PoC Archive PoC Archive

tag

Arbitrary-File-Read

Microweber CMS Unauthenticated Path Traversal → Arbitrary File Read (CVE-2026-65694)
CVE-2026-65694 (VulnCheck advisory) web Patched
CVE-2026-65694webHIGH 7.5Patched2026-07-31Rails Active Storage Arbitrary File Read to RCE via libvips Unfuzzed Loaders (CVE-2026-66066) EPSS 28%
CVE-2026-66066 (GHSA-xr9x-r78c-5hrm) web Patched
CVE-2026-66066webCRITICAL 9.5Patched2026-07-27ZKTeco BioTime v8.5.5 Unauthenticated Path Traversal / Arbitrary File Read via iclock API (CVE-2023-38950) KEV EPSS 85%
CVE-2023-38950 web Patched
CVE-2023-38950webHIGH 7.5Patched2026-07-11Gladinet CentreStack / Triofox Hardcoded AES Key Access-Ticket Forgery to Arbitrary File Read (CVE-2025-14611) KEV EPSS 53%
CVE-2025-14611 web Unverified
CVE-2025-14611webCRITICAL 9.8Unverified2026-07-06Weblate Arbitrary File Read via ssh-keyscan Host Argument Injection — CVE-2026-24126
CVE-2026-24126 web Patched
CVE-2026-24126webHIGH 6.5Patched2026-07-05Veno File Manager Path Traversal to Arbitrary File Read (CVE-2026-37066)
CVE-2026-37066 web Unverified
CVE-2026-37066webHIGHUnverified2026-07-05Veno File Manager 4.4.9 — Authenticated Arbitrary File Read (CVE-2026-37070)
CVE-2026-37070 web Unverified
CVE-2026-37070webMEDIUMUnverified2026-07-05UnPoller Path Traversal / Arbitrary File Read via file:// Password Prefix (CVE-2026-36851)
CVE-2026-36851 misc Unverified
CVE-2026-36851miscHIGH 7.5Unverified2026-07-05Tandoor Recipes Authenticated Local File Disclosure via Recipe Import (CVE-2026-25964)
CVE-2026-25964 (GHSA-6485-jr28-52xx) web Patched
CVE-2026-25964webMEDIUM 4.9Patched2026-07-05OpenEMR EtherFax Module Authenticated Arbitrary File Read (CVE-2026-24849)
CVE-2026-24849 web Patched
CVE-2026-24849webCRITICAL 6.5Patched2026-07-05n8n Unauthenticated Arbitrary File Read to RCE Full Chain — CVE-2026-21858 + CVE-2025-68613 EPSS 78%
CVE-2026-21858, CVE-2025-68613 web Patched
CVE-2026-21858, CVE-2025-68613webCRITICAL 10Patched2026-07-05mcp-atlassian Path Traversal via confluence_upload_attachment (CVE-2026-27825) EPSS 13%
CVE-2026-27825 (read-side twin of GHSA-xjgw-4wvw-rgm4) web Patched
CVE-2026-27825webCRITICAL 9.3Patched2026-07-05LiquidJS Template Engine Path Traversal — CVE-2026-30952
CVE-2026-30952 (GHSA-wmfp-5q7x-987x) misc Patched
CVE-2026-30952miscHIGH 8.7Patched2026-07-05Jenkins ClassFilter Deserialization Bypass → Arbitrary File Read — CVE-2026-53435 EPSS 53%
CVE-2026-53435 (Jenkins SECURITY-3707) web Patched
CVE-2026-53435webHIGH 9.1Patched2026-07-05InvoicePlane Unauthenticated Path Traversal in Guest Controller (CVE-2026-23491)
CVE-2026-23491 web Patched
CVE-2026-23491webCRITICALPatched2026-07-05HashiCorp go-getter Git Pathspec Arbitrary File Read (CVE-2026-4660)
CVE-2026-4660 / HCSEC-2026-04 cloud Patched
CVE-2026-4660 / HCSEC-2026-04cloudHIGH 7.5Patched2026-07-05exiftool-vendored.js Argument Injection via Newline-Delimited Tag Names (CVE-2026-43893)
CVE-2026-43893 / GHSA-cw26-7653-2rp5 misc Patched
CVE-2026-43893 / GHSA-cw26-7653-2rp5miscHIGH 8.2Patched2026-07-05Apache HTTP Server mod_rewrite/mod_setenvif/mod_proxy_fcgi ap_expr Local File Read — CVE-2026-24072
CVE-2026-24072 web Patched
CVE-2026-24072webMEDIUMPatched2026-07-05Jenkins CLI Arbitrary File Read to RCE (CVE-2024-23897) KEV RW EPSS 100%
CVE-2024-23897 web Patched
CVE-2024-23897webCRITICAL 9.8Patched2026-05-17