VYPR
Vendor

Jfs Jfs

Products
10
CVEs
10
Across products
10
Status
Private

Products

10

Recent CVEs

10
  • CVE-2026-37073Aug 27, 2026
    risk 0.00cvss epss

    Incorrect access control in /vfm-admin/ajax/sendfiles.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to send emails from the configured SMPT server on the application via making a POST request to the endpoint with needed parameters and header.

  • CVE-2026-37072Aug 27, 2026
    risk 0.00cvss epss

    Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php.

  • CVE-2026-37071Aug 27, 2026
    risk 0.00cvss epss

    Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4.9 allows an authenticated attacker with 'reanme' permission to take over the super administrator account via a specially crafted POST request to the affected…

  • CVE-2026-37070Aug 27, 2026
    risk 0.00cvss epss

    Incorrect access control in /vfm-admin/ajax/streamvid.php in Veno File Manager Project in 4.4.9 allows an authenticated attacker to read any uploaded files by other users as long as it knows the path and filename via a specially crafted GET request to the affected endpoint.

  • CVE-2026-37069Aug 27, 2026
    risk 0.00cvss epss

    Absolute Path Disclosure in /vfm-admin/assets/zipstream/grandt/relativepath/RelativePath.Example1.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to know in which system directory the application code is running by sending a GET request to the endpoint.

  • CVE-2026-37068Aug 27, 2026
    risk 0.00cvss epss

    Arbitrary file write in /vfm-admin/index.php?section=translations&action=update in Veno File Manager Project 4.4.9 allows an authenticated user with the role of super administrator to overwrite any php file in the application via a specially crafted POST request to the affected…

  • CVE-2026-37067Aug 27, 2026
    risk 0.00cvss epss

    Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract all application logs from a desired date forwards via a specially crafted POST request.

  • CVE-2026-37066Aug 27, 2026
    risk 0.00cvss epss

    Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Manager Project 4.4.9 allows and authenticated attacker with super administrator role to disclose sensitive information via two specially crafted http requests…

  • CVE-2026-37065Aug 27, 2026
    risk 0.00cvss epss

    Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deletion in /vfm-admin/index.php?section=translations&action=update&remove=.

  • CVE-2026-37064Aug 27, 2026
    risk 0.00cvss epss

    User enumeration in /vfm-admin/ajax/usr-check.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to enumerate the application users via sending a specially crafted POST request to the affected endpoint with a chosen 'user_name' parameter to test if the…