VulnSea

CWE-441

CVEs classified under CWE-441, newest first.

72 CVEsRSS

CVE-2026-53931Medium
3mo ago

NocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint

NocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint

▾ Sunlitnocodb · nocodbEPSS 0.41%via GHSA
CVE-2026-9595Medium· 5.3
3mo ago

webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies

webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies

▾ Sunlitwebpack-dev-server · webpack-dev-serverEPSS 0.23%via GHSA
CVE-2026-50169Medium
3mo ago

Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities

Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities

▾ Sunlitangular · @angular/service-workerEPSS 0.23%via GHSA
CVE-2026-48522Medium· 4.2
3mo ago

PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes

PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes

▾ Sunlitpyjwt · pyjwtEPSS 0.22%via OSV
CVE-2026-53999High· 7.7
3mo ago

Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)

Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)

▾ Twilightradius-project · github.com/radius-project/radiusvia GHSA
CVE-2026-44494High· 8.7PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's depen…

▾ Midnightaxios · axiosEPSS 0.93%via NVD
CVE-2026-0098High· 7.8
3mo ago

In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictions due to a confused deputy

In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User intera…

▾ Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-42043High· 7.2PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to complet…

▾ Midnightaxios · axiosEPSS 0.58%via NVD
CVE-2025-62718Critical· 9.9PoC⚖ disputed
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a tra…

▾ Abyssalaxios · axiosEPSS 1.2%via NVD
CVE-2026-0008High· 8.4
6mo ago

In multiple functions of FaceEnroll.kt, there is a possible privilege escalation due to a confused deputy

In multiple functions of FaceEnroll.kt, there is a possible privilege escalation due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed fo…

▾ Twilightgoogle · androidEPSS 0.12%via NVD
CVE-2026-0013High· 8.4PoC
6mo ago

In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy

In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User inter…

▾ Midnightgoogle · androidEPSS 0.16%via NVD
CVE-2025-11393High· 8.7
9mo ago

A flaw was found in runtimes-inventory-rhel8-operator

A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of this flaw, the proxy attaches the cluster's main administrative credentials to any command it receives, instead of o…

▾ TwilightEPSS 0.20%via NVD
CWE-441 vulnerabilities (CVEs) — page 3 · VulnSea