Veno File Manager Project
Veno File Manager Project Veno File Manager: vulnerabilidades y CVE
Veno File Manager Project Veno File Manager tiene 11 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses10
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-37073 | Media (5.3) | 0.32% | — | 27 ago 2026 | Incorrect access control in /vfm-admin/ajax/sendfiles.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to send emails from the configured SMPT server on the application via making a POST request… |
| CVE-2026-37072 | Crítica (9.8) | 0.51% | — | 27 ago 2026 | Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php. |
| CVE-2026-37071 | Crítica (9.8) | 0.51% | — | 27 ago 2026 | Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4.9 allows an authenticated attacker with 'reanme' permission to take over the super administrator… |
| CVE-2026-37070 | Media (6.5) | 0.35% | — | 27 ago 2026 | Incorrect access control in /vfm-admin/ajax/streamvid.php in Veno File Manager Project in 4.4.9 allows an authenticated attacker to read any uploaded files by other users as long as it knows the path and filename via a… |
| CVE-2026-37069 | Media (5.3) | 0.36% | — | 27 ago 2026 | Absolute Path Disclosure in /vfm-admin/assets/zipstream/grandt/relativepath/RelativePath.Example1.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to know in which system directory the… |
| CVE-2026-37068 | Alta (8.1) | 0.53% | — | 27 ago 2026 | Arbitrary file write in /vfm-admin/index.php?section=translations&action=update in Veno File Manager Project 4.4.9 allows an authenticated user with the role of super administrator to overwrite any php file in the… |
| CVE-2026-37067 | Media (5.3) | 0.34% | — | 27 ago 2026 | Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract all application logs from a desired date forwards via a specially… |
| CVE-2026-37066 | Media (6.5) | 0.54% | — | 27 ago 2026 | Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Manager Project 4.4.9 allows and authenticated attacker with super administrator role to disclose… |
| CVE-2026-37065 | Crítica (9.1) | 0.50% | — | 27 ago 2026 | Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deletion in /vfm-admin/index.php?section=translations&action=update&remove=. |
| CVE-2026-37064 | Media (5.3) | 0.36% | — | 27 ago 2026 | User enumeration in /vfm-admin/ajax/usr-check.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to enumerate the application users via sending a specially crafted POST request to the affected… |
| CVE-2020-22550 | Alta (7.5) | 2.3% | — | 4 ene 2021 | Veno File Manager 3.5.6 is affected by a directory traversal vulnerability. Using the traversal allows an attacker to download sensitive files from the server. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.