VulnSea

CWE-918

CVEs classified under CWE-918, newest first.

694 CVEsRSS

CVE-2026-61612Medium· 5.7
today

@aborruso/ckan-mcp-server has SSRF via DNS-name → internal IP — incomplete fix of CVE-2026-53509

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to version 0.4.108, the SSRF guard `validateServerUrl` (added for CVE-2026-33060, extended for CVE-2026-53509) validates only the hostname string and never resolves DNS…

Sunlitondata · ckan-mcp-servervia CVEORG
CVE-2026-63334Medium· 6.8
today

draw.io is a configurable diagramming and whiteboarding application

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, deployments with ENABLE_DRAWIO_PROXY=1 are vulnerable to server-side request forgery because src/main/java/com/mxgraph/online/Utils.java perfor…

Sunlitjgraph · drawiovia NVD
CVE-2026-76898High· 7.7
today

draw.io is a configurable diagramming and whiteboarding application

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.3.8, src/main/java/com/mxgraph/online/Utils.java checks IPv6 Unique Local Addresses in Utils.sanitizeUrl() by comparing the text prefixes fc00:: and…

Twilightjgraph · drawiovia NVD
CVE-2026-61681Medium· 4.1
today

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, the SNS UnsubscribeConfirmation handler in internal/integrations/ingestors/sns/sns.go calls http.Get() on payload.Unsub…

Sunlithatchet-dev · hatchetvia NVD
CVE-2026-94401High· 8.3
today

MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access internal network services. When importing an XML file, MISP did not properly verify that the uploaded content was act…

MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access internal network services. When importing an XML file, MISP did not properly verify that the uploaded content was act…

TwilightMISP · MISPvia NVD
CVE-2026-94051Medium· 6.3PoC
yesterday

A vulnerability was found in 0717376 cowork_bench up to d943e75bc0fc8e3b27141979300cd8cbcd1e890d

A vulnerability was found in 0717376 cowork_bench up to d943e75bc0fc8e3b27141979300cd8cbcd1e890d. Affected by this vulnerability is the function ControlFlowNode of the file local_servers/pdf-tools-mcp/pdf_tools_mcp/server.py of the compo…

Twilight0717376 · cowork_benchEPSS 0.21%via NVD
CVE-2026-94040Medium· 5.3
yesterday

A flaw has been found in vas3k TaxHacker up to 0.8.5

A flaw has been found in vas3k TaxHacker up to 0.8.5. Affected by this vulnerability is the function testLLMProviderAction of the file app/(app)/apps/settings/actions.ts. Executing a manipulation of the argument provider/apiKey/model/bas…

Sunlitvas3k · TaxHackerEPSS 0.31%via NVD
CVE-2026-94039High· 7.3
yesterday

A vulnerability was detected in vas3k TaxHacker up to 0.8.5

A vulnerability was detected in vas3k TaxHacker up to 0.8.5. Affected is the function generateInvoicePDF of the file /apps/invoices/actions.ts of the component Invoice PDF Renderer. Performing a manipulation of the argument businessLogo …

Twilightvas3k · TaxHackerEPSS 0.29%via NVD
CVE-2026-94038High· 7.3
yesterday

A security vulnerability has been detected in NonceGeek dim-sum-app

A security vulnerability has been detected in NonceGeek dim-sum-app. This impacts the function textSearchV2Handler of the file deno/main.tsx of the component Deno Backend. Such manipulation of the argument supabase_url leads to server-si…

TwilightNonceGeek · dim-sum-appEPSS 0.30%via NVD
CVE-2026-94028Medium· 4.3
yesterday

A weakness has been identified in mealie-recipes Mealie up to 3.25.1

A weakness has been identified in mealie-recipes Mealie up to 3.25.1. Affected is the function payload.model_dump of the file mealie/routes/households/controller_group_recipe_actions.py of the component Recipe Action Trigger. Executing a…

Sunlitmealie-recipes · MealieEPSS 0.43%via NVD
CVE-2026-16542Medium· 4.1
yesterday

The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before requesting it server-side during a CSV import, allowing high-privileged users to perform Server-Side Request Forgery att…

The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before requesting it server-side during a CSV import, allowing high-privileged users to perform Server-Side Request Forgery att…

SunlitEPSS 0.18%via NVD
CVE-2026-1641Medium· 6.5
2d ago

The Wow Elements Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.11.2

The Wow Elements Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.11.2. This is due to the plugin passing user-controlled input from the 'Changelog File' setti…

Sunlitwowelements · Wow Elements Addons for ElementorEPSS 0.28%via NVD
CVE-2026-75885Critical· 9.3
3d ago

A flaw was found in the OpenShift console

A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF)…

MidnightRed Hat · openshift4/ose-consoleEPSS 0.41%via NVD
CVE-2026-76900Medium· 6.8
3d ago

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. In version 1.7.3, ApprovalResourceService.sendWebHook reads WebHookConfig.webHookUrl from stored approval-node configuration…

Sunlit1Panel-dev · CordysCRMEPSS 0.38%via NVD
CVE-2026-18869Medium· 6.4
3d ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions and access internal network services due to improper validation of FTP PORT and EPRT commands.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions and access internal network services due to improper validation of FTP PORT and EPRT commands.

SunlitIBM · iEPSS 0.22%via NVD
GHSA-jgh3-fggc-mcpmHigh· 7.6
3d ago

Obot: Server-Side Request Forgery via remote MCP server URL

Obot: Server-Side Request Forgery via remote MCP server URL

Twilightobot-platform · github.com/obot-platform/obotvia OSV
GHSA-39wr-7q6h-cf68High· 7.5
3d ago

LMDeploy has an SSRF bypass

LMDeploy has an SSRF bypass

Twilightlmdeploy · lmdeployvia OSV
CVE-2026-93506Medium· 6.3
3d ago

A vulnerability was determined in SveltyCMS 0.0.6

A vulnerability was determined in SveltyCMS 0.0.6. This issue affects some unknown processing of the file /mediagallery/upload-media of the component File Upload Endpoint. Executing a manipulation can lead to server-side request forgery.…

SunlitEPSS 0.35%via NVD
CVE-2026-62282Medium· 6.5
3d ago

OpenCVE is a vulnerability intelligence platform

OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, OpenCVE notification testing for Webhook and Slack integrations does not sufficiently validate user-supplied HTTP or HTTPS destinations. An authenticated user with permiss…

Sunlitopencve · opencveEPSS 0.33%via NVD
CVE-2026-93597High· 7.7PoC
3d ago

ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands

ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands. Authenticated attackers can supply URLs resolving to NAT64, 6to4, or Teredo addresses embedding RFC…

MidnightArcadeData · arcadedbEPSS 0.33%via NVD
CVE-2026-40537Medium· 4.3
3d ago

A server-side request forgery (SSRF) vulnerability in PersonMail API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information.

A server-side request forgery (SSRF) vulnerability in PersonMail API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information.

SunlitSynology · DiskStation Manager (DSM)EPSS 0.25%via NVD
CVE-2026-67101Critical· 9.3
3d ago

HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not …

HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not …

MidnightHCL Software · HCL BigFix Service ManagementEPSS 0.27%via NVD
CVE-2026-12106Medium· 6.4
3d ago

The Auto Upload Images plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 3.3.2 via the downloadImage function

The Auto Upload Images plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 3.3.2 via the downloadImage function. This makes it possible for authenticated attackers, with contrib…

Sunlitairani · Auto Upload ImagesEPSS 0.25%via NVD
CVE-2026-90984Medium· 5.8
3d ago

The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetch its PDF renderer performs on submitted form content, allowing unauthenticated users to make the server request inter…

The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetch its PDF renderer performs on submitted form content, allowing unauthenticated users to make the server request inter…

SunlitEPSS 0.19%via NVD
CVE-2026-77164Medium· 6.2
3d ago

Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this request, bypassing Nextcloud's core SSRF p…

Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this request, bypassing Nextcloud's core SSRF p…

SunlitNextcloud · ServerEPSS 0.13%via NVD
CVE-2026-85917High· 7.5
4d ago

Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

TwilightMicrosoft · Azure AI FoundryEPSS 0.55%via NVD
CVE-2026-54734Critical· 10.0
4d ago

Prebid Server Java is the Java version of Prebid Server

Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the resulting domain or path segment. A …

Midnightprebid · prebid-server-javaEPSS 0.36%via NVD
CVE-2026-54507High· 8.4
4d ago

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, the oEmbedProxy() handler in admin/controller/editor/editor.php accepts an attacker-controlled url parameter and pa…

Twilightgivanz · VvvebEPSS 0.32%via NVD
CVE-2026-93384Low· 3.7
4d ago

Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic

Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security sev…

Sunlitgoogle · chromeEPSS 0.24%via NVD
CVE-2026-54339High· 7.7
4d ago

Glean is a self-hosted RSS reader and personal knowledge management tool

Glean is a self-hosted RSS reader and personal knowledge management tool. Prior to 0.2.6, POST /api/feeds/discover passes an attacker-supplied feed_url to discover_feed(feed_url), creates a subscription through FeedService.create_subscri…

TwilightLeslieLeung · gleanEPSS 0.34%via NVD
CWE-918 vulnerabilities (CVEs) · VulnSea