CVE-2026-102457Medium· 6.5▾ SunlitEasyFlow .NET developed by Digiwin has an Arbitrary File Read vulnerability. Authenticated remote attackers can exploit this vulnerability to download arbitrary system files.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
EasyFlow .NET developed by Digiwin has an Arbitrary File Read vulnerability. Authenticated remote attackers can exploit this vulnerability to download arbitrary system files.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102455Critical· 9.8EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability
CVE-2026-102458Critical· 9.8EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability
CVE-2026-102459Medium· 6.1EasyFlow .NET developed by Digiwin has a Reflected Cross-site Scripting vulnerability
CVE-2026-102456Medium· 6.5EasyFlow .NET developed by Digiwin has an SQL Injection vulnerability
CVE-2026-102454High· 7.2EasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability
CVE-2024-13986High· 8.8Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload and a path traversal in the Core Config Snapshots interface