CWE-441
CVEs classified under CWE-441, newest first.
72 CVEsRSS
CVE-2026-53931MediumNocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint
NocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint
CVE-2026-9595Medium· 5.3webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies
webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies
CVE-2026-50169MediumAngular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities
Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities
CVE-2026-48522Medium· 4.2PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes
PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes
CVE-2026-53999High· 7.7Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)
Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)
CVE-2026-44494High· 8.7PoCAxios is a promise based HTTP client for the browser and Node.js
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's depen…
CVE-2026-0098High· 7.8In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictions due to a confused deputy
In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User intera…
CVE-2026-42043High· 7.2PoCAxios is a promise based HTTP client for the browser and Node.js
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to complet…
CVE-2025-62718Critical· 9.9PoC⚖ disputedAxios is a promise based HTTP client for the browser and Node.js
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a tra…
CVE-2026-0008High· 8.4In multiple functions of FaceEnroll.kt, there is a possible privilege escalation due to a confused deputy
In multiple functions of FaceEnroll.kt, there is a possible privilege escalation due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed fo…
CVE-2026-0013High· 8.4PoCIn setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy
In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User inter…
CVE-2025-11393High· 8.7A flaw was found in runtimes-inventory-rhel8-operator
A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of this flaw, the proxy attaches the cluster's main administrative credentials to any command it receives, instead of o…