VYPR

AnyShare Cloud

by AnyShare

CVEs (2)

  • CVE-2025-34160CriAug 27, 2025
    risk 0.65cvss epss 0.01

    AnyShare contains a critical unauthenticated remote code execution vulnerability in the ServiceAgent API exposed on port 10250. The endpoint /api/ServiceAgent/start_service accepts user-supplied input via POST and fails to sanitize command-like payloads. An attacker can inject…

  • CVE-2020-8996MedFeb 16, 2020
    risk 0.28cvss 4.3epss 0.01

    AnyShare Cloud 6.0.9 allows authenticated directory traversal to read files, as demonstrated by the interface/downloadwithpath/downloadfile/?filepath=/etc/passwd URI.