CVE-2026-37066
Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Manager Project 4.4.9 a
CVSS
6.5
Medio
EPSS
0.4%
p34
KEV
—
Exploit Today
10
0-100
Publicado: 27 ago 2026 · Última mod.: 2 sept 2026 · CWE-22
0.2%EPSS · 30 días0.4%
2026-08-282026-09-22
Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Manager Project 4.4.9 allows and authenticated attacker with super administrator role to disclose sensitive information via two specially crafted http requests (POST and GET) to the affected endpoints.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-918017.8 ALT—
———A path traversal vulnerability exists in Foxit PDF Editor/Reader's handling of embedded PDF resources. Insufficient validation of resource file paths may allow files to be written outside their intended locations, potentially enabling arbitrary code execution.11hCVE-2026-194387.5 ALT—
———Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Mint Workbench I.
This issue affects Mint Workbench I: through 5876.13hCVE-2026-181699.9 CRÍ—
———IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.20hCVE-2026-181335.4 MED—
———IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to modify server files due to path traversal.21hCVE-2026-181146.5 MED—
———IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to read arbitrary files due to improper path canonicalization.21hCVE-2026-883447.5 ALT—
———An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact-length FlatBuffers schema buffer ends with a digit, the integer digit-scan loop in lex() advances past the end of the input buffer and dereferences the out-of-bounds pointer. A specially crafted schema can trigger a one-byte heap buffer over-read, resulting in application crash and denial of service.6h