CVE-2026-40425
The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authent
CVSS
5.7
Medio
EPSS
0.4%
p30
KEV
—
Exploit Today
9
0-100
Publicado: 29 may 2026 · Última mod.: 20 jul 2026 · CWE-552
0.4%EPSS · 30 días0.4%
2026-06-302026-07-21
The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authentication, potentially changing the root password.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-597037.5 ALT31.0%
——9repomix contains a local file inclusion vulnerability in the git clone endpoint that allows unauthenticated attackers to read arbitrary local git repositories. The isValidRemoteValue function in src/core/git/gitRemoteParse.ts fails to block file:// URLs, permitting attackers to supply file:// scheme URLs that bypass validation and are passed directly to git clone, enabling unauthorized access to all tracked file contents on the server filesystem.11dCVE-2026-347857.5 ALT31.1%
——9Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whether a request should be served as a static file using a simple string prefix check. When configured with URL prefixes such as "/css", it matches any request path that begins with that string, including unrelated paths such as "/css-config.env" or "/css-backup.sql". As a result, files under the static root whose names merely share the configured prefix may be served unintentionally, leading to information disclosure. This issue has been patched in versions 2.2.23, 3.1.21, and 3.2.6.7dCVE-2025-669556.5 MED18.9%
——6Local File Inclusion in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote authenticated users to access files on the host via "path" parameter in the downloadAttachment and downloadAttachmentFromPath API calls.17dCVE-2025-52736.5 MED24.7%
——7Versions of the package mcp-markdownify-server before 1.0.0 are vulnerable to Files or Directories Accessible to External Parties via the get-markdown-file tool. An attacker can craft a prompt that, once accessed by the MCP host, will allow it to read arbitrary files from the host running the server.5dCVE-2025-257996.0 MED13.5%
——4SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe.php.17dCVE-2024-448075.3 MED38.8%
——12A directory listing issue in the baserCMS plugin in D-ZERO CO., LTD. BurgerEditor and BurgerEditor Limited Edition before 2.25.1 allows remote attackers to obtain sensitive information by exposing a list of the uploaded files.16d