Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-37073

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Veno 文件管理器项目 4.4.9 版本中, 存在不正确的访问控制漏洞。未经身份验证的攻击者可以通过向该端点发送包含必要参数和请求头的 POST 请求,利用应用配置的 SMTP 服务器发送邮件。

AI Predicted 5.3 Difficulty: Easy EPSS 0.16% · P6

Possible ATT&CK Techniques 1 AI

T1210 · Exploitation of Remote Services

Affected Version Matrix 1

VendorProduct Version RangeStatus
n/a n/a n/a affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-37073

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Incorrect access control in /vfm-admin/ajax/sendfiles.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to send emails from the configured SMPT server on the application via making a POST request to the endpoint with needed parameters and header.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2026-37073

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-37073

登录查看更多情报信息。

Proof of Concept for CVE-2026-37073 (1)

Other References for CVE-2026-37073 (1)

Same Patch Batch · n/a · 2026-08-27 · 62 CVEs total

CVE-2026-75419 8.8 HIGH GoWind低于1.0.0存在授权缺失漏洞
CVE-2026-75418 7.5 HIGH Lektor<3.3.14 Windows下路径遍历漏洞
CVE-2026-37004 BerriAI litellm<=1.82.4模板注入漏洞
CVE-2026-38347 FFmpeg git-master 堆溢出致拒绝服务
CVE-2026-38349 FFmpeg N-122528 hScale16To19_c整数溢出致DoS
CVE-2026-38346 FFmpeg N-122528:整数溢出致DoS
CVE-2026-37068 VFM 4.4.9 认证用户任意文件写入
CVE-2026-37198 Open5GS v2.7.6 SMF组件整数溢出致服务拒绝
CVE-2026-37007 crewai-tools 1.10.2rc1 路径遍历致代码执行
CVE-2026-37067 Veno File Manager 4.4.9 日志未认证访问
CVE-2026-37069 Veno File Manager 4.4.9 绝对路径泄露漏洞
CVE-2026-37064 Veno File Manager 4.4.9 未认证用户枚举漏洞
CVE-2026-37003 Agno≤2.5.8提示词注入致远程代码执行
CVE-2026-37070 Veno 4.4.9 文件管理器访问控制不当
CVE-2026-37009 crewai-tools 1.10.2rc1 SQL注入漏洞
CVE-2026-37006 gpt-researcher v0.14.7之前WebSocket端点RCE漏洞
CVE-2026-37066 Veno File Manager 4.4.9 路径遍历致任意文件读取漏洞
CVE-2026-37071 Veno File Manager 4.4.9 任意文件重命名致权限提升
CVE-2026-37065 Veno File Manager 4.4.9 任意文件删除
CVE-2026-37012 PentestGPT 1.0.0 Langfuse 硬编码密钥致数据泄露

Showing top 20 of 62 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-37073

No comments yet


Leave a comment