbig-ip access policy manager9.8 (v3.1)Critical
CVE-2020-7209LinuxKI Toolset <= 6.01 - Remote Command Executionlinuxki9.8 (v3.1)Critical
CVE-2020-9054Zyxel NAS Firmware 5.21- Remote Code Executionnas326 firmware9.8 (v3.1)Critical
CVE-2021-40960Galera WebTemplate 1.0 Directory Traversalgalera webtemplate9.8 (v3.1)Critical
CVE-2021-41773Apache 2.4.49 - Path Traversal and Remote Code Executionhttp server9.8 (v3.1)Critical
CVE-2021-42013Apache 2.4.49/2.4.50 - Path Traversal and Remote Code Executionhttp server9.8 (v3.1)Critical
CVE-2022-1390WordPress Admin Word Count Column 2.2 - Local File Inclusionadmin word count column9.8 (v3.1)Critical
CVE-2022-1391WordPress Cab fare calculator < 1.0.4 - Local File Inclusioncab fare calculator9.8 (v3.1)Critical
CVE-2022-32409Portal do Software Publico Brasileiro i3geo 7.0.5 - Local File Inclusioni3geo9.8 (v3.1)Critical
CVE-2022-36553Hytec Inter HWL-2511-SS - Remote Command Executionhwl-2511-ss firmware9.8 (v3.1)Critical
CVE-2022-36642Omnia MPX 1.5.0+r1 - Local File Inclusionomnia mpx node firmware9.8 (v3.1)Critical
CVE-2022-4060WordPress User Post Gallery <=2.19 - Remote Code Executionuser post gallery9.8 (v3.1)Critical
CVE-2022-41840Welcart eCommerce <=2.7.7 - Local File Inclusionwelcart e-commerce9.8 (v3.1)Critical
CVE-2022-47615LearnPress Plugin < 4.2.0 - Local File Inclusionlearnpress9.8 (v3.1)Critical
CVE-2023-5991Hotel Booking Lite < 4.8.5 - Arbitrary File Download & Deletionhotel booking lite9.8 (v3.1)Critical
CVE-2023-6623Essential Blocks < 4.4.3 - Local File Inclusionessential blocks9.8 (v3.1)Critical
CVE-2024-12209WP Umbrella Update Backup Restore & Monitoring <= 2.17.0 - Local File Inclusionwp-umbrella9.8 (v3.1)Critical
CVE-2024-5827Vanna - SQL injectionvanna-ai/vanna9.8 (v3.0)Critical
CVE-2025-2294Kubio AI Page Builder <= 2.5.1 - Local File InclusionKubio AI Page Builder9.8 (v3.1)Critical
CVE-2025-24893XWiki Platform - Remote Code Executionxwiki9.8 (v3.1)Critical
CVE-2025-29306FoxCMS v.1.2.5 - Remote Code Executionfoxcms9.8 (v3.1)Critical
CVE-2025-47445WordPress Eventin (Themewinter) ≤ 4.0.26 - Arbitrary File Downloadeventin9.8 (v3.1)Critical
CVE-2026-12940Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpointlangflow9.8 (v3.1)Critical
CVE-2026-30118scalar/astro v0.1.13 was discovered to Server-Side Request Forgery Vulnerability-9.8 (v3.1)Critical
CVE-2026-3296Everest Forms <= 3.4.3 - Unauthenticated PHP Object Injection via Form Entry MetadataEverest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder9.8 (v3.1)Critical
CVE-2026-35471Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshsgoshs9.8 (v3.0)Critical
CVE-2026-35847the CheckUils.php file Arbitrary Code Execution Vulnerabilitythe CheckUils.php file9.8 (v3.1)Critical
CVE-2026-37281the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 Command Injection Vulnerabilitythe /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.09.8 (v3.1)Critical
CVE-2026-38428kestra SQL Injection Vulnerabilitykestra9.8 (v3.1)Critical
CVE-2026-39394CI4MS has an .env CRLF Injection via Unvalidated host Parameter in Install Controllerci4ms9.8 (v3.1)Critical
CVE-2026-46562Yamcs: Remote Code Execution via Mission Database algorithm overrideyamcs9.8 (v3.1)Critical
CVE-2026-53545Termix: Remote Code Execution via Tunnel Disconnect pkill Command InjectionTermix9.8 (v3.1)Critical
CVE-2026-75337Yu AI Code Mother v4.3 is vulnerable to path traversal VulnerabilityYu AI Code Mother v4.3 is vulnerable to path traversal9.8 (v3.1)Critical
CVE-2026-84372Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connectionspredis9.8 (v3.1)Critical
CVE-2019-8982Wavemaker Studio 6.6 - Local File Inclusion/Server-Side Request Forgerywavemarker studio9.6 (v3.0)Critical
CVE-2026-12564Automation-controller: automation-controller: kubernetes service account token exfiltration via hashicorp vault credentiRed Hat Ansible Automation Platform 29.6 (v3.1)Critical
CVE-2026-12605glassfish Server-Side Request Forgery Vulnerabilityglassfish9.6 (v3.1)Critical
CVE-2026-35906An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 OS Command Injection Vulnerability-9.6 (v3.1)Critical
CVE-2026-39932OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injectionopenemr9.4 (v4.0)Critical
CVE-2026-69256Flowise: Remote Code Execution Vulnerability in CSVAgentFlowise9.4 (v4.0)Critical
CVE-2026-72850Budibase before 3.40.0 Arbitrary File Write via Path Traversalserver9.4 (v4.0)Critical
CVE-2026-77086SiYuan before v3.7.4 Path Traversal via packageNamesiyuan9.4 (v4.0)Critical
CVE-2018-25357Dolibarr ERP CRM 7.0.3 Remote Code Execution via install/step1.phpdolibarr erp/crm9.3 (v4.0)Critical
CVE-2019-25727WordPress Plugin ad manager wd 1.0.11 Arbitrary File DownloadAd Manager WD9.3 (v4.0)Critical
CVE-2024-27954WordPress Automatic Plugin <3.92.1 - Arbitrary File Download and SSRFAutomatic9.3 (v3.1)Critical
CVE-2026-23734XWiki Platform: Path traversal via resources parameter in ssx and jsx endpoints when using leading slashxwiki-commons9.3 (v4.0)Critical
CVE-2026-27174MajorDoMo - Unauthenticated RCEmajordomo9.3 (v4.0)Critical
CVE-2026-41939Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFlyCare Everywhere Gateway9.3 (v4.0)Critical
CVE-2026-44343WGDashboard < 4.3.2 - Unauthenticated File Readwgdashboard9.3 (v4.0)Critical
CVE-2026-44402Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgiSNMP Web Pro9.3 (v4.0)Critical
CVE-2026-45668Trilium Notes : Note Import to RCE via #docName Path Traversal (Safe Import Enabled)Trilium9.3 (v4.0)Critical
CVE-2026-47754unauthenticated path traversal in Metacat 2.xmetacat9.3 (v3.1)Critical
CVE-2026-53975OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/execOpenChamber9.3 (v4.0)Critical
CVE-2026-53976OpenChamber <1.13.0 - Unauthenticated Arbitrary File ReadOpenChamber9.3 (v4.0)Critical
CVE-2026-59111Command Injection vulnerability in eObčanka-IdentifikaceeObčanka-Identifikace9.3 (v3.1)Critical
CVE-2026-61498Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via gen_graphs.phpflamingo9.3 (v4.0)Critical
CVE-2026-61511vBulletin 6.x - Remote Code ExecutionvBulletin9.3 (v4.0)Critical
CVE-2026-63766GPT-SoVITS 20250606v2pro OS Command Injection via webui.pyGPT-SoVITS9.3 (v4.0)Critical
CVE-2026-64849MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirectmlflow9.3 (v3.1)Critical
CVE-2026-65700h2oGPT 0.2.1 Path Traversal via OpenAI-compatible Files APIh2ogpt9.3 (v4.0)Critical
CVE-2026-66794Cluster-proxy-addon: cluster-proxy-addon: unauthenticated ssrf to arbitrary managed-cluster services via public routemulticluster engine for Kubernetes 2.19.3 (v3.1)Critical
CVE-2026-69110OpenCode Studio < 2.4.4 Unauthenticated File Read via /api/tmp and /api/musicopencode-studio9.3 (v4.0)Critical
CVE-2026-71921DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection via setget.cgiVigorSwitch G2540xs9.3 (v4.0)Critical
CVE-2026-71946D-Link DWR-M961 Command Injection via /boafrm/formPingDiagnosticRunDWR-M9619.3 (v4.0)Critical
CVE-2026-71947D-Link DWR-M961 Command Injection via /boafrm/formTracerouteDiagnosticRunDWR-M9619.3 (v4.0)Critical
CVE-2026-71948D-Link DWR-M961 Command Injection via /boafrm/formDebugDiagnosticRunDWR-M9619.3 (v4.0)Critical
CVE-2026-71955D-Link DWR-M961 Command Injection via /boafrm/formWscDWR-M9619.3 (v4.0)Critical
CVE-2026-71984MSI Radix AXE6600 v781521 Command Injection via urlfilterRadix AXE66009.3 (v4.0)Critical
CVE-2026-71992MSI Radix AXE6600 v781521 Command Injection via macfilterRadix AXE66009.3 (v4.0)Critical
CVE-2026-72710SPIP < 4.4.18 Remote Code Execution via editer_objet.php Job Queue InjectionSPIP9.3 (v4.0)Critical
CVE-2026-65317Verba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware BypassVerba9.2 (v4.0)Critical
CVE-2026-65760Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0Easy Store extension for Joomla9.2 (v4.0)Critical
CVE-2026-85614OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checkeropenpanel9.2 (v4.0)Critical
CVE-2026-86119Webstudio through 0.296.0 SSRF via /cgi proxy routeswebstudio9.2 (v4.0)Critical
CVE-2018-14916Loytec LGATE-902 <6.4.2 - Local File Inclusionlgate-9029.1 (v3.0)Critical
CVE-2018-16716NCBI ToolBox - Directory Traversalncbi toolbox9.1 (v3.0)Critical
CVE-2018-19365Wowza Streaming Engine Manager 4.7.4.01 - Directory Traversalstreaming engine9.1 (v3.1)Critical
CVE-2021-28918Netmask NPM Package - Server-Side Request Forgerynetmask9.1 (v3.1)Critical
CVE-2022-26960elFinder <=2.1.60 - Local File Inclusionelfinder9.1 (v3.1)Critical
CVE-2024-40422Devika v1 - Path Traversaldevika9.1 (v3.1)Critical
CVE-2025-55526n8n workflow collection Path Traversal Vulnerabilityn8n workflow collection9.1 (v3.1)Critical
CVE-2026-13147WordPress Kirki < 6.0.12 - Server-Side Request Forgerykirki9.1 (v3.1)Critical
CVE-2026-44313LinkWarden: Server-Side Request Forgery (SSRF) in Link Creation via fetchTitleAndHeaders Functionlinkwarden9.1 (v3.1)Critical
CVE-2026-46621Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injectionyamcs9.1 (v3.1)Critical
CVE-2026-52610reportico-web <= 8.1.0 Path Traversal Vulnerabilityreportico-web <= 8.1.09.1 (v3.1)Critical
CVE-2026-55511Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs executeSqlyamcs9.1 (v3.1)Critical
CVE-2026-58400GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configuration in formattercore-geonetwork9.1 (v3.1)Critical
CVE-2026-75332Zyplayer-Doc <=1.0.0 Server-Side Request Forgery Vulnerability-9.1 (v3.1)Critical
CVE-2008-4668Joomla! Image Browser 0.1.5 rc2 - Local File Inclusioncom imagebrowser9.0 (v2.0)High
CVE-2026-34612Kestra: Remote Code Execution via SQL Injectionkestra9.0 (v3.1)Critical
CVE-2026-62674Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCEomnigent9.0 (v3.1)Critical
CVE-2026-69251Flowise RCE via TypeORM DataSourceFlowise9.0 (v4.0)Critical
CVE-2026-43945FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration InjectionFUXA8.9 (v4.0)High
CVE-2026-73570zimbra collaboration suite Arbitrary Code Execution Vulnerabilityzimbra collaboration suite8.9 (v3.1)High
CVE-2016-6277NETGEAR Routers - Remote Code Executiond6220 firmware8.8 (v3.1)High
CVE-2017-14535Trixbox - 2.8.0.4 OS Command Injectiontrixbox8.8 (v3.1)High
CVE-2017-6884Zyxel_ EMG2926 < V1.00(AAQT.4)b8 - OS Command Injectionemg2926 firmware8.8 (v3.1)High
CVE-2018-10093AudioCodes 420HD - Remote Code Execution420hd ip phone firmware8.8 (v3.0)High
CVE-2018-10823D-Link Routers - Remote Command Injectiondwr-116 firmware8.8 (v3.1)High
CVE-2018-12613PhpMyAdmin <4.8.2 - Local File Inclusionphpmyadmin8.8 (v3.1)High
CVE-2019-14530OpenEMR <5.0.2 - Local File Inclusionopenemr8.8 (v3.1)High
CVE-2020-13851Artica Pandora FMS 7.44 - Remote Code Executionpandora fms8.8 (v3.1)High
CVE-2020-15874Command Injection-8.8 (v3.1)High
CVE-2020-24579D-Link DSL 2888a - Authentication Bypass/Remote Command Executiondsl2888a firmware8.8 (v3.1)High
CVE-2020-8163Ruby on Rails <5.0.1 - Remote Code Executionrails8.8 (v3.1)High
CVE-2020-8641Lotus Core CMS 1.0.1 - Local File Inclusionlotus core cms8.8 (v3.1)High
CVE-2023-39108rConfig 3.9.4 - Server-Side Request Forgeryrconfig8.8 (v3.1)High
CVE-2023-39109rConfig 3.9.4 - Server-Side Request Forgeryrconfig8.8 (v3.1)High
CVE-2023-39110rConfig 3.9.4 - Server-Side Request Forgeryrconfig8.8 (v3.1)High
CVE-2024-7340W&B Weave Server - Remote Arbitrary File Leak-8.8 (v3.1)High
CVE-2026-17623Langflow is affected OS Command Injection in Model Context Protocol featureslangflow8.8 (v3.1)High
CVE-2026-17625Langflow is affected by OS Command Injection in Model Context Protocol featureslangflow8.8 (v3.1)High
CVE-2026-34197Apache ActiveMQ - Remote Code Executionactivemq8.8 (v3.1)High
CVE-2026-35196Chamilo LMS has OS Command Injection via export_all_certificates actionchamilo lms8.8 (v3.1)High
CVE-2026-42605AzuraCast: Path Traversal in currentDirectory Parameter Enables Remote Code Execution via Media Uploadazuracast8.8 (v3.1)High
CVE-2026-501864gaBoards: Path Traversal leading to Arbitrary File Read and Deletion in Board Export4gaBoards8.8 (v3.1)High
CVE-2026-72875Dokploy: Remote Code Execution (RCE) via Command Injection in settings.readTraefikFiledokploy8.8 (v3.1)High
CVE-2026-76842Mercado Pago Node.js SDK through 3.4.0 Path Injection via Unencoded Identifiers in Payment Clientsmercadopago8.8 (v4.0)High
CVE-2026-87927MaxSite CMS through 109.6 Local File Inclusion via ajax dispatcherMaxSite CMS8.8 (v4.0)High
CVE-2017-20248WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File DownloadApptha Slider Gallery8.7 (v4.0)High
CVE-2017-20250WordPress Plugin Mac Photo Gallery 3.0 Arbitrary File DownloadMac Photo Gallery8.7 (v4.0)High
CVE-2018-25374Softneta MedDream PACS Server Premium 6.7.1.1 Directory TraversalMedDream PACS Server Premium8.7 (v4.0)High
CVE-2021-4463Longjing Technology BEMS API 1.21 - Unauthenticated Arbitrary File DownloadBEMS API8.7 (v4.0)High
CVE-2021-47943TextPattern CMS 4.8.7 Remote Code Execution via File UploadTextPattern CMS8.7 (v4.0)High
CVE-2022-50944Aero CMS 0.0.1 PHP Code Injection via posts.phpAero CMS8.7 (v4.0)High
CVE-2024-11303Korenix JetPort 5601v3 - Path TraversalJetPort 56018.7 (v4.0)High
CVE-2024-26291Avid NEXIS Agent - Arbitrary File Readnexis8.7 (v4.0)High
CVE-2025-34031Moodle Jmol Filter 6.1 - Local File Inclusionjmol8.7 (v4.0)High
CVE-2025-34115OP5 Monitor <= 7.1.9 Authenticated Command Execution via command_test.phpOP5 Monitor8.7 (v4.0)High
CVE-2026-10108xiaomusic 0.5.7 Path Traversal via GET /music endpointxiaomusic8.7 (v4.0)High
CVE-2026-17524zip-lib Path Traversal Vulnerabilityzip-lib8.7 (v4.0)High
CVE-2026-25559OpenBullet2 0.3.2 Path Traversal via Wordlist Endpointopenbullet28.7 (v4.0)High
CVE-2026-25855OpenBullet2 0.3.2 Authenticated RCE via FileProxySource Script Uploadopenbullet28.7 (v4.0)High
CVE-2026-25856OpenBullet2 0.3.2 Authenticated RCE via Job Configuration Interfaceopenbullet28.7 (v4.0)High
CVE-2026-34228Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File Writeemlog8.7 (v4.0)High
CVE-2026-34367InvoiceShelf: SSRF in Invoice PDF Rendering via Unsanitised HTML in Notes Fieldinvoiceshelf8.7 (v3.1)High
CVE-2026-34735Hytale Modding Vulnerable to Remote Code Execution via File Upload Bypass in FileControllerwiki8.7 (v4.0)High
CVE-2026-34792Endian Firewall /cgi-bin/logs_clamav.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34793Endian Firewall /cgi-bin/logs_firewall.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34794Endian Firewall /cgi-bin/logs_ids.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34795Endian Firewall /cgi-bin/logs_log.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34796Endian Firewall /cgi-bin/logs_openvpn.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34797Endian Firewall /cgi-bin/logs_smtp.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-47659Pathling has path traversal in $import-pnp manifest that enables read-capable SSRF via /jobs/{jobId}/{filename}pathling8.7 (v4.0)High
CVE-2026-47661Pathling has path traversal in $result endpoint that allows arbitrary warehouse file readpathling8.7 (v4.0)High
CVE-2026-64837ICEcoder through 8.1 OS Command Injection via lib/properties.phpICEcoder8.7 (v4.0)High
CVE-2026-64838ICEcoder through 8.1 Path Traversal via oldFileName ParameterICEcoder8.7 (v4.0)High
CVE-2026-65694Microweber CMS <= 2.0.20 - Unauthenticated Arbitrary File Readmicroweber8.7 (v4.0)High
CVE-2026-65759Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1Easy Store extension for Joomla8.7 (v4.0)High
CVE-2026-65919Meshery < 1.0.57 Unauthenticated Arbitrary File Read via fileView and fileDownloadmeshery8.7 (v4.0)High
CVE-2026-67200Perspective 5.0.0 Path Traversal via cwd_static_file_handlerperspective8.7 (v4.0)High
CVE-2026-67206Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Uploadwolfcms8.7 (v4.0)High
CVE-2026-67281Unauthenticated file read in Mikrotik RouterOSRouterOS8.7 (v4.0)High
CVE-2026-69089Grav CMS before 2.0.11 Path Traversal via watermarkgrav8.7 (v4.0)High
CVE-2026-69095OpenWrt luci-app-bmx7 Path Traversal via bmx7-infoluci8.7 (v4.0)High
CVE-2026-75111Evidently UI Path Traversal via Dataset Materialization Filenameevidently8.7 (v4.0)High
CVE-2026-75482SWE-agent Trajectory Inspector Path Traversal File DisclosureSWE-agent8.7 (v4.0)High
CVE-2026-76060OS Command Injection in PayRange APIZoneminder8.7 (v4.0)High
CVE-2026-76836AzuraCast through 0.23.8 Liquidsoap Configuration Write via Profile Edit Serialization Group BypassAzuraCast8.7 (v4.0)High
CVE-2026-79756Nuclio: Unauthenticated OS command injection via namespace header in list-all resource path on local platformnuclio8.7 (v4.0)High
CVE-2026-81093Apify Actors MCP Server before 0.9.12 Server-Side Request Forgery via get-html-skeletonactors-mcp-server8.7 (v4.0)High
CVE-2026-82270Portkey AI Gateway Server-Side Request Forgery via /v1/proxy/*gateway8.7 (v4.0)High
CVE-2026-82638jina-ai reader Server-Side Request Forgery via disabled private-address guardreader8.7 (v4.0)High
CVE-2026-85608Douyin_TikTok_Download_API 4.1.2 SSRF via url parameterDouyin TikTok Download API8.7 (v4.0)High
CVE-2026-85610OpenPanel before 2.3.0 Remote Code Execution via chart formulasopenpanel8.7 (v4.0)High
CVE-2026-85612OpenPanel before 2.3.0 SSRF via favicon and og endpointsopenpanel8.7 (v4.0)High
CVE-2026-85673LLaMA-Factory SSRF Guard Bypass via Redirect and DNS RebindingLlamaFactory8.7 (v4.0)High
CVE-2026-85685AgentScope through 2.0.7.post1 Arbitrary Directory Copy via add_skillagentscope8.7 (v4.0)High
CVE-2026-89250WWBN AVideo Unauthenticated File Read via getRecordedFile.phpAVideo8.7 (v4.0)High
CVE-2026-9506Path Traversal Vulnerability in BagistoBagisto8.7 (v4.0)High
CVE-2015-4694WordPress Zip Attachments <= 1.1.4 - Arbitrary File Retrievalzip attachments8.6 (v3.0)High
CVE-2018-16288LG SuperSign EZ CMS 2.5 - Local File Inclusionsupersign cms8.6 (v3.0)High
CVE-2021-32820Express-handlebars - Local File Inclusionexpress handlebars8.6 (v3.1)High
CVE-2022-24900Piano LED Visualizer 1.3 - Local File Inclusionpiano led visualizer8.6 (v3.1)High
CVE-2024-20353adaptive security appliance software Denial of Service Vulnerabilityadaptive security appliance software8.6 (v3.1)High
CVE-2024-34470HSC Mailinspector 5.2.17-3 through 5.2.18 - Local File Inclusionmailinspector8.6 (v3.1)High
CVE-2025-2558WordPress The Wound Theme <= 0.0.1 - Local File Inclusionthe wound8.6 (v3.1)High
CVE-2026-30958OneUptime < 10.0.21 - Path Traversaloneuptime8.6 (v3.1)High
CVE-2026-34160Chamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata serchamilo lms8.6 (v3.1)High
CVE-2026-34577Postiz: Unauthenticated Full-Read SSRF via /public/stream Endpoint with Trivially Bypassable Extension Checkpostiz8.6 (v3.1)High
CVE-2026-40187Authenticated RCE via Malicious eTemplate Upload in EGroupwareegroupware8.6 (v4.0)High
CVE-2026-42785OpenKM 6.3.12 Remote Code Execution via Administrative ScriptingOpenKM Community Edition8.6 (v4.0)High
CVE-2026-46491SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditisimplesamlphp-module-casserver8.6 (v3.1)High
CVE-2026-53804OTRS Community Edition OS Command Injection via PGP ConfigurationOTRS Community Edition8.6 (v4.0)High
CVE-2026-54650openhole-server vulnerable to path traversal via URL-decoded request pathopenhole8.6 (v3.1)High
CVE-2026-56703Adminer before 5.4.3 Remote Code Execution via SQLite VACUUM INTOadminer8.6 (v4.0)High
CVE-2026-5917libgit2 Shell Command Injection via ssh_libssh2 Backendlibgit28.6 (v4.0)High
CVE-2026-67599ClearOS 7.9 OS Command Injection via Log Viewer filter parameterClearOS8.6 (v4.0)High
CVE-2026-67608Telenia TVox 26.5.3 OS Command Injection via action_audio.phpTVox8.6 (v4.0)High
CVE-2026-71908DrayTek VigorAP Multiple Models OS Command Injection via mesh_start_speed_testVigorAP 918R8.6 (v4.0)High
CVE-2026-71913DrayTek VigorAP Multiple Models OS Command Injection via upload_settings.cgiVigorAP 918R8.6 (v4.0)High
CVE-2026-71918DrayTek VigorSwitch Multiple Models OS Command Injection via webBackupActionVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71919DrayTek VigorSwitch Multiple Models OS Command Injection via sysrebootVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71931DrayTek VigorSwitch Multiple Models OS Command Injection via tftp_upgradeVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-7412Eclipse BaSyx SSRF VulnerabilityEclipse BaSyx8.6 (v3.1)High
CVE-2026-75123PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_smtp_test_postPLANET GS-4210-16P2S V38.6 (v4.0)High
CVE-2026-80214LibreNMS Virtualisation Discovery Module RCElibrenms8.6 (v4.0)High
CVE-2026-81889elFinder: SSRF protection bypass via DNS rebinding in the fsock_get_contents() fallbackelFinder8.6 (v3.1)High
CVE-2026-82692D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injectionDNS-340L8.6 (v4.0)High
CVE-2026-86733Snipe-IT before 8.7.0 Remote Code Execution via Backup Restoresnipe-it8.6 (v4.0)High
CVE-2015-2996SysAid Help Desk <15.2 - Local File Inclusionsysaid8.5 (v2.0)High
CVE-2025-34023Karel IP Phone IP1211 Web Management Panel - Local File InclusionKarel IP Phone IP12118.5 (v4.0)High
CVE-2026-22244OpenMetadata Server-Side Template Injection (SSTI) in FreeMarker email templates that leads to RCEopenmetadata8.5 (v4.0)High
CVE-2026-44881Portainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-Updateportainer8.5 (v4.0)High
CVE-2026-61640Wallos: SSRF via OIDC Token/UserInfo URL ConfigurationWallos8.5 (v4.0)High
CVE-2026-67424Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidationflyto-core8.5 (v3.1)High
CVE-2026-69250Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret ExfiltrationFlowise8.5 (v4.0)High
CVE-2026-73079Sub2API: Path traversal in the Responses subpath routes lets an authenticated tenant relay requests to arbitrary upstreasub2api8.5 (v3.1)High
CVE-2026-82690D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injectionDNS-327L8.5 (v4.0)High
CVE-2026-85222D-Link DNS-340L Add-On Center addon_center.cgi os command injectionDNS-340L8.5 (v4.0)High
CVE-2026-85224D-Link DNS-320 ShareCenter File Sharing file_sharing.cgi os command injectionDNS-320 ShareCenter8.5 (v4.0)High
CVE-2026-72855Budibase before 3.40.0 DNS Rebinding SSRF via OpenAPI and RESTserver8.4 (v4.0)High
CVE-2026-52769YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub Signature.keyIdyeswiki8.3 (v3.1)High
CVE-2026-76844webpack-dev-middleware Path Traversal via Offset Slice on a Non-Slash-Terminated publicPathwebpack-dev-middleware8.3 (v4.0)High
CVE-2024-40348Bazarr < 1.4.3 - Arbitrary File Readbazarr8.2 (v3.1)High
CVE-2025-44137MapTiler Tileserver-php v2.0 - Unauthenticated File Readtileserver php8.2 (v3.1)High
CVE-2025-44177White Star Software Protop 4.4.2-2024-11-27 - Local File Inclusion (LFI)protop8.2 (v3.1)High
CVE-2026-16268Newsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Bounce HandlerNewsletters8.2 (v3.1)High
CVE-2026-23482Blinko < 1.8.4 - Path Traversalblinko8.2 (v4.0)High
CVE-2026-39363Vite Affected by Arbitrary File Read via Vite Dev Server WebSocketvite8.2 (v4.0)High
CVE-2026-39364Vite Dev Server - Directory Traversalvite8.2 (v4.0)High
CVE-2026-40075OpenMRS Core arbitrary file read via path traversal in ModuleResourcesServletopenmrs8.2 (v4.0)High
CVE-2026-43910Appium java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutorjava-client8.2 (v3.1)High
CVE-2026-48126Algernon: Host header path traversal in –domain mode reads files and runs Lua from parent diralgernon8.2 (v3.1)High
CVE-2026-54691datamodel-code-generator vulnerable to SSRF via –url: no host/IP validation, follows redirectsdatamodel-code-generator8.2 (v3.1)High
CVE-2026-73658Trigger.dev: Cross-tenant object store read and write via URL path traversaltrigger.dev8.2 (v3.1)High
CVE-2026-74907Grav before 2.0.15 Path Traversal via plugin-asset-map.phpgrav8.2 (v4.0)High
CVE-2026-77348Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.phWallos8.2 (v3.1)High
CVE-2026-82262Logto Server-Side Request Forgery via webhook test endpointlogto8.2 (v4.0)High
CVE-2016-3081Apache S2-032 Struts - Remote Code Executionstruts8.1 (v3.0)High
CVE-2017-12615Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (1)tomcat8.1 (v3.1)High
CVE-2018-11776Apache Struts2 S2-057 - Remote Code Executionstruts8.1 (v3.1)High
CVE-2024-30188Apache DolphinScheduler >= 3.1.0, < 3.2.2 Resource File Read And Writedolphinscheduler8.1 (v3.1)High
CVE-2025-48157WordPress Formality Plugin <= 1.5.9 - Local File InclusionFormality8.1 (v3.1)High
CVE-2026-19303Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing clangflow8.1 (v3.1)High
CVE-2026-33236NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwritenltk8.1 (v3.1)High
CVE-2026-34365InvoiceShelf: SSRF in Estimate PDF Rendering via Unsanitised HTML in Notes Fieldinvoiceshelf8.1 (v3.1)High
CVE-2026-34366InvoiceShelf: SSRF in Payment Receipt PDF Rendering via Unsanitised HTML in Notes Fieldinvoiceshelf8.1 (v3.1)High
CVE-2026-46484Headplane: Path Traversal + RBAC Bypass in renameNode allows authenticated OIDC users to expire or rename any node/userheadplane8.1 (v3.1)High
CVE-2026-53580Trilium arbitrary file read and denial of service via file:// URLs in the automatic image-download featureTrilium8.1 (v3.1)High
CVE-2026-73659Trigger.dev: Cross-tenant object read/write via path traversal in packet presign APItrigger.dev8.1 (v3.1)High
CVE-2009-1558Cisco Linksys WVC54GCA 1.00R22/1.00R24 - Local File Inclusionwvc54gca7.8 (v2.0)High
CVE-2010-4231Camtron CMNC-200 IP Camera - Directory Traversalcmnc-200 firmware7.8 (v2.0)High
CVE-2011-3315Cisco CUCM, UCCX, and Unified IP-IVR- Directory Traversalunified ip interactive voice response7.8 (v2.0)High
CVE-2014-2962Belkin N150 Router 1.00.08/1.00.09 - Path Traversaln150 f9k1009 firmware7.8 (v2.0)High
CVE-2021-21315Node.JS System Information Library <5.3.1 - Remote Command Injectionsysteminformation7.8 (v3.1)High
CVE-2026-65600Traefik before v2.11.52 Authentication Bypass via ReplacePathRegextraefik7.8 (v4.0)High
CVE-2026-67309Traefik v3.7.0 Path Traversal via RewriteTarget Authentication Bypasstraefik7.8 (v4.0)High
CVE-2020-35749WordPress Simple Job Board <2.9.4 - Local File Inclusionsimple board job7.7 (v3.1)High
CVE-2021-21234Spring Boot Actuator Logview Directory Traversalspring-boot-actuator-logview7.7 (v3.1)High
CVE-2021-43831Gradio < 2.5.0 - Arbitrary File Readgradio7.7 (v3.1)High
CVE-2025-46822Java-springboot-codebase 1.1 - Arbitrary File ReadJava-springboot-codebase7.7 (v4.0)High
CVE-2025-59341esm.sh <= v136 - Local File Inclusionesm.sh7.7 (v4.0)High
CVE-2026-34936PraisonAI: SSRF via Unvalidated api_base in passthrough() Fallbackpraisonai7.7 (v3.1)High
CVE-2026-42345FastGPT: Cloud metadata endpoint SSRF protection bypass via port specification, IPv6 mapping, hex/decimal IP encoding, aFastGPT7.7 (v3.1)High
CVE-2026-47179Arcane: Authenticated Arbitrary Host File Read via Docker Compose Include Directives in Arcanearcane7.7 (v3.1)High
CVE-2026-53549Termix: Server-Side Request Forgery via Proxy Connectivity TestTermix7.7 (v3.1)High
CVE-2026-54910FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary filesfilebrowser7.7 (v3.1)High
CVE-2026-61835Directus: SSRF Protection Bypass via 0.0.0.0 in File Importdirectus7.7 (v3.1)High
CVE-2026-63764LMDeploy Server-Side Request Forgery via HTTP Redirect Bypasslmdeploy7.7 (v4.0)High
CVE-2026-66738SPIP < 4.4.18 Code Injection via Navigation Endpoint on SQLiteSPIP7.7 (v4.0)High
CVE-2026-67346Swarms 6.8.1 Server-Side Request Forgery via DNS Rebinding Bypassswarms7.7 (v4.0)High
CVE-2026-69192ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trusip-address7.7 (v4.0)High
CVE-2026-73498MCP Atlassian is a Model Context Protocol (MCP): Arbitrary file read via missing path validation in confluence_upload_atmcp-atlassian7.7 (v3.1)High
CVE-2026-77775Headroom Proxy Sends Upstream Requests to a Client-Supplied Base URL Without Address ValidationHeadroom7.7 (v4.0)High
CVE-2026-8183Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcementlangflow7.7 (v3.1)High
CVE-2026-44239FreePBX: Authenticated Local File Inclusion in Dashboard Modulefreepbx7.6 (v4.0)High
CVE-2026-79749MCPHub: SSRF Guard Bypass via IPv6 Transition Addresses in URL Validationmcphub7.6 (v4.0)High
CVE-2006-2842Squirrelmail <=1.4.6 - Local File Inclusionsquirrelmail7.5 (v2.0)High
CVE-2009-2015Joomla! MooFAQ 1.0 - Local File InclusionJoomla!7.5 (v2.0)High
CVE-2009-3318Joomla! Roland Breedveld Album 1.14 - Local File InclusionJoomla!7.5 (v2.0)High
CVE-2009-4202Joomla! Omilen Photo Gallery 0.5b - Local File Inclusionjoomla!7.5 (v2.0)High
CVE-2009-4679Joomla! Portfolio Nexus - Remote File Inclusioncom if nexus7.5 (v2.0)High
CVE-2010-0157Joomla! Component com_biblestudy - Local File Inclusionjoomla!7.5 (v2.0)High
CVE-2010-0759Joomla! Plugin Core Design Scriptegrator - Local File Inclusionscriptegrator plugin7.5 (v2.0)High
CVE-2010-0972Joomla! Component com_gcalendar Suite 2.1.5 - Local File Inclusioncom gcalendar7.5 (v2.0)High
CVE-2010-0985Joomla! Component com_abbrev - Local File Inclusioncom abbrev7.5 (v2.0)High
CVE-2010-1306Joomla! Component Picasa 2.0 - Local File Inclusioncom joomlapicasa27.5 (v2.0)High
CVE-2010-1470Joomla! Component Web TV 1.0 - Local File Inclusioncom webtv7.5 (v2.0)High
CVE-2010-1471Joomla! Component Address Book 1.5.0 - Local File Inclusioncom addressbook7.5 (v2.0)High
CVE-2010-1472Joomla! Component Horoscope 1.5.0 - Local File Inclusioncom horoscope7.5 (v2.0)High
CVE-2010-1495Joomla! Component Matamko 1.01 - Local File Inclusioncom matamko7.5 (v2.0)High
CVE-2010-1531Joomla! Component redSHOP 1.0 - Local File Inclusioncom redshop7.5 (v2.0)High
CVE-2010-1533Joomla! Component TweetLA 1.0.1 - Local File Inclusioncom tweetla7.5 (v2.0)High
CVE-2010-1535Joomla! Component TRAVELbook 1.0.1 - Local File Inclusioncom travelbook7.5 (v2.0)High
CVE-2010-1602Joomla! Component ZiMB Comment 0.8.1 - Local File Inclusioncom zimbcomment7.5 (v2.0)High
CVE-2010-1603Joomla! Component ZiMBCore 0.1 - Local File Inclusioncom zimbcore7.5 (v2.0)High
CVE-2010-1653Joomla! Component Graphics 1.0.6 - Local File Inclusioncom graphics7.5 (v2.0)High
CVE-2010-1717Joomla! Component iF surfALERT 1.2 - Local File Inclusionif surfalert7.5 (v2.0)High
CVE-2010-1875Joomla! Component Property - Local File Inclusioncom properties7.5 (v2.0)High
CVE-2010-1878Joomla! Component OrgChart 1.0.0 - Local File Inclusioncom orgchart7.5 (v2.0)High
CVE-2010-1952Joomla! Component BeeHeard 1.0 - Local File Inclusioncom beeheard7.5 (v2.0)High
CVE-2010-1953Joomla! Component iNetLanka Multiple Map 1.0 - Local File Inclusioncom multimap7.5 (v2.0)High
CVE-2010-1954Joomla! Component iNetLanka Multiple root 1.0 - Local File Inclusioncom multiroot7.5 (v2.0)High
CVE-2010-1955Joomla! Component Deluxe Blog Factory 1.1.2 - Local File Inclusioncom blogfactory7.5 (v2.0)High
CVE-2010-1956Joomla! Component Gadget Factory 1.0.0 - Local File Inclusioncom gadgetfactory7.5 (v2.0)High
CVE-2010-1957Joomla! Component Love Factory 1.3.4 - Local File Inclusioncom lovefactory7.5 (v2.0)High
CVE-2010-1977Joomla! Component J!WHMCS Integrator 1.5.0 - Local File Inclusioncom jwhmcs7.5 (v2.0)High
CVE-2010-1980Joomla! Component Joomla! Flickr 1.0 - Local File Inclusioncom joomlaflickr7.5 (v2.0)High
CVE-2010-1983Joomla! Component redTWITTER 1.0 - Local File Inclusioncom redtwitter7.5 (v2.0)High
CVE-2010-2033Joomla! Percha Categories Tree 0.6 - Local File Inclusioncom perchacategoriestree7.5 (v2.0)High
CVE-2010-2034Joomla! Component Percha Image Attach 1.1 - Directory Traversalcom perchaimageattach7.5 (v2.0)High
CVE-2010-2035Joomla! Component Percha Gallery 1.6 Beta - Directory Traversalcom perchagallery7.5 (v2.0)High
CVE-2010-2036Joomla! Component Percha Fields Attach 1.0 - Directory Traversalcom perchafieldsattach7.5 (v2.0)High
CVE-2010-2037Joomla! Component Percha Downloads Attach 1.1 - Directory Traversalcom perchadownloadsattach7.5 (v2.0)High
CVE-2010-2045Joomla! Component FDione Form Wizard 1.0.2 - Local File Inclusioncom dioneformwizard7.5 (v2.0)High
CVE-2010-2050Joomla! Component MS Comment 0.8.0b - Local File Inclusioncom mscomment7.5 (v2.0)High
CVE-2010-2128Joomla! Component JE Quotation Form 1.0b1 - Local File Inclusioncom jequoteform7.5 (v2.0)High
CVE-2010-2259Joomla! Component com_bfsurvey - Local File Inclusioncom bfsurvey profree7.5 (v2.0)High
CVE-2010-2682Joomla! Component Realtyna Translator 1.0.15 - Local File Inclusioncom realtyna7.5 (v2.0)High
CVE-2010-2918Joomla! Component Visites 1.1 - MosConfig_absolute_path Remote File Inclusioncom joomla visites7.5 (v2.0)High
CVE-2010-3426Joomla! Component Jphone 1.0 Alpha 3 - Local File Inclusioncom jphone7.5 (v2.0)High
CVE-2010-4282Pandora Fms < 3.1.1 - Directory Traversalpandora fms7.5 (v2.0)High
CVE-2010-4719Joomla! Component JRadio - Local File Inclusioncom jradio7.5 (v2.0)High
CVE-2010-4769Joomla! Component Jimtawl 1.0.2 - Local File Inclusioncom jimtawl7.5 (v2.0)High
CVE-2010-4977Joomla! Component Canteen 1.0 - Local File Inclusioncom canteen7.5 (v2.0)High
CVE-2010-5028Joomla! Component JE Job 1.0 - Local File Inclusioncom jejob7.5 (v2.0)High
CVE-2012-1226Dolibarr ERP/CRM 3.2 Alpha - Multiple Directory Traversal Vulnerabilitiesdolibarr erp/crm7.5 (v2.0)High
CVE-2014-10037DomPHP 0.83 - Directory Traversaldomphp7.5 (v2.0)High
CVE-2014-3744Node.js st module Directory Traversalnode.js7.5 (v3.0)High
CVE-2015-1000005WordPress Candidate Application Form <= 1.3 - Local File Inclusioncandidate-application-form7.5 (v3.0)High
CVE-2015-1000010WordPress Simple Image Manipulator < 1.0 - Local File Inclusionsimple-image-manipulator7.5 (v3.0)High
CVE-2015-1000012WordPress MyPixs <=0.3 - Local File Inclusionmypixs7.5 (v3.0)High
CVE-2015-1503IceWarp Mail Server < 11.1.1 - Directory Traversalmail server7.5 (v3.0)High
CVE-2015-3035TP-LINK - Local File Inclusiontl-wr841n (9.0) firmware7.5 (v3.1)High
CVE-2015-3648ResourceSpace - Local File inclusionresourcespace7.5 (v2.0)High
CVE-2015-4074Joomla! Helpdesk Pro plugin <1.4.0 - Local File Inclusionhelpdesk pro7.5 (v3.0)High
CVE-2015-4632Koha 3.20.1 - Directory Traversalkoha7.5 (v3.0)High
CVE-2015-5469WordPress MDC YouTube Downloader 2.1.0 - Local File Inclusionmdc youtube downloader7.5 (v3.0)High
CVE-2016-10956WordPress Mail Masta 1.0 - Local File Inclusionmail-masta7.5 (v3.1)High
CVE-2016-2389SAP xMII 15.0 for SAP NetWeaver 7.4 - Local File Inclusionnetweaver7.5 (v3.0)High
CVE-2016-6601WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilitieswebnms framework7.5 (v3.0)High
CVE-2017-1000028Oracle GlassFish Server Open Source Edition 4.1 - Local File Inclusionglassfish server7.5 (v3.0)High
CVE-2017-1000029Oracle GlassFish Server Open Source Edition 3.0.1 - Local File Inclusionglassfish server7.5 (v3.0)High
CVE-2017-14849Node.js <8.6.0 - Directory Traversalnode.js7.5 (v3.0)High
CVE-2017-15647FiberHome Routers - Local File Inclusionrouterfiberhome firmware7.5 (v3.0)High
CVE-2017-16806Ulterius Server < 1.9.5.0 - Directory Traversalulterius server7.5 (v3.0)High
CVE-2017-16877Nextjs <2.4.1 - Local File Inclusionnext.js7.5 (v3.0)High
CVE-2017-6190D-Link DWR-116 / DWR-116A1 - Arbitrary File Downloaddwr-116 firmware7.5 (v3.0)High
CVE-2017-9833BOA Web Server 0.94.14 - Arbitrary File Accessboa7.5 (v3.1)High
CVE-2018-10822D-Link Routers - Local File Inclusiondwr-116 firmware7.5 (v3.1)High
CVE-2018-10956IPConfigure Orchid Core VMS 2.0.5 - Local File Inclusionorchid core vms7.5 (v3.0)High
CVE-2018-12909Webgrind <= 1.5 - Local File Inclusionwebgrind7.5 (v3.0)High
CVE-2018-14912cgit < 1.2.1 - Directory Traversalcgit7.5 (v3.0)High
CVE-2018-14918LOYTEC LGATE-902 6.3.2 - Local File Inclusionlgate-902 firmware7.5 (v3.0)High
CVE-2018-15138LG-Ericsson iPECS NMS 30M - Local File Inclusionipecs nms7.5 (v3.0)High
CVE-2018-15535Responsive FileManager < 9.13.4 - Directory Traversalresponsive filemanager7.5 (v3.0)High
CVE-2018-16299WordPress Localize My Post 1.0 - Local File Inclusionlocalize my post7.5 (v3.0)High
CVE-2018-18323Centos Web Panel 0.9.8.480 - Local File Inclusionwebpanel7.5 (v3.0)High
CVE-2018-19326Zyxel VMG1312-B10D 5.13AAXA.8 - Local File Inclusionvmg1312-b10d firmware7.5 (v3.0)High
CVE-2018-19458PHP Proxy 3.0.3 - Local File Inclusionphp-proxy7.5 (v3.0)High
CVE-2018-19753Tarantella Enterprise <3.11 - Local File Inclusiontarantella enterprise7.5 (v3.0)High
CVE-2018-3760Ruby On Rails - Local File Inclusioncloudforms7.5 (v3.0)High
CVE-2018-6008Joomla! Jtag Members Directory 5.3.7 - Local File Inclusionjtag members directory7.5 (v3.0)High
CVE-2018-6184Zeit Next.js < 4.2.3 - Local File Inclusionnext.js7.5 (v3.0)High
CVE-2018-7422WordPress Site Editor <=1.1.1 - Local File Inclusionsite editor7.5 (v3.0)High
CVE-2018-7490uWSGI PHP Plugin Local File Inclusionuwsgi7.5 (v3.0)High
CVE-2018-9205Drupal avatar_uploader v7.x-1.0-beta8 - Local File Inclusionavatar uploader7.5 (v3.0)High
CVE-2019-12276GrandNode 4.40 - Local File Inclusiongrandnode7.5 (v3.0)High
CVE-2019-14251T24 Web Server - Local File Inclusiont247.5 (v3.1)High
CVE-2019-16123PilusCart <=1.4.1 - Local File Inclusionpiluscart7.5 (v3.1)High
CVE-2019-17538Jiangnan Online Judge 0.8.0 - Local File Inclusionjiangnan online judge7.5 (v3.1)High
CVE-2019-18371Xiaomi Mi WiFi R3G Routers - Local file Inclusionmillet router 3g firmware7.5 (v3.1)High
CVE-2019-18665DOMOS 5.5 - Local File Inclusiondomos7.5 (v3.1)High
CVE-2019-18922Allied Telesis AT-GS950/8 - Local File Inclusionat-gs950/8 firmware7.5 (v3.1)High
CVE-2019-7254eMerge E3 1.00-06 - Local File Inclusionlinear emerge essential firmware7.5 (v3.1)High
CVE-2019-7315Genie Access WIP3BVAF IP Camera - Local File Inclusionwip3bvaf7.5 (v3.0)High
CVE-2019-9922Joomla! Harmis Messenger 1.2.2 - Local File Inclusionje messenger7.5 (v3.1)High
CVE-2020-11738WordPress Duplicator 1.3.24 & 1.3.26 - Local File Inclusionduplicator7.5 (v3.1)High
CVE-2020-12447Onkyo TX-NR585 Web Interface - Directory Traversaltx-nr585 firmware7.5 (v3.1)High
CVE-2020-13158Artica Proxy Community Edition <4.30.000000 - Local File Inclusionartica proxy7.5 (v3.1)High
CVE-2020-14864Oracle Fusion - Directory Traversal/Local File Inclusionbusiness intelligence7.5 (v3.1)High
CVE-2020-19360FHEM 6.0 - Local File Inclusionfhem7.5 (v3.1)High
CVE-2020-23575Kyocera Printer d-COPIA253MF - Directory Traversald-copia253mf plus firmware7.5 (v3.1)High
CVE-2020-24285INTELBRAS TELEFONE IP TIP200 60.61.75.22 - Local File Inclusiontip2007.5 (v3.1)High
CVE-2020-26073Cisco SD-WAN vManage Software - Local File Inclusioncatalyst sd-wan manager7.5 (v3.1)High
CVE-2020-27191LionWiki <3.2.12 - Local File Inclusionlionwiki7.5 (v3.1)High
CVE-2020-27467Processwire CMS <2.7.1 - Local File Inclusionprocesswire7.5 (v3.1)High
CVE-2020-35580SearchBlox <9.2.2 - Local File Inclusionsearchblox7.5 (v3.1)High
CVE-2020-35598Advanced Comment System 1.0 - Local File Inclusionadvanced comment system7.5 (v3.1)High
CVE-2020-35736GateOne 1.1 - Local File Inclusiongateone7.5 (v3.1)High
CVE-2020-8209Citrix XenMobile Server - Local File Inclusionxenmobile server7.5 (v3.1)High
CVE-2021-20123Draytek VigorConnect 1.6.0-B - Local File Inclusionvigorconnect7.5 (v3.1)High
CVE-2021-20124Draytek VigorConnect 6.0-B3 - Local File Inclusionvigorconnect7.5 (v3.1)High
CVE-2021-24227Patreon WordPress <1.7.0 - Unauthenticated Local File Inclusionpatreon wordpress7.5 (v3.1)High
CVE-2021-25864Hue Magic 3.0.0 - Local File Inclusionhuemagic7.5 (v3.1)High
CVE-2021-3223Node RED Dashboard <2.26.2 - Local File Inclusionnode-red-dashboard7.5 (v3.1)High
CVE-2021-39316WordPress DZS Zoomsounds <=6.50 - Local File Inclusionzoomsounds7.5 (v3.1)High
CVE-2021-39433BIQS IT Biqs-drive v1.83 Local File Inclusionbiqsdrive7.5 (v3.1)High
CVE-2021-40978MKdocs 1.2.2 - Directory Traversalmkdocs7.5 (v3.1)High
CVE-2021-41277Metabase - Local File Inclusionmetabase7.5 (v3.1)High
CVE-2021-41291ECOA Building Automation System - Directory Traversal Content Disclosureecs router controller-ecs firmware7.5 (v3.1)High
CVE-2021-41569SAS/Internet 9.4 1520 - Local File Inclusionsas/intrnet7.5 (v3.1)High
CVE-2021-43287Pre-Auth Takeover of Build Pipelines in GoCDgocd7.5 (v3.1)High
CVE-2021-43495AlquistManager Local File Inclusionalquist7.5 (v3.1)High
CVE-2021-43496Clustering Local File Inclusionclustering7.5 (v3.1)High
CVE-2021-43734kkFileview v4.0.0 - Local File Inclusionkkfileview7.5 (v3.1)High
CVE-2021-43778GLPI plugin Barcode < 2.6.1 - Path Traversal Vulnerability.barcode7.5 (v3.1)High
CVE-2021-43798Grafana v8.x - Arbitrary File Readgrafana7.5 (v3.1)High
CVE-2021-46107Ligeo Archives Ligeo Basics - Server Side Request Forgeryligeo basics7.5 (v3.1)High
CVE-2021-46417Franklin Fueling Systems Colibri Controller Module 1.8.19.8580 - Local File Inclusion (LFI)colibri firmware7.5 (v3.1)High
CVE-2022-24716Icinga Web 2 - Arbitrary File Disclosureicinga web 27.5 (v3.1)High
CVE-2022-27043Yearning - Directory Traversalyearning7.5 (v3.1)High
CVE-2022-29298SolarView Compact 6.00 - Local File Inclusionsv-cpt-mc310 firmware7.5 (v3.1)High
CVE-2022-31474BackupBuddy - Local File Inclusionbackupbuddy7.5 (v3.1)High
CVE-2022-33901WordPress MultiSafepay for WooCommerce <=4.13.1 - Arbitrary File Readmultisafepay plugin for woocommerce7.5 (v3.1)High
CVE-2022-37122Carel pCOWeb HVAC BACnet Gateway 2.1.0 - Path Traversalpcoweb hvac bacnet gateway7.5 (v3.1)High
CVE-2022-38794Zaver - Local File Inclusionzaver7.5 (v3.1)High
CVE-2022-4140WordPress Welcart e-Commerce <2.8.5 - Arbitrary File Accesswelcart e-commerce7.5 (v3.1)High
CVE-2022-47501Apache OFBiz < 18.12.07 - Local File Inclusionofbiz7.5 (v3.1)High
CVE-2023-0126SonicWall SMA1000 LFIsma10007.5 (v3.1)High
CVE-2023-22047Oracle Peoplesoft - Unauthenticated File Readpeoplesoft enterprise7.5 (v3.1)High
CVE-2023-23063Cellinx NVT Web Server - Local File Disclosurenvt web server7.5 (v3.1)High
CVE-2023-26256STAGIL Navigation for Jira Menu & Themes <2.0.52 - Local File Inclusionstagil navigation7.5 (v3.1)High
CVE-2023-29887Nuovo Spreadsheet Reader 0.5.11 - Local File Inclusionspreadsheet-reader7.5 (v3.1)High
CVE-2023-33510Jeecg P3 Biz Chat - Local File Inclusionjeecg p3 biz chat7.5 (v3.1)High
CVE-2023-35843NocoDB version <= 0.106.1 - Arbitrary File Readnocodb7.5 (v3.1)High
CVE-2023-35844Lightdash version <= 0.510.3 Arbitrary File Readlightdash7.5 (v3.1)High
CVE-2023-37474Copyparty <= 1.8.2 - Directory Traversalcopyparty7.5 (v3.1)High
CVE-2023-38879openSIS v9.0 - Path Traversalopensis7.5 (v3.1)High
CVE-2023-39141Aria2 WebUI - Path traversalwebui-aria27.5 (v3.1)High
CVE-2023-40924SolarView Compact < 6.00 - Directory Traversalsolarview compact firmware7.5 (v3.1)High
CVE-2023-6020Ray Static File - Local File Inclusionray7.5 (v3.1)High
CVE-2023-6023VertaAI ModelDB - Path Traversalmodeldb7.5 (v3.1)High
CVE-2023-6038H2O ImportFiles - Local File Inclusionh2o7.5 (v3.1)High
CVE-2024-23334aiohttp - Directory Traversalaiohttp7.5 (v3.1)High
CVE-2024-27292Docassemble - Local File Inclusiondocassemble7.5 (v3.1)High
CVE-2024-38816WebMvc.fn/WebFlux.fn - Path TraversalSpring7.5 (v3.1)High
CVE-2024-38819Spring Framework Path Traversal in Functional Web Frameworksspring framework7.5 (v3.1)High
CVE-2024-41628Cluster Control CMON API - Directory Traversalcluster control7.5 (v3.1)High
CVE-2024-4956Sonatype Nexus Repository Manager 3 - Local File Inclusionnexus7.5 (v3.1)High
CVE-2024-5334Devika - Local File Inclusiondevika7.5 (v3.0)High
CVE-2024-9362Polyaxon - Unauthenticated Directory Traversalpolyaxon/polyaxon7.5 (v3.0)High
CVE-2024-9935PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Arbitrary File Downloadpdf-generator-addon-for-elementor-page-builder7.5 (v3.1)High
CVE-2025-13339Hippoo Mobile App for WooCommerce <= 1.7.1 - Unauthenticated Arbitrary File ReadHippoo Mobile App for WooCommerce7.5 (v3.1)High
CVE-2025-13801Yoco Payments <= 3.8.8 - Path TraversalYoco Payments7.5 (v3.1)High
CVE-2025-24963Vitest Browser Mode - Local File Readvitest7.5 (v3.1)High
CVE-2025-30208Vite - Arbitrary File Readvite7.5 (v3.1)High
CVE-2025-31125Vite Development Server - Path Traversalvite7.5 (v3.1)High
CVE-2025-31131Yeswiki < 4.5.2 - Unauthenticated Path Traversalyeswiki7.5 (v3.1)High
CVE-2025-45145Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 Path Traversal Vulnerability-7.5 (v3.1)High
CVE-2025-57231Path Traversal in avatar attachments in Docmost v0.21.0 Vulnerability-7.5 (v3.1)High
CVE-2025-59049Mockoon < 9.2.0 - Path Traversalmockoon7.5 (v3.1)High
CVE-2025-61884Oracle E-Business Suite - Server-Side Request Forgeryconfigurator7.5 (v3.1)High
CVE-2025-69411ionCube Tester Plus <= 1.3 - Local File InclusionionCube tester plus7.5 (v3.1)High
CVE-2026-29962HSC MailInspector - Local File Inclusionmailinspector7.5 (v3.1)High
CVE-2026-32820dataCycle Public Markdown Path Traversal Via /docs/*pathdataCycle-CORE7.5 (v3.1)High
CVE-2026-34239Chamilo Authenticated Remote Code Executionchamilo-lms7.5 (v4.0)High
CVE-2026-36783Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to Denial of Service Vulnerability-7.5 (v3.1)High
CVE-2026-36796Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to Denial of Service Vulnerability-7.5 (v3.1)High
CVE-2026-39847Emmett has a path traversal in internal assets handleremmett7.5 (v3.1)High
CVE-2026-46581mojarra Path Traversal Vulnerabilitymojarra7.5 (v3.1)High
CVE-2026-50776Pronis Loisirs Billetterie CSE - < 04/2026 Arbitrary Code Execution VulnerabilityPronis Loisirs Billetterie CSE - < 04/20267.5 (v3.1)High
CVE-2026-53599Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mocore7.5 (v3.1)High
CVE-2026-54293NLTK: URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Readnltk7.5 (v3.1)High
CVE-2026-5487DriveLock Directory Traversal Information Disclosure VulnerabilityDriveLock7.5 (v3.0)High
CVE-2026-5491DriveLock Directory Traversal Information Disclosure VulnerabilityDriveLock7.5 (v3.0)High
CVE-2026-55552Yamcs: Unauthenticated Directory Traversalyamcs7.5 (v3.1)High
CVE-2026-56671ComfyUI: Path traversal in /experiment/models/preview allows arbitrary image file readComfyUI7.5 (v3.1)High
CVE-2026-61891theia Exposure of Sensitive Information to an Unauthorized Actor Vulnerabilitytheia7.5 (v3.1)High
CVE-2026-71209audiobookshelf - %2F Encoding Discrepancy Bypasses Cover/Image Auth Exemption Regex, Enabling Unauthenticated Path Traveaudiobookshelf7.5 (v3.1)High
CVE-2026-75328In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java Path Traversal VulnerabilityIn DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java7.5 (v3.1)High
CVE-2026-75333yx-image-recognition v1.0 Path Traversal Vulnerability-7.5 (v3.1)High
CVE-2026-19771Baicells EG3661M LuCI Web luci os command injectionEG3661M7.3 (v4.0)High
CVE-2026-20297Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprisesplunk7.2 (v3.1)High
CVE-2026-27891Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanismfacturascripts7.2 (v3.1)High
CVE-2026-34607Emlog: Path Traversal in emUnZip() allows arbitrary file write leading to RCEemlog7.2 (v3.1)High
CVE-2026-35174Chyrp Lite has a Path Traversal to Remote Code Executionchyrp lite7.2 (v3.1)High
CVE-2026-3576Planyo Online Reservation System <= 3.0 - Arbitrary File ReadPlanyo online reservation system7.2 (v3.1)High
CVE-2026-39387BoidCMS: Local File Inclusion (LFI) leads to Remote Code Execution (RCE) via tpl parameterboidcms7.2 (v3.1)High
CVE-2026-85160AVideo through c91b5975d CSRF and Path Traversal via stopLive.phpAVideo7.2 (v4.0)High
CVE-2018-25393Navigate CMS 2.8.5 Path Traversal via navigate_download.phpNavigate CMS7.1 (v4.0)High
CVE-2018-25421Open STA Manager 2.3 Arbitrary File Download via Path TraversalOpen STA Manager7.1 (v4.0)High
CVE-2019-25246BEWARD N100 H.264 VGA IP Camera M2.1.6 - Arbitrary File DisclosureN100 H.264 VGA IP Camera7.1 (v4.0)High
CVE-2026-22664prompts.chat SSRF via Fal.ai Media Status Pollingprompts.chat7.1 (v4.0)High
CVE-2026-40526Volmarg Personal Management System Path Traversal via get-file Endpointpersonal-management-system7.1 (v4.0)High
CVE-2026-45725compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversalcompliance-trestle7.1 (v4.0)High
CVE-2026-46555WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltrationwhatsapp mcp server7.1 (v3.1)High
CVE-2026-64826rConfig < 8.2.13 Path Traversal File Read via FileDownloadControllerrConfig7.1 (v4.0)High
CVE-2026-75844ArcadeDB before 26.8.1 SSRF via IMPORT DATABASE validator bypassarcadedb7.1 (v4.0)High
CVE-2026-76210phpMyFAQ before v4.1.6 Local File Disclosure via PDF Exportphpmyfaq7.1 (v4.0)High
CVE-2026-79747MCPHub vulnerable to SSRF: a non-admin user can make mcphub request arbitrary URLs and read the response (OpenAPI proxymcphub7.1 (v3.1)High
CVE-2026-81030Mage AI through 0.9.79 Arbitrary File Read via Unvalidated Path in browser_items Endpointmage-ai7.1 (v4.0)High
CVE-2026-85164WWBN AVideo Server-Side Request Forgery via set_api_userImagesAVideo7.1 (v4.0)High
CVE-2026-10107MoviePilot v2 SSRF via /api/v1/system/img/{proxy} EndpointMoviePilot7.0 (v4.0)High
CVE-2026-40506OpenEMR Path Traversal Arbitrary Directory Deletion via standard_tables_manage.phpopenemr7.0 (v4.0)High
CVE-2026-54134OctoPrint: File exfiltration possible via query parameters on upload endpointsOctoPrint7.0 (v4.0)High
CVE-2026-73033Sucuri WordPress Plugin 2.7.3 Path Traversal via integrity.lib.phpsucuri-wordpress-plugin7.0 (v4.0)High
CVE-2019-25760Joomla! Component Easy Shop 1.2.3 Local File Inclusioneasy shop6.9 (v4.0)Medium
CVE-2022-50954WordPress Plugin cab-fare-calculator 1.0.3 Local File Inclusioncab-fare-calculator6.9 (v4.0)Medium
CVE-2022-50956WordPress Plugin amministrazione-aperta 3.7.3 Local File Readamministrazione-aperta6.9 (v4.0)Medium
CVE-2024-12987DrayTek Vigor - Command InjectionVigor300B6.9 (v4.0)Medium
CVE-2025-1743Pichome 2.1.0 - Arbitrary File ReadPichome6.9 (v4.0)Medium
CVE-2026-19983GL.iNet XE3000 NAS Command Service gl_nas_sys os command injectionA13006.9 (v4.0)Medium
CVE-2026-23483Blinko <= 1.8.3 - Path Traversal via /pluginsblinko6.9 (v4.0)Medium
CVE-2026-29059Windmill/Nextcloud Flow < 1.603.3 - Unauthenticated Path Traversalwindmill6.9 (v4.0)Medium
CVE-2026-34964Adminer before 5.5.0 SSRF via PDO DSN Injectionadminer6.9 (v4.0)Medium
CVE-2026-41917OpenKM 6.3.12 Local File Inclusion via Admin ScriptingOpenKM Community Edition6.9 (v4.0)Medium
CVE-2026-44652SillyTavern: SSRF vulnerability in the CORS proxy middlewareSillyTavern6.9 (v4.0)Medium
CVE-2026-45774compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversalcompliance-trestle6.9 (v4.0)Medium
CVE-2026-46337WWBN AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in view/img/image404Raw.phpavideo6.9 (v4.0)Medium
CVE-2026-54885Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri fetchingboruta6.9 (v4.0)Medium
CVE-2026-59809SiYuan before v3.8.0 Secret Exfiltration via http_request URLsiyuan6.9 (v4.0)Medium
CVE-2026-71932DrayTek VigorSwitch Multiple Models Path Traversal via getSyslogFileVigorSwitch G2540xs6.9 (v4.0)Medium
CVE-2026-73058stoatchat before 0.15.0 SSRF via IPv6 unspecified address bypassstoatchat6.9 (v4.0)Medium
CVE-2026-74235GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Configuration Download HandlerGFI Exinda AI6.9 (v4.0)Medium
CVE-2026-75592Kirby: Access to image files outside of the site root via path traversal in the media handlingkirby6.9 (v4.0)Medium
CVE-2026-79743MCPHub: Path Traversal via Malicious MCPB Manifest Namemcphub6.9 (v4.0)Medium
CVE-2026-79773Winter CMS before 1.2.13 Local File Inclusion via JavaScriptwinter6.9 (v4.0)Medium
CVE-2026-79781rclone serve s3 Path Traversal via dot-dot object keysrclone6.9 (v4.0)Medium
CVE-2026-81678AVideo SSRF Guard Bypass via IPv6 Transition AddressesAVideo6.9 (v4.0)Medium
CVE-2026-85609Openpanel before 2.3.0 SSRF via Site Checker Endpointopenpanel6.9 (v4.0)Medium
CVE-2026-86806opengeos GeoLibre _is_within_roots server-side request forgeryGeoLibre6.9 (v4.0)Medium
CVE-2026-8712Wyoming < 1.10.2 SSRF via uri Query Parameterwyoming6.9 (v4.0)Medium
CVE-2026-88940knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpointknowns6.9 (v4.0)Medium
CVE-2008-2650CMSimple 3.1 - Local File Inclusioncmsimple6.8 (v2.0)Medium
CVE-2008-6172Joomla! Component RWCards 3.0.11 - Local File Inclusionrwcards6.8 (v2.0)Medium
CVE-2009-3053Joomla! Agora 3.0.0b - Local File InclusionJoomla!6.8 (v2.0)Medium
CVE-2010-1056Joomla! Component com_rokdownloads - Local File Inclusioncom rokdownloads6.8 (v2.0)Medium
CVE-2010-1219Joomla! Component com_janews - Local File Inclusioncom janews6.8 (v2.0)Medium
CVE-2010-1469Joomla! Component JProject Manager 1.0 - Local File Inclusioncom jprojectmanager6.8 (v2.0)Medium
CVE-2010-1473Joomla! Component Advertising 0.25 - Local File Inclusioncom advertising6.8 (v2.0)Medium
CVE-2010-1474Joomla! Component Sweetykeeper 1.5 - Local File Inclusioncom sweetykeeper6.8 (v2.0)Medium
CVE-2010-1475Joomla! Component Preventive And Reservation 1.0.5 - Local File Inclusioncom preventive6.8 (v2.0)Medium
CVE-2010-1476Joomla! Component AlphaUserPoints 1.5.5 - Local File Inclusioncom alphauserpoints6.8 (v2.0)Medium
CVE-2010-1478Joomla! Component Jfeedback 1.2 - Local File Inclusioncom jfeedback6.8 (v2.0)Medium
CVE-2010-1607Joomla! Component WMI 1.5.0 - Local File Inclusioncom wmi6.8 (v2.0)Medium
CVE-2010-1715Joomla! Component Online Exam 1.5.0 - Local File Inclusioncom onlineexam6.8 (v2.0)Medium
CVE-2010-1718Joomla! Component Archery Scores 1.0.6 - Local File Inclusioncom archeryscores6.8 (v2.0)Medium
CVE-2010-1719Joomla! Component MT Fire Eagle 1.2 - Local File Inclusioncom mtfireeagle6.8 (v2.0)Medium
CVE-2010-1722Joomla! Component Online Market 2.x - Local File Inclusioncom market6.8 (v2.0)Medium
CVE-2010-1723Joomla! Component iNetLanka Contact Us Draw Root Map 1.1 - Local File Inclusioncom drawroot6.8 (v2.0)Medium
CVE-2010-1979Joomla! Component Affiliate Datafeeds 880 - Local File Inclusioncom datafeeds6.8 (v2.0)Medium
CVE-2010-1981Joomla! Component Fabrik 2.0 - Local File Inclusionfabrik6.8 (v2.0)Medium
CVE-2010-2122Joomla! Component simpledownload <=0.9.5 - Arbitrary File Retrievalcom simpledownload6.8 (v2.0)Medium
CVE-2010-2507Joomla! Component Picasa2Gallery 1.2.8 - Local File Inclusioncom picasa2gallery6.8 (v2.0)Medium
CVE-2010-2680Joomla! Component jesectionfinder - Local File Inclusioncom jesectionfinder6.8 (v2.0)Medium
CVE-2010-2857Joomla! Component Music Manager - Local File Inclusioncom music6.8 (v2.0)Medium
CVE-2010-2920Joomla! Component Foobla Suggestions 1.5.1.2 - Local File Inclusioncom foobla suggestions6.8 (v2.0)Medium
CVE-2010-4617Joomla! Component JotLoader 2.2.1 - Local File Inclusioncom jotloader6.8 (v2.0)Medium
CVE-2011-2744Chyrp 2.x - Local File Inclusionchyrp6.8 (v2.0)Medium
CVE-2012-0392Apache Struts2 S2-008 RCEstruts6.8 (v2.0)Medium
CVE-2014-2383Dompdf < v0.6.0 - Local File Inclusiondompdf6.8 (v2.0)Medium
CVE-2026-71475Insights-client-rhel9: insights-client: spoke-controlled clusterid injected unencoded into insights api url pathadvanced cluster management for kubernetes6.8 (v3.1)Medium
CVE-2016-6435Cisco Firepower Threat Management Console 6.0.1 - Local File Inclusionsecure firewall management center6.5 (v3.0)Medium
CVE-2017-14537Trixbox 2.8.0 - Path Traversaltrixbox6.5 (v3.1)Medium
CVE-2017-9416Odoo 8.0/9.0/10.0 - Local File Inclusionodoo6.5 (v3.0)Medium
CVE-2018-3714node-srv - Local File Inclusionnode-srv6.5 (v3.1)Medium
CVE-2019-11013Nimble Streamer <=3.5.4-9 - Local File Inclusionnimble streamer6.5 (v3.0)Medium
CVE-2019-14312Aptana Jaxer 1.0.3.4547 - Local File inclusionjaxer6.5 (v3.0)Medium
CVE-2019-3799Spring Cloud Config Server - Local File Inclusionspring cloud config6.5 (v3.1)Medium
CVE-2021-24947WordPress Responsive Vector Maps < 6.4.2 - Arbitrary File Readresponsive vector maps6.5 (v3.1)Medium
CVE-2021-28149Hongdian H8922 3.0.5 Devices - Local File Inclusionh8922 firmware6.5 (v3.1)Medium
CVE-2021-29006rConfig 3.9.6 - Local File Inclusionrconfig6.5 (v3.1)Medium
CVE-2021-40651OS4Ed OpenSIS Community 8.0 - Local File Inclusionopensis6.5 (v3.1)Medium
CVE-2022-37299Shirne CMS 1.2.0 - Local File Inclusionshirne cms6.5 (v3.1)Medium
CVE-2024-27564ChatGPT个人专用版 - Server Side Request Forgerychatgpt web6.5 (v3.1)Medium
CVE-2024-36527Puppeteer Renderer - Directory Traversal-6.5 (v3.1)Medium
CVE-2024-55457MasterSAM Star Gate v11 - Local File Inclusion-6.5 (v3.1)Medium
CVE-2024-9765EKC Tournament Manager WordPress plugin - Path Traversalekc tournament manager6.5 (v3.1)Medium
CVE-2025-45870LogicalDOC Enterprise up to and for v9.1.1 Path Traversal Vulnerability-6.5 (v3.1)Medium
CVE-2026-11442Allegra exportReport Directory Traversal Information Disclosure VulnerabilityAllegra6.5 (v3.0)Medium
CVE-2026-14470Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base componelangflow6.5 (v3.1)Medium
CVE-2026-15974sglang Server-Side Request Forgery Vulnerabilitysglang6.5 (v3.1)Medium
CVE-2026-34787Emlog: Local File Inclusion in plugin.php via unsanitized plugin parameteremlog6.5 (v3.1)Medium
CVE-2026-35718fd8136 firmware Path Traversal Vulnerabilityfd8136 firmware6.5 (v3.1)Medium
CVE-2026-52607reportico-web <= 8.1.0 Path Traversal Vulnerabilityreportico-web <= 8.1.06.5 (v3.1)Medium
CVE-2026-73255Mongoose: Path traversal in SSI #include directives enables arbitrary file readmongoose6.5 (v3.1)Medium
CVE-2026-73573zimbra collaboration suite Path Traversal Vulnerabilityzimbra collaboration suite6.5 (v3.1)Medium
CVE-2026-73574zimbra collaboration suite Incorrect Resource Transfer Between Spheres Vulnerabilityzimbra collaboration suite6.5 (v3.1)Medium
CVE-2026-7646Langflow is affected by security vulnerabilities in Model Context Protocol featureslangflow6.5 (v3.1)Medium
CVE-2026-39365Vite has a Path Traversal in Optimized Deps .map Handlingvite6.3 (v4.0)Medium
CVE-2026-42335MaxKB: SSRF Bypass in MaxKB OSS URL Fetch due to URL Parsing DiscrepancyMaxKB6.3 (v4.0)Medium
CVE-2026-42344FastGPT: DNS rebinding TOCTOU bypass in isInternalAddress allows SSRF on all protected endpointsFastGPT6.3 (v3.1)Medium
CVE-2026-45626Arcane: OS Command Injection in Volume Browser ListDirectory via path query parameterarcane6.3 (v3.1)Medium
CVE-2026-54020Open WebUI: DNS Rebinding SSRF Bypassopen-webui6.3 (v3.1)Medium
CVE-2026-63107LimeSurvey SSRF via REST API Survey Template Host HeaderLimeSurvey6.3 (v4.0)Medium
CVE-2026-65012InvokeAI < 6.13.7 Unauthenticated Directory Enumeration via scan_folderInvokeAI6.3 (v4.0)Medium
CVE-2026-67620Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-Listflowise6.3 (v4.0)Medium
CVE-2026-72814actix-web before 0.6.10 Information Disclosure via Filesactix-web6.3 (v4.0)Medium
CVE-2026-73530Flyto2 Core < 2.28.0 SSRF Guard Bypass via is_private_ip()flyto-core6.3 (v4.0)Medium
CVE-2026-78886liketrek TREK Public Journey Photo Proxy journey-public.controller.ts path traversalTREK6.3 (v4.0)Medium
CVE-2026-29066TinaCMS - Path Traversaltinacms6.2 (v3.1)Medium
CVE-2026-41363OpenClaw 2026.2.6 < 2026.3.28 - Arbitrary File Read via Feishu upload_image Parameteropenclaw6.0 (v4.0)Medium
CVE-2026-65698Void 1.3.4 Path Traversal via AI Agent File-Reading Toolsvoid6.0 (v4.0)Medium
CVE-2026-66004BlenderMCP Path Traversal via download_polyhaven_asset APIblender-mcp6.0 (v4.0)Medium
CVE-2025-41242Spring Framework - Path TraversalSpring Framework5.9 (v3.1)Medium
CVE-2026-49244SFTPGo: Path confinement bypass in public browsable share partial ZIP downloadsftpgo5.9 (v3.1)Medium
CVE-2010-0467Joomla! Component CCNewsLetter - Local File Inclusioncom ccnewsletter5.8 (v3.1)Medium
CVE-2026-10526EmbedPress < 4.6.1 - Unauthenticated Blind SSRFEmbedPress5.8 (v3.1)Medium
CVE-2026-45709Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filtemailpit5.8 (v3.1)Medium
CVE-2026-48053Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewsetkolibri5.8 (v3.1)Medium
CVE-2026-73243kkFileView: Unauthenticated SSRF via /addTask with fullfilename type-confusion bypasskkFileView5.8 (v3.1)Medium
CVE-2025-1035KLog Server - Path TraversalKLog Server5.7 (v3.1)Medium
CVE-2026-40605Tautulli Vulnerable to Authenticated Path Traversal in Cache Deletion APITautulli5.7 (v4.0)Medium
CVE-2018-13980Zeta Producer Desktop CMS <14.2.1 - Local File Inclusionzeta producer5.5 (v3.1)Medium
CVE-2018-15536Responsive FileManager < 9.13.4 - Directory Traversalresponsive filemanager5.5 (v3.0)Medium
CVE-2025-13786taosir WTCMS index.php fetch code injectionwtcms5.5 (v4.0)Medium
CVE-2025-13792Qualitor getResumo.php eval code injectionthe file /html/st/stdeslocamento/request/getResumo.php5.5 (v4.0)Medium
CVE-2025-13810jsnjfz WebStack-Guns KaptchaController.java renderPicture path traversalwebstack-guns5.5 (v4.0)Medium
CVE-2026-10694SourceCodester Online Food Ordering System index.php include file inclusionOnline Food Ordering System5.5 (v4.0)Medium
CVE-2026-16252Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System Staffshinel Ds.jsp sql injectionMultimedia Integrated Business Display System5.5 (v4.0)Medium
CVE-2026-18646danpros HTMLy Author Name htmly.php path traversalHTMLy5.5 (v4.0)Medium
CVE-2026-18973heshengtao super-agent-party extension_proxy Route server.py sanitize_proxy_url server-side request forgerysuper-agent-party5.5 (v4.0)Medium
CVE-2026-19379EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injectionipTIME AX8004M5.5 (v4.0)Medium
CVE-2026-19753Model Context Protocol mcp-rdf-explorer MCP Server server.py explore_url server-side request forgerymcp-rdf-explorer5.5 (v4.0)Medium
CVE-2026-19827alldatacenter alldata logDetailCat Endpoint JobLogController.java FileInputStream path traversalalldata5.5 (v4.0)Medium
CVE-2026-54611InstantCMS has Remote Code Execution in package installericms25.5 (v3.1)Medium
CVE-2026-68922MobSF: Arbitrary File Read via Path Traversal in ZIP UploadsMobile-Security-Framework-MobSF5.5 (v3.1)Medium
CVE-2026-7178ChatGPTNextWeb NextChat Artifacts Endpoint route.ts storeUrl server-side request forgerynextchat5.5 (v4.0)Medium
CVE-2026-7221TencentCloudBase CloudBase-MCP open-url API Endpoint interactive-server.ts openUrl server-side request forgeryCloudBase-MCP5.5 (v4.0)Medium
CVE-2026-76795AeternaLabsHQ PullMD REST API Endpoint api server-side request forgeryPullMD5.5 (v4.0)Medium
CVE-2026-82598SeaCMS Template search.php parseIf code injectionSeaCMS5.5 (v4.0)Medium
CVE-2026-82801NASA earthdata-search scale Endpoint handler.js scaleImage server-side request forgeryearthdata-search5.5 (v4.0)Medium
CVE-2026-84441Piwigo Image Derivative i.php path traversalPiwigo5.5 (v4.0)Medium
CVE-2026-85380light0011 cms UEditor controller.php catchimage server-side request forgerycms5.5 (v4.0)Medium
CVE-2026-9474yashpokharna2555 StudentManagementSystem studentdel.php confirm_logged_in sql injectionStudentManagementSystem5.5 (v4.0)Medium
CVE-2026-17621Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base componelangflow5.4 (v3.1)Medium
CVE-2026-48483TypeBot's WhatsApp status forwarding uses unvalidated user-controlled URLs, allowing SSRF from the Typebot servertypebot.io5.4 (v3.1)Medium
CVE-2026-7798FluentCRM <= 2.9.87 - Unauthenticated Blind Server-Side Request Forgery via 'SubscribeURL' ParameterFluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution5.4 (v3.1)Medium
CVE-2014-8676SO Planning 1.32 - Multiple Vulnerabilitiessoplanning5.3 (v3.0)Medium
CVE-2014-9609Netsweeper 4.0.8 - Directory Traversalnetsweeper5.3 (v3.1)Medium
CVE-2015-5471Swim Team <= v1.44.10777 - Local File Inclusionswim team5.3 (v3.0)Medium
CVE-2020-11798Mitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory Traversalmicollab audio, web &amp; video conferencing5.3 (v3.1)Medium
CVE-2020-13886Intelbras TIP 200/200 LITE/300 - Local File Inclusiontip200 firmware5.3 (v3.1)Medium
CVE-2021-23241MERCUSYS Mercury X18G 1.0.5 Router - Local File Inclusionmercury x18g firmware5.3 (v3.1)Medium
CVE-2021-28377Joomla! ChronoForums 2.0.11 - Local File Inclusionchronoforums5.3 (v3.1)Medium
CVE-2023-41599JFinalCMS v5.0.0 - Directory Traversaljfinalcms5.3 (v3.1)Medium
CVE-2023-7299DataGear resolveSql sql injectiondatagear5.3 (v4.0)Medium
CVE-2025-31486Vite server.fs.deny Bypass - Local File Inclusionvite5.3 (v3.1)Medium
CVE-2025-4078Wangshen SecGate 3600 Path Traversal VulnerabilitySecGate 36005.3 (v4.0)Medium
CVE-2026-15932Support Genix Lite < 1.4.48 - Unauthenticated Arbitrary File Read via Path TraversalSupport Genix5.3 (v3.1)Medium
CVE-2026-16536Simple Google Calendar Outlook Events Widget < 3.1.0 - Unauthenticated SSRF via calendar_idSimple Google Calendar Outlook Events Widget5.3 (v3.1)Medium
CVE-2026-19785francoisjacquet RosarioSIS Student Medical Medical.inc.php sql injectionRosarioSIS5.3 (v4.0)Medium
CVE-2026-34523SillyTavern: Path traversal allows file existence oraclesillytavern5.3 (v3.1)Medium
CVE-2026-34967Adminer sql-log Plugin 5.3.0 through 5.4.2 Arbitrary File Writeadminer5.3 (v4.0)Medium
CVE-2026-36726bookcars v8.3 Path Traversal Vulnerabilitybookcars v8.35.3 (v3.1)Medium
CVE-2026-44583Paymenter: Blind Unauthenticated SSRF on the Paypal gateway modulePaymenter5.3 (v3.1)Medium
CVE-2026-49138Nanobot < 0.2.1 SSRF via web_fetch Tool Redirect Followingnanobot5.3 (v4.0)Medium
CVE-2026-54508TREK: Blind SSRF via unvalidated redirect-following in Google/Naver list import and Maps URL resolutionTREK5.3 (v4.0)Medium
CVE-2026-59231Server-Side Request Forgery in Pentestify PDF export via unvalidated image URLsPentestify5.3 (v4.0)Medium
CVE-2026-63730HyperDX < 2.31.0 SSRF via Webhook Test Endpointhyperdx5.3 (v4.0)Medium
CVE-2026-64626AVideo Encoder downloadURL SSRF via unpinned retry fallbackAVideo5.3 (v4.0)Medium
CVE-2026-74858jae-jae fetcher-mcp URL Validation security-credentials fetch_urls server-side request forgeryfetcher-mcp5.3 (v4.0)Medium
CVE-2026-89247WWBN AVideo XML Injection via plugin/AD_Server/VMAP.phpAVideo5.3 (v4.0)Medium
CVE-2026-19761DTStack Taier Upload Controller UploadController.java MultipartFile.getOriginalFilename path traversalTaier5.1 (v4.0)Medium
CVE-2026-19763DTStack Taier Cluster Creation ClusterController.java FileUtils.deleteDirectory path traversalTaier5.1 (v4.0)Medium
CVE-2026-42336MaxKB: SSRF Bypass via DNS Rebinding in MaxKB OSS URL FetchMaxKB5.1 (v4.0)Medium
CVE-2026-63302Local File Inclusion in Quick.CMSQuick.CMS5.1 (v4.0)Medium
CVE-2006-3392Webmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosurewebmin5.0 (v2.0)Medium
CVE-2007-4504Joomla! RSfiles <=1.0.2 - Local File Inclusionrsfiles5.0 (v2.0)Medium
CVE-2008-4764Joomla! <=2.0.0 RC2 - Local File Inclusioncom extplorer5.0 (v2.0)Medium
CVE-2008-6080Joomla! ionFiles 4.4.2 - Local File Inclusioncom ionfiles5.0 (v2.0)Medium
CVE-2008-6222Joomla! ProDesk 1.0/1.2 - Local File Inclusionpro desk support center5.0 (v2.0)Medium
CVE-2008-6668nweb2fax <=0.2.7 - Local File Inclusionnweb2fax5.0 (v2.0)Medium
CVE-2009-1496Joomla! Cmimarketplace 0.1 - Local File InclusionJoomla!5.0 (v2.0)Medium
CVE-2009-2100Joomla! JoomlaPraise Projectfork 2.0.10 - Local File InclusionJoomla!5.0 (v2.0)Medium
CVE-2009-5114WebGlimpse 2.18.7 - Directory Traversalwebglimpse5.0 (v2.0)Medium
CVE-2010-0696Joomla! Component Jw_allVideos - Arbitrary File Retrievaljw allvideos5.0 (v2.0)Medium
CVE-2010-0942Joomla! Component com_jvideodirect - Directory Traversalcom jvideodirect5.0 (v2.0)Medium
CVE-2010-0943Joomla! Component com_jashowcase - Directory Traversalcom jashowcase5.0 (v2.0)Medium
CVE-2010-0944Joomla! Component com_jcollection - Directory Traversalcom jcollection5.0 (v2.0)Medium
CVE-2010-1081Joomla! Component com_communitypolls 1.5.2 - Local File Inclusioncom communitypolls5.0 (v2.0)Medium
CVE-2010-1302Joomla! Component DW Graph - Local File Inclusioncom dwgraphs5.0 (v2.0)Medium
CVE-2010-1304Joomla! Component User Status - Local File Inclusioncom userstatus5.0 (v2.0)Medium
CVE-2010-1305Joomla! Component JInventory 1.23.02 - Local File Inclusioncom jinventory5.0 (v2.0)Medium
CVE-2010-1307Joomla! Component Magic Updater - Local File Inclusioncom joomlaupdater5.0 (v2.0)Medium
CVE-2010-1308Joomla! Component SVMap 1.1.1 - Local File Inclusioncom svmap5.0 (v2.0)Medium
CVE-2010-1312Joomla! Component News Portal 1.5.x - Local File Inclusioncom news portal5.0 (v2.0)Medium
CVE-2010-1314Joomla! Component Highslide 1.5 - Local File Inclusioncom hsconfig5.0 (v2.0)Medium
CVE-2010-1315Joomla! Component webERPcustomer - Local File Inclusioncom weberpcustomer5.0 (v2.0)Medium
CVE-2010-1340Joomla! Component com_jresearch - 'Controller' Local File Inclusioncom jresearch5.0 (v2.0)Medium
CVE-2010-1345Joomla! Component Cookex Agency CKForms - Local File Inclusioncom ckforms5.0 (v2.0)Medium
CVE-2010-1352Joomla! Component Juke Box 1.7 - Local File Inclusioncom jukebox5.0 (v2.0)Medium
CVE-2010-1353Joomla! Component LoginBox - Local File Inclusioncom loginbox5.0 (v2.0)Medium
CVE-2010-1354Joomla! Component VJDEO 1.0 - Local File Inclusioncom vjdeo5.0 (v2.0)Medium
CVE-2010-1461Joomla! Component Photo Battle 1.0.1 - Local File Inclusioncom photobattle5.0 (v2.0)Medium
CVE-2010-1491Joomla! Component MMS Blog 2.3.0 - Local File Inclusioncom mmsblog5.0 (v2.0)Medium
CVE-2010-1494Joomla! Component AWDwall 1.5.4 - Local File Inclusioncom awdwall5.0 (v2.0)Medium
CVE-2010-1532Joomla! Component PowerMail Pro 1.5.3 - Local File Inclusioncom powermail5.0 (v2.0)Medium
CVE-2010-1534Joomla! Component Shoutbox Pro - Local File Inclusioncom shoutbox5.0 (v2.0)Medium
CVE-2010-1540Joomla! Component com_blog - Directory Traversalcom myblog5.0 (v2.0)Medium
CVE-2010-1601Joomla! Component JA Comment - Local File Inclusioncom jacomment5.0 (v2.0)Medium
CVE-2010-1657Joomla! Component SmartSite 1.0.0 - Local File Inclusioncom smartsite5.0 (v2.0)Medium
CVE-2010-1658Joomla! Component NoticeBoard 1.3 - Local File Inclusioncom noticeboard5.0 (v2.0)Medium
CVE-2010-1659Joomla! Component Ultimate Portfolio 1.0 - Local File Inclusioncom ultimateportfolio5.0 (v2.0)Medium
CVE-2010-1714Joomla! Component Arcade Games 1.0 - Local File Inclusioncom arcadegames5.0 (v2.0)Medium
CVE-2010-1858Joomla! Component SMEStorage - Local File Inclusioncom smestorage5.0 (v2.0)Medium
CVE-2010-1982Joomla! Component JA Voice 2.0 - Local File Inclusioncom javoice5.0 (v2.0)Medium
CVE-2010-2018Lokomedia CMS - Local File Inclusionlokomedia cms5.0 (v2.0)Medium
CVE-2010-2307Motorola SBV6120E SURFboard Digital Voice Modem SBV6X2X-1.0.0.5-SCM - Directory Traversalsurfboard sbv6120e5.0 (v2.0)Medium
CVE-2011-0049Majordomo2 - SMTP/HTTP Directory Traversalmajordomo 25.0 (v2.0)Medium
CVE-2011-1669WP Custom Pages 0.5.0.1 - Local File Inclusion (LFI)wp custom pages5.0 (v2.0)Medium
CVE-2011-2780Chyrp 2.x - Local File Inclusionchyrp5.0 (v2.0)Medium
CVE-2011-4804Joomla! Component com_kp - 'Controller' Local File Inclusioncom obsuggest5.0 (v2.0)Medium
CVE-2012-0896Count Per Day <= 3.1 - download.php f Parameter Traversal Arbitrary File Accesscount per day5.0 (v2.0)Medium
CVE-2012-0981phpShowtime 2.0 - Directory Traversalphpshowtime5.0 (v2.0)Medium
CVE-2012-099611in1 CMS 1.2.1 - Local File Inclusion (LFI)11in15.0 (v2.0)Medium
CVE-2013-5979Xibo 1.2.2/1.4.1 - Directory Traversalxibo5.0 (v2.0)Medium
CVE-2013-7091Zimbra Collaboration Server 7.2.2/8.0.2 Local File Inclusionzimbra collaboration suite5.0 (v2.0)Medium
CVE-2014-4577WP AmASIN – The Amazon Affiliate Shop - Local File Inclusionwp amasin - the amazon affiliate shop5.0 (v2.0)Medium
CVE-2014-4940WordPress Plugin Tera Charts - Local File Inclusiontera-charts5.0 (v2.0)Medium
CVE-2014-4941Cross RSS 1.7 - Local File Inclusionwp-cross-rss5.0 (v2.0)Medium
CVE-2014-5111Fonality trixbox - Local File Inclusiontrixbox5.0 (v2.0)Medium
CVE-2014-5181Last.fm Rotation 1.0 - Path Traversallastfm-rotation plugin5.0 (v2.0)Medium
CVE-2014-5187Tom M8te (tom-m8te) Plugin 1.5.3 - Directory Traversaltom-m8te plugin5.0 (v2.0)Medium
CVE-2014-6308Osclass Security Advisory 3.4.1 - Local File Inclusionosclass5.0 (v2.0)Medium
CVE-2015-2067Magento Server MAGMI - Directory Traversalmagmi5.0 (v2.0)Medium
CVE-2015-2166Ericsson Drutt MSDP - Local File Inclusiondrutt mobile service delivery platform5.0 (v2.0)Medium
CVE-2015-4414WordPress SE HTML5 Album Audio Player 1.1.0 - Directory Traversalse html5 album audio player5.0 (v2.0)Medium
CVE-2015-4666Xceedium Xsuite - Multiple Vulnerabilitiesxsuite5.0 (v2.0)Medium
CVE-2015-5531ElasticSearch <1.6.1 - Local File Inclusionelasticsearch5.0 (v2.0)Medium
CVE-2015-5688Geddy <13.0.8 - Local File Inclusiongeddy5.0 (v2.0)Medium
CVE-2017-7461Intellinet NFC-30IR Camera - Multiple Vulnerabilitiesnfc-30ir firmware4.9 (v3.0)Medium
CVE-2023-34259Kyocera TASKalfa printer - Path Traversald-copia253mf plus firmware4.9 (v3.1)Medium
CVE-2026-53594FreeScout has Arbitrary File Read in App Logs Viewer via Forged Encrypted Pathfreescout4.9 (v3.1)Medium
CVE-2008-5587phpPgAdmin <=4.2.1 - Local File Inclusionphppgadmin4.3 (v2.0)Medium
CVE-2010-0982Joomla! Component com_cartweberp - Local File Inclusioncom cartweberp4.3 (v2.0)Medium
CVE-2010-1217Joomla! Component & Plugin JE Tooltip 1.0 - Local File Inclusionje form creator4.3 (v2.0)Medium
CVE-2010-1313Joomla! Component Saber Cart 1.0.0.12 - Local File Inclusioncom sebercart4.3 (v2.0)Medium
CVE-2012-4253MySQLDumper 1.24.4 - Directory Traversalmysqldumper4.3 (v2.0)Medium
CVE-2015-3337Elasticsearch - Local File Inclusionelasticsearch4.3 (v2.0)Medium
CVE-2018-18777Microstrategy Web 7 - Local File Inclusionmicrostrategy web4.3 (v3.0)Medium
CVE-2024-7631Openshift-console: openshift console: path traversalRed Hat OpenShift Container Platform 3.114.3 (v3.1)Medium
CVE-2026-26477dokuwiki Denial of Service Vulnerabilitydokuwiki4.3 (v3.1)Medium
CVE-2026-55495Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Accountcloudreve4.3 (v3.1)Medium
CVE-2026-73657Trigger.dev: Cross-tenant payload poisoning via packet write + replaytrigger.dev4.2 (v3.1)Medium
CVE-2011-4640WebTitan < 3.60 - Local File Inclusionwebtitan4.0 (v2.0)Medium
CVE-2013-5528Cisco Unified Communications Manager 7/8/9 - Directory Traversalunified communications manager4.0 (v2.0)Medium
CVE-2014-5258webEdition 6.3.8.0 - Directory Traversalwebedition cms4.0 (v2.0)Medium
CVE-2019-19411Huawei Firewall - Local File Inclusionusg95003.7 (v3.1)Low
CVE-2012-0991OpenEMR 4.1 - Local File Inclusionopenemr3.5 (v2.0)Low
CVE-2025-55523Agent-Zero 0.8.0 - 0.9.4 - Arbitrary File Downloadagent-zero3.5 (v3.1)Low
CVE-2026-55825Contao: Possible path traversal in job download URIscontao3.1 (v3.1)Low
CVE-2026-49262Aimeos Pagible CMS vulnerable to Server Side Request Forgery (SSRF) via DNS rebinding in admin proxypagible3.0 (v3.1)Low
CVE-2026-68927MobSF: SSRF port restriction bypass in assetlinks_checkMobile-Security-Framework-MobSF3.0 (v3.1)Low
CVE-2023-2252Directorist < 7.5.4 - Local File Inclusiondirectorist2.7 (v3.1)Low
CVE-2026-16434Adminer before 5.5.1 X-Forwarded-Prefix Backslash Bypassadminer2.3 (v4.0)Low
CVE-2026-73087Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcherdozzle2.3 (v4.0)Low
CVE-2026-10239JeecgBoot edit WordUtil.addImage server-side request forgeryJeecgBoot2.1 (v4.0)Low
CVE-2026-10558SourceCodester Pizzafy Ecommerce System index.php file inclusionPizzafy Ecommerce System2.1 (v4.0)Low
CVE-2026-10559SourceCodester Pizzafy Ecommerce System index.php file inclusionPizzafy Ecommerce System2.1 (v4.0)Low
CVE-2026-11408vertex-app vertex Log Viewer Endpoint LogMod.js os command injectionvertex2.1 (v4.0)Low
CVE-2026-12210universal-tool-calling-protocol python-utcp utcp-gql/utcp-websocket server-side request forgerypython-utcp2.1 (v4.0)Low
CVE-2026-16194zhayujie CowAgent web_fetch.py WebFetch.execute server-side request forgeryCowAgent2.1 (v4.0)Low
CVE-2026-16219Croogo CMS Admin File Manager FileManager.php isEditable path traversalCMS2.1 (v4.0)Low
CVE-2026-17458mf-yang openclaw-cn Browser Control HTTP API agent.act.ts clickViaPlaywright server-side request forgeryopenclaw-cn2.1 (v4.0)Low
CVE-2026-19828648540858 wvp-GB28181-pro Snapshot Endpoint PlayController.java path traversalwvp-GB28181-pro2.1 (v4.0)Low
CVE-2026-19829648540858 wvp-GB28181-pro Log File Download Endpoint LogController.java path traversalwvp-GB28181-pro2.1 (v4.0)Low
CVE-2026-19927OpenBoxes Product Upload Endpoint ProductController.groovy upload server-side request forgeryOpenBoxes2.1 (v4.0)Low
CVE-2026-5803bigsk1 openai-realtime-ui API Proxy Endpoint server.js server-side request forgeryopenai-realtime-ui2.1 (v4.0)Low
CVE-2026-74842Kira-Pgr PromptShopMCP Image-Toolkit-MCP-Server server.py download_image server-side request forgeryPromptShopMCP2.1 (v4.0)Low
CVE-2026-76576yangzongzhuan RuoYi-Vue Common Download Endpoint CommonController.java resourceDownload path traversalRuoYi-Vue2.1 (v4.0)Low
CVE-2026-8191Wavlink NU516U1 adm.cgi wifi_region os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-82599SeaCMS Avatar Upload member.php unlink path traversalSeaCMS2.1 (v4.0)Low
CVE-2026-82603SeaCMS Comment Cache member.php del_pl path traversalSeaCMS2.1 (v4.0)Low
CVE-2026-83744invoiceninja Invoice Ninja invoices Endpoint Purify.php isHostSafe server-side request forgeryInvoice Ninja2.1 (v4.0)Low
CVE-2026-12211Intelbras iNVU 7016 FT Web syslog path traversaliNVU 7016 FT2.0 (v4.0)Low
CVE-2026-16088halo-dev halo Files Backup Endpoint MigrationEndpoint.java download path traversalhalo2.0 (v4.0)Low
CVE-2026-18856Poesis Rhymix CMS Data Import importer.admin.controller.php procImporterAdminCheckXmlFile server-side request forgeryRhymix CMS2.0 (v4.0)Low
CVE-2026-78435Faveo Helpdesk Logo SettingsController.php unlink path traversalHelpdesk2.0 (v4.0)Low
CVE-2026-81835RooCodeInc Roo-Code MCP Integration Trust Model malicious_mcp_server.py fetch_instructions code injectionRoo-Code2.0 (v4.0)Low
CVE-2026-82678diem-project diem Administrative Console actions.class.php executeCommand os command injectiondiem2.0 (v4.0)Low
CVE-2026-86240liufee FeehiCMS UEditor Uploader.php catchImage server-side request forgeryFeehiCMS2.0 (v4.0)Low

Observed CWEs

These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.

CWERelated Published CVEs
CWE-20CVE-2009-0545 , CVE-2017-12611 , CVE-2026-44343 , CVE-2024-7340 , CVE-2026-34197 , CVE-2025-34115 , CVE-2026-73658 , CVE-2024-30188 , CVE-2026-69192 , CVE-2016-10956 , CVE-2026-27891 , CVE-2026-3576 , CVE-2026-16434
CWE-22CVE-2010-5286 , CVE-2019-11510 , CVE-2010-2861 , CVE-2017-7462 , CVE-2018-12031 , CVE-2018-14064 , CVE-2018-16283 , CVE-2018-16836 , CVE-2019-12314 , CVE-2019-9618 , CVE-2020-11455 , CVE-2020-5902 , CVE-2021-40960 , CVE-2021-41773 , CVE-2021-42013 , CVE-2022-1390 , CVE-2022-1391 , CVE-2022-32409 , CVE-2022-41840 , CVE-2023-5991 , CVE-2023-6623 , CVE-2025-2294 , CVE-2026-35471 , CVE-2026-75337 , CVE-2026-72850 , CVE-2026-77086 , CVE-2019-25727 , CVE-2024-27954 , CVE-2026-45668 , CVE-2026-47754 , CVE-2026-53976 , CVE-2026-65700 , CVE-2026-69110 , CVE-2018-16716 , CVE-2018-19365 , CVE-2022-26960 , CVE-2024-40422 , CVE-2025-55526 , CVE-2026-52610 , CVE-2008-4668 , CVE-2019-14530 , CVE-2020-8641 , CVE-2024-7340 , CVE-2026-42605 , CVE-2026-50186 , CVE-2026-76842 , CVE-2017-20248 , CVE-2017-20250 , CVE-2018-25374 , CVE-2021-4463 , CVE-2024-11303 , CVE-2025-34031 , CVE-2026-10108 , CVE-2026-17524 , CVE-2026-25559 , CVE-2026-47659 , CVE-2026-47661 , CVE-2026-64838 , CVE-2026-65694 , CVE-2026-65919 , CVE-2026-67200 , CVE-2026-67281 , CVE-2026-69089 , CVE-2026-69095 , CVE-2026-75111 , CVE-2026-75482 , CVE-2026-85685 , CVE-2026-9506 , CVE-2015-4694 , CVE-2022-24900 , CVE-2026-30958 , CVE-2026-46491 , CVE-2026-54650 , CVE-2015-2996 , CVE-2025-34023 , CVE-2026-73079 , CVE-2026-76844 , CVE-2024-40348 , CVE-2025-44137 , CVE-2025-44177 , CVE-2026-23482 , CVE-2026-40075 , CVE-2026-48126 , CVE-2026-73658 , CVE-2026-74907 , CVE-2026-19303 , CVE-2026-33236 , CVE-2026-46484 , CVE-2026-73659 , CVE-2009-1558 , CVE-2010-4231 , CVE-2011-3315 , CVE-2014-2962 , CVE-2026-65600 , CVE-2026-67309 , CVE-2020-35749 , CVE-2021-21234 , CVE-2021-43831 , CVE-2026-47179 , CVE-2026-54910 , CVE-2026-73498 , CVE-2026-8183 , CVE-2009-2015 , CVE-2009-3318 , CVE-2009-4202 , CVE-2009-4679 , CVE-2010-0157 , CVE-2010-0759 , CVE-2010-0972 , CVE-2010-0985 , CVE-2010-1306 , CVE-2010-1470 , CVE-2010-1471 , CVE-2010-1472 , CVE-2010-1495 , CVE-2010-1531 , CVE-2010-1533 , CVE-2010-1535 , CVE-2010-1602 , CVE-2010-1603 , CVE-2010-1653 , CVE-2010-1717 , CVE-2010-1875 , CVE-2010-1878 , CVE-2010-1952 , CVE-2010-1953 , CVE-2010-1954 , CVE-2010-1955 , CVE-2010-1956 , CVE-2010-1957 , CVE-2010-1977 , CVE-2010-1980 , CVE-2010-1983 , CVE-2010-2033 , CVE-2010-2034 , CVE-2010-2035 , CVE-2010-2036 , CVE-2010-2037 , CVE-2010-2045 , CVE-2010-2050 , CVE-2010-2128 , CVE-2010-2259 , CVE-2010-2682 , CVE-2010-3426 , CVE-2010-4282 , CVE-2010-4719 , CVE-2010-4769 , CVE-2012-1226 , CVE-2014-10037 , CVE-2014-3744 , CVE-2015-1000005 , CVE-2015-1503 , CVE-2015-3035 , CVE-2015-3648 , CVE-2015-4074 , CVE-2015-4632 , CVE-2015-5469 , CVE-2016-2389 , CVE-2016-6601 , CVE-2017-1000028 , CVE-2017-14849 , CVE-2017-15647 , CVE-2017-16806 , CVE-2017-16877 , CVE-2017-6190 , CVE-2017-9833 , CVE-2018-10822 , CVE-2018-10956 , CVE-2018-12909 , CVE-2018-14912 , CVE-2018-14918 , CVE-2018-15138 , CVE-2018-15535 , CVE-2018-16299 , CVE-2018-18323 , CVE-2018-19326 , CVE-2018-19753 , CVE-2018-3760 , CVE-2018-6184 , CVE-2018-7422 , CVE-2018-7490 , CVE-2018-9205 , CVE-2019-12276 , CVE-2019-14251 , CVE-2019-16123 , CVE-2019-17538 , CVE-2019-18371 , CVE-2019-18665 , CVE-2019-18922 , CVE-2019-7254 , CVE-2019-7315 , CVE-2019-9922 , CVE-2020-11738 , CVE-2020-12447 , CVE-2020-13158 , CVE-2020-14864 , CVE-2020-19360 , CVE-2020-23575 , CVE-2020-27467 , CVE-2020-35580 , CVE-2020-35598 , CVE-2020-35736 , CVE-2020-8209 , CVE-2021-20123 , CVE-2021-20124 , CVE-2021-25864 , CVE-2021-3223 , CVE-2021-39316 , CVE-2021-40978 , CVE-2021-41277 , CVE-2021-41291 , CVE-2021-43495 , CVE-2021-43496 , CVE-2021-43734 , CVE-2021-43778 , CVE-2021-43798 , CVE-2021-46417 , CVE-2022-24716 , CVE-2022-27043 , CVE-2022-29298 , CVE-2022-31474 , CVE-2022-37122 , CVE-2022-38794 , CVE-2022-47501 , CVE-2023-0126 , CVE-2023-23063 , CVE-2023-26256 , CVE-2023-29887 , CVE-2023-33510 , CVE-2023-35843 , CVE-2023-35844 , CVE-2023-37474 , CVE-2023-38879 , CVE-2023-39141 , CVE-2023-40924 , CVE-2023-6023 , CVE-2024-23334 , CVE-2024-38816 , CVE-2024-38819 , CVE-2024-41628 , CVE-2024-4956 , CVE-2024-9362 , CVE-2024-9935 , CVE-2025-13339 , CVE-2025-13801 , CVE-2025-24963 , CVE-2025-31131 , CVE-2025-45145 , CVE-2025-57231 , CVE-2025-59049 , CVE-2025-61884 , CVE-2025-69411 , CVE-2026-32820 , CVE-2026-39847 , CVE-2026-46581 , CVE-2026-50776 , CVE-2026-54293 , CVE-2026-5487 , CVE-2026-5491 , CVE-2026-55552 , CVE-2026-56671 , CVE-2026-61891 , CVE-2026-71209 , CVE-2026-75328 , CVE-2026-75333 , CVE-2026-20297 , CVE-2026-34607 , CVE-2026-35174 , CVE-2018-25393 , CVE-2018-25421 , CVE-2019-25246 , CVE-2026-40526 , CVE-2026-46555 , CVE-2026-64826 , CVE-2026-81030 , CVE-2026-40506 , CVE-2026-73033 , CVE-2022-50956 , CVE-2025-1743 , CVE-2026-23483 , CVE-2026-29059 , CVE-2026-41917 , CVE-2026-45774 , CVE-2026-46337 , CVE-2026-71932 , CVE-2026-74235 , CVE-2026-75592 , CVE-2026-79743 , CVE-2026-79773 , CVE-2026-79781 , CVE-2026-88940 , CVE-2008-2650 , CVE-2008-6172 , CVE-2009-3053 , CVE-2010-1056 , CVE-2010-1219 , CVE-2010-1469 , CVE-2010-1473 , CVE-2010-1474 , CVE-2010-1475 , CVE-2010-1476 , CVE-2010-1478 , CVE-2010-1607 , CVE-2010-1715 , CVE-2010-1718 , CVE-2010-1719 , CVE-2010-1722 , CVE-2010-1723 , CVE-2010-1979 , CVE-2010-1981 , CVE-2010-2122 , CVE-2010-2507 , CVE-2010-2680 , CVE-2010-2857 , CVE-2010-2920 , CVE-2010-4617 , CVE-2011-2744 , CVE-2026-71475 , CVE-2017-14537 , CVE-2017-9416 , CVE-2018-3714 , CVE-2019-11013 , CVE-2019-14312 , CVE-2019-3799 , CVE-2021-28149 , CVE-2021-29006 , CVE-2021-40651 , CVE-2022-37299 , CVE-2024-36527 , CVE-2024-55457 , CVE-2025-45870 , CVE-2026-11442 , CVE-2026-14470 , CVE-2026-35718 , CVE-2026-52607 , CVE-2026-73255 , CVE-2026-7646 , CVE-2026-39365 , CVE-2026-72814 , CVE-2026-78886 , CVE-2026-41363 , CVE-2026-65698 , CVE-2026-66004 , CVE-2025-41242 , CVE-2026-49244 , CVE-2010-0467 , CVE-2025-1035 , CVE-2026-40605 , CVE-2018-13980 , CVE-2018-15536 , CVE-2025-13810 , CVE-2026-18646 , CVE-2026-19827 , CVE-2026-68922 , CVE-2026-84441 , CVE-2026-17621 , CVE-2014-8676 , CVE-2014-9609 , CVE-2015-5471 , CVE-2020-11798 , CVE-2020-13886 , CVE-2021-23241 , CVE-2021-28377 , CVE-2023-41599 , CVE-2025-4078 , CVE-2026-15932 , CVE-2026-34523 , CVE-2026-36726 , CVE-2026-19761 , CVE-2026-19763 , CVE-2008-4764 , CVE-2008-6080 , CVE-2008-6222 , CVE-2008-6668 , CVE-2009-1496 , CVE-2009-2100 , CVE-2009-5114 , CVE-2010-0696 , CVE-2010-0942 , CVE-2010-0943 , CVE-2010-0944 , CVE-2010-1081 , CVE-2010-1302 , CVE-2010-1304 , CVE-2010-1305 , CVE-2010-1307 , CVE-2010-1308 , CVE-2010-1312 , CVE-2010-1314 , CVE-2010-1315 , CVE-2010-1340 , CVE-2010-1345 , CVE-2010-1352 , CVE-2010-1353 , CVE-2010-1354 , CVE-2010-1461 , CVE-2010-1491 , CVE-2010-1494 , CVE-2010-1532 , CVE-2010-1534 , CVE-2010-1540 , CVE-2010-1601 , CVE-2010-1657 , CVE-2010-1658 , CVE-2010-1659 , CVE-2010-1714 , CVE-2010-1858 , CVE-2010-1982 , CVE-2010-2018 , CVE-2010-2307 , CVE-2011-0049 , CVE-2011-1669 , CVE-2011-2780 , CVE-2011-4804 , CVE-2012-0896 , CVE-2012-0981 , CVE-2012-0996 , CVE-2013-5979 , CVE-2013-7091 , CVE-2014-4577 , CVE-2014-4940 , CVE-2014-4941 , CVE-2014-5111 , CVE-2014-5181 , CVE-2014-5187 , CVE-2014-6308 , CVE-2015-2067 , CVE-2015-2166 , CVE-2015-4414 , CVE-2015-4666 , CVE-2015-5531 , CVE-2015-5688 , CVE-2017-7461 , CVE-2023-34259 , CVE-2026-53594 , CVE-2008-5587 , CVE-2010-0982 , CVE-2010-1217 , CVE-2010-1313 , CVE-2012-4253 , CVE-2015-3337 , CVE-2018-18777 , CVE-2024-7631 , CVE-2026-55495 , CVE-2026-73657 , CVE-2011-4640 , CVE-2013-5528 , CVE-2014-5258 , CVE-2012-0991 , CVE-2025-55523 , CVE-2026-55825 , CVE-2023-2252 , CVE-2026-16219 , CVE-2026-19828 , CVE-2026-19829 , CVE-2026-76576 , CVE-2026-82599 , CVE-2026-82603 , CVE-2026-12211 , CVE-2026-16088 , CVE-2026-78435
CWE-23CVE-2025-47445 , CVE-2026-23734 , CVE-2026-48126 , CVE-2025-59341 , CVE-2026-54910
CWE-24CVE-2025-59049 , CVE-2026-73573
CWE-29CVE-2024-34470 , CVE-2023-6023
CWE-35CVE-2020-26073
CWE-36CVE-2025-46822 , CVE-2026-61891
CWE-59CVE-2026-44881
CWE-73CVE-2018-17246 , CVE-2022-24900 , CVE-2026-53580 , CVE-2024-5334 , CVE-2025-59049 , CVE-2026-29962 , CVE-2026-35174 , CVE-2026-85160 , CVE-2026-45725 , CVE-2026-76210 , CVE-2026-54134 , CVE-2026-40605 , CVE-2026-10694 , CVE-2026-34967 , CVE-2026-10558 , CVE-2026-10559
CWE-74CVE-2018-16763 , CVE-2025-13786 , CVE-2025-13792 , CVE-2026-16252 , CVE-2026-82598 , CVE-2026-9474 , CVE-2023-7299 , CVE-2026-19785 , CVE-2026-81835
CWE-77CVE-2026-72869 , CVE-2022-36553 , CVE-2026-35847 , CVE-2020-15874 , CVE-2026-82692 , CVE-2026-82690 , CVE-2026-85222 , CVE-2026-85224 , CVE-2016-3081 , CVE-2026-19771 , CVE-2024-12987 , CVE-2026-19983 , CVE-2026-19379 , CVE-2026-11408 , CVE-2026-8191 , CVE-2026-82678
CWE-78CVE-2025-34037 , CVE-2026-49869 , CVE-2026-42454 , CVE-2026-45629 , CVE-2026-72738 , CVE-2026-72869 , CVE-2026-72876 , CVE-2026-73294 , CVE-2019-12725 , CVE-2019-16662 , CVE-2019-17270 , CVE-2019-7256 , CVE-2020-15920 , CVE-2020-29390 , CVE-2020-9054 , CVE-2026-12940 , CVE-2026-37281 , CVE-2026-53545 , CVE-2026-35906 , CVE-2026-53975 , CVE-2026-59111 , CVE-2026-61498 , CVE-2026-63766 , CVE-2026-71921 , CVE-2026-71946 , CVE-2026-71947 , CVE-2026-71948 , CVE-2026-71955 , CVE-2026-71984 , CVE-2026-71992 , CVE-2026-73570 , CVE-2017-14535 , CVE-2017-6884 , CVE-2018-10823 , CVE-2020-13851 , CVE-2026-17623 , CVE-2026-17625 , CVE-2026-34197 , CVE-2026-35196 , CVE-2026-72875 , CVE-2025-34115 , CVE-2026-25855 , CVE-2026-34792 , CVE-2026-34793 , CVE-2026-34794 , CVE-2026-34795 , CVE-2026-34796 , CVE-2026-34797 , CVE-2026-64837 , CVE-2026-76060 , CVE-2026-79756 , CVE-2026-40187 , CVE-2026-53804 , CVE-2026-5917 , CVE-2026-67599 , CVE-2026-67608 , CVE-2026-71908 , CVE-2026-71913 , CVE-2026-71918 , CVE-2026-71919 , CVE-2026-71931 , CVE-2026-75123 , CVE-2026-80214 , CVE-2026-82692 , CVE-2026-86733 , CVE-2026-82690 , CVE-2026-85222 , CVE-2026-85224 , CVE-2021-21315 , CVE-2026-19771 , CVE-2024-12987 , CVE-2026-19983 , CVE-2026-45626 , CVE-2026-19379 , CVE-2026-11408 , CVE-2026-8191 , CVE-2026-82678
CWE-79CVE-2026-45668
CWE-88CVE-2026-73294
CWE-89CVE-2024-5827 , CVE-2026-38428 , CVE-2026-34612 , CVE-2010-4977 , CVE-2010-5028 , CVE-2026-16252 , CVE-2026-9474 , CVE-2023-7299 , CVE-2026-19785
CWE-91CVE-2026-89247
CWE-93CVE-2026-39394 , CVE-2026-84372 , CVE-2025-61884
CWE-94CVE-2026-55565 , CVE-2025-24893 , CVE-2025-29306 , CVE-2026-46562 , CVE-2026-69256 , CVE-2018-25357 , CVE-2026-27174 , CVE-2026-46621 , CVE-2026-55511 , CVE-2026-58400 , CVE-2026-62674 , CVE-2026-69251 , CVE-2026-43945 , CVE-2020-8163 , CVE-2026-34197 , CVE-2022-50944 , CVE-2026-25856 , CVE-2026-76836 , CVE-2026-85610 , CVE-2021-32820 , CVE-2026-42785 , CVE-2026-56703 , CVE-2026-22244 , CVE-2026-66738 , CVE-2010-2918 , CVE-2026-46581 , CVE-2025-13786 , CVE-2025-13792 , CVE-2026-54611 , CVE-2026-82598 , CVE-2026-81835
CWE-95CVE-2025-24893 , CVE-2026-46562 , CVE-2026-39932 , CVE-2026-61511 , CVE-2026-40187
CWE-98CVE-2024-12209 , CVE-2026-87927 , CVE-2025-48157 , CVE-2026-44239 , CVE-2026-39387 , CVE-2019-25760 , CVE-2022-50954 , CVE-2026-34787 , CVE-2026-63302
CWE-120CVE-2026-36796
CWE-121CVE-2026-36783
CWE-180CVE-2026-39364
CWE-184CVE-2026-49869
CWE-200CVE-2026-65760 , CVE-2018-16288 , CVE-2021-32820 , CVE-2026-44881 , CVE-2026-39363 , CVE-2015-1000012 , CVE-2017-1000029 , CVE-2018-3760 , CVE-2018-6008 , CVE-2021-24227 , CVE-2021-41277 , CVE-2021-43287 , CVE-2025-30208 , CVE-2025-31125 , CVE-2026-61891 , CVE-2014-2383 , CVE-2016-6435 , CVE-2026-29066 , CVE-2025-31486
CWE-201CVE-2026-59809
CWE-284CVE-2026-54745 , CVE-2026-65760 , CVE-2026-43945 , CVE-2026-65759 , CVE-2026-39364 , CVE-2015-1000010 , CVE-2025-30208 , CVE-2025-31125 , CVE-2025-31486
CWE-285CVE-2024-26291 , CVE-2026-46484 , CVE-2026-34239
CWE-287CVE-2026-49869 , CVE-2018-12613 , CVE-2020-24579 , CVE-2018-19458 , CVE-2025-61884
CWE-288CVE-2026-43945
CWE-306CVE-2025-34115 , CVE-2026-89250 , CVE-2026-34160 , CVE-2026-39363 , CVE-2023-22047 , CVE-2026-61891 , CVE-2026-46555 , CVE-2026-65012
CWE-345CVE-2026-73657
CWE-346CVE-2026-46555
CWE-352CVE-2016-6277 , CVE-2026-34228 , CVE-2021-24947
CWE-367CVE-2026-42344 , CVE-2026-54020 , CVE-2026-42336 , CVE-2026-49262
CWE-400CVE-2026-53580 , CVE-2026-26477
CWE-434CVE-2022-47615 , CVE-2026-44402 , CVE-2021-47943 , CVE-2026-34735 , CVE-2026-67206 , CVE-2017-12615 , CVE-2026-53599 , CVE-2026-27891 , CVE-2026-35174 , CVE-2021-24947 , CVE-2026-54611
CWE-441CVE-2026-73079 , CVE-2026-43910 , CVE-2026-77348
CWE-444CVE-2025-61884
CWE-470CVE-2026-46562 , CVE-2026-58400
CWE-472CVE-2026-39364
CWE-501CVE-2025-61884
CWE-502CVE-2026-3296
CWE-552CVE-2021-4463 , CVE-2026-53580 , CVE-2021-39316 , CVE-2022-33901 , CVE-2026-29066
CWE-639CVE-2026-72876 , CVE-2026-69250 , CVE-2026-73657
CWE-641CVE-2026-46581
CWE-644CVE-2026-48126
CWE-665CVE-2019-19411
CWE-668CVE-2022-24900 , CVE-2023-33510
CWE-669CVE-2026-73574
CWE-704CVE-2021-28918
CWE-706CVE-2024-27292
CWE-732CVE-2018-14916
CWE-770CVE-2026-26477
CWE-798CVE-2017-7462
CWE-824CVE-2026-67281
CWE-829CVE-2018-17246 , CVE-2018-7422 , CVE-2021-41569
CWE-835CVE-2024-20353
CWE-862CVE-2026-33712 , CVE-2026-72876 , CVE-2022-36642 , CVE-2026-47754 , CVE-2018-10093 , CVE-2026-73658 , CVE-2023-6020 , CVE-2023-6038
CWE-863CVE-2026-43945 , CVE-2026-76836 , CVE-2021-24947
CWE-913CVE-2020-15568
CWE-915CVE-2026-72710
CWE-917CVE-2020-17530
CWE-918CVE-2026-33712 , CVE-2026-49869 , CVE-2026-54745 , CVE-2026-31818 , CVE-2026-43986 , CVE-2026-30118 , CVE-2019-8982 , CVE-2026-12564 , CVE-2026-12605 , CVE-2026-64849 , CVE-2026-66794 , CVE-2026-65317 , CVE-2026-85614 , CVE-2026-86119 , CVE-2026-44313 , CVE-2026-75332 , CVE-2023-39108 , CVE-2023-39109 , CVE-2023-39110 , CVE-2026-34367 , CVE-2026-47659 , CVE-2026-81093 , CVE-2026-82270 , CVE-2026-82638 , CVE-2026-85608 , CVE-2026-85612 , CVE-2026-85673 , CVE-2026-34160 , CVE-2026-34577 , CVE-2026-7412 , CVE-2026-81889 , CVE-2026-61640 , CVE-2026-67424 , CVE-2026-72855 , CVE-2026-52769 , CVE-2026-16268 , CVE-2026-43910 , CVE-2026-54691 , CVE-2026-77348 , CVE-2026-82262 , CVE-2026-34365 , CVE-2026-34366 , CVE-2026-34936 , CVE-2026-42345 , CVE-2026-53549 , CVE-2026-61835 , CVE-2026-63764 , CVE-2026-67346 , CVE-2026-69192 , CVE-2026-77775 , CVE-2026-79749 , CVE-2021-46107 , CVE-2025-61884 , CVE-2026-22664 , CVE-2026-75844 , CVE-2026-79747 , CVE-2026-85164 , CVE-2026-10107 , CVE-2026-34964 , CVE-2026-44652 , CVE-2026-54885 , CVE-2026-73058 , CVE-2026-81678 , CVE-2026-85609 , CVE-2026-86806 , CVE-2026-8712 , CVE-2024-27564 , CVE-2026-15974 , CVE-2026-42335 , CVE-2026-54020 , CVE-2026-63107 , CVE-2026-67620 , CVE-2026-73530 , CVE-2026-10526 , CVE-2026-45709 , CVE-2026-48053 , CVE-2026-73243 , CVE-2026-18973 , CVE-2026-19753 , CVE-2026-7178 , CVE-2026-7221 , CVE-2026-76795 , CVE-2026-82801 , CVE-2026-85380 , CVE-2026-48483 , CVE-2026-7798 , CVE-2026-16536 , CVE-2026-44583 , CVE-2026-49138 , CVE-2026-54508 , CVE-2026-59231 , CVE-2026-63730 , CVE-2026-64626 , CVE-2026-74858 , CVE-2026-42336 , CVE-2026-49262 , CVE-2026-68927 , CVE-2026-73087 , CVE-2026-10239 , CVE-2026-12210 , CVE-2026-16194 , CVE-2026-17458 , CVE-2026-19927 , CVE-2026-5803 , CVE-2026-74842 , CVE-2026-83744 , CVE-2026-18856 , CVE-2026-86240
CWE-1188CVE-2026-31818 , CVE-2026-77348
CWE-1220CVE-2026-39363
CWE-1336CVE-2026-22244
CWE-1392CVE-2026-41939