VulnSea

CWE-918

CVEs classified under CWE-918, newest first.

838 CVEsRSS

CVE-2026-69851Critical· 9.9
1mo ago

Microsoft Entra ID Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Microsoft EntraEPSS 0.78%via CVEORG
CVE-2026-69543High· 8.5
1mo ago

Azure Virtual Machines Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Azure Virtual MachinesEPSS 0.56%via CVEORG
CVE-2026-69855High· 7.7
1mo ago

Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.

Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.

▾ Twilightmicrosoft · azure_copilotEPSS 0.84%via NVD
CVE-2026-65801Critical· 10.0
1mo ago

Microsoft Exchange Online Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Microsoft Exchange OnlineEPSS 0.90%via CVEORG
CVE-2026-66800High· 8.6
1mo ago

Azure Data Factory Information Disclosure Vulnerability

Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.

▾ TwilightMicrosoft · Azure Data FactoryEPSS 0.97%via CVEORG
CVE-2026-71428Critical· 9.3
1mo ago

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 until 0.24.0, the url argument of partition, partition_html, an…

▾ Midnightunstructured · unstructuredEPSS 0.44%via NVD
CVE-2026-65842High· 8.2
1mo ago

Plate is a rich-text editor with AI and shadcn/ui

Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.2, @platejs/docx-io fetches remote image URLs while converting attacker-controlled HTML through htmlToDocxBlob in a server-side or privileged environment. The converter can…

▾ Twilightplatejs · @platejs/docx-ioEPSS 0.52%via NVD
CVE-2026-61704High· 7.5
1mo ago

Link Preview JS extracts web links information

Link Preview JS extracts web links information. Prior to 4.0.4, the resolveDNSHost mitigation in index.ts validates one resolved IP address but fetches the original hostname, allowing an attacker-controlled DNS server to return a public …

▾ Twilightlink-preview-js · link-preview-jsEPSS 0.55%via NVD
GHSA-5p3m-vhh6-9236Medium· 6.3
1mo ago

stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address

stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address

▾ Sunlitstigmem-node · stigmem-nodevia GHSA
CVE-2026-75583Low· 3.5
1mo ago

keeper.sh's calendar module version prior to 2.18.14 contains a server-side request forgery (SSRF) guard bypass vulnerability that allows authenticated attackers to reach private network addresses by exploiting a DNS rebinding attack aga…

keeper.sh's calendar module version prior to 2.18.14 contains a server-side request forgery (SSRF) guard bypass vulnerability that allows authenticated attackers to reach private network addresses by exploiting a DNS rebinding attack aga…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-45741High· 7.5PoC
1mo ago

Gotenberg is a Docker-powered stateless API for PDF files

Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, the IsPublicIP function in pkg/gotenberg/outbound.go does not reject the 2002::/16 6to4 prefix, the 64:ff9b::/96 and 64:ff9b:1::/48 NAT64 prefixes, the fec…

▾ Midnightgotenberg · gotenbergEPSS 0.37%via NVD
CVE-2026-53549High· 7.7
1mo ago

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the POST /host/db/proxy/test endpoint accepts the singleProxy, proxyChain, and testTarget request fields withou…

▾ TwilightEPSS 0.45%via NVD
CVE-2026-68558High· 8.5
1mo ago

Wekan is open source kanban built with Meteor

Wekan is open source kanban built with Meteor. From 8.36 until 9.74, the outgoing webhook Integration URL validator in models/integrations.js checked only the literal URL.hostname against regular expressions, so DNS names such as 169-254…

▾ TwilightEPSS 0.39%via NVD
CVE-2026-62668None
1mo ago

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, the Grav API plugin WebhookController.php accepts webhook URLs after only FILTER_VALIDATE_URL syntax validation, and…

▾ SunlitEPSS 0.45%via NVD
CVE-2026-76225High· 7.7
1mo ago

ArcadeDB before 26.8.1 contains a server-side request forgery vulnerability in the OpenCypher LOAD CSV implementation that fails to validate HTTP/HTTPS URLs

ArcadeDB before 26.8.1 contains a server-side request forgery vulnerability in the OpenCypher LOAD CSV implementation that fails to validate HTTP/HTTPS URLs. Authenticated attackers can craft LOAD CSV queries pointing to internal network…

▾ TwilightEPSS 0.35%via NVD
CVE-2026-66794Critical· 9.3
1mo ago

A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes

A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks…

▾ MidnightRed Hat · multicluster-engine/cluster-proxy-addon-rhel9EPSS 0.62%via NVD
CVE-2026-62680High· 7.1
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.22.0, Orval resolves remote and local external $ref values without an allowlist or confinement to the input directory. P…

▾ Twilightorval · orvalEPSS 0.40%via NVD
CVE-2026-76239Medium· 6.3
1mo ago

Stigmem before 0.9.0a11 fails to validate the delivery_address parameter when creating webhook subscriptions, allowing authenticated users to specify internal loopback and private network destinations

Stigmem before 0.9.0a11 fails to validate the delivery_address parameter when creating webhook subscriptions, allowing authenticated users to specify internal loopback and private network destinations. Attackers can trigger matching fact…

▾ Sunlitstigmem-node · stigmem-nodeEPSS 0.32%via NVD
GHSA-p77j-g7h5-r2vwHigh
1mo ago

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

▾ Twilightgeolens · geolensvia GHSA
CVE-2026-54491High· 7.1
1mo ago

Koel is a free, open-source music streaming solution

Koel is a free, open-source music streaming solution. Prior to 9.7.1, outbound podcast and radio fetch paths perform a point-in-time App\Helpers\Network::isPublicHost() or isSafeUrl() check without pinning the validated address, and most…

▾ Twilightphanan · phanan/koelEPSS 0.38%via NVD
CVE-2026-54494Medium
1mo ago

Koel is a free, open-source music streaming solution

Koel is a free, open-source music streaming solution. Prior to 9.7.1, App\Helpers\Network::isPublicHost() uses filter_var() with FILTER_FLAG_NO_PRIV_RANGE and FILTER_FLAG_NO_RES_RANGE, which treats NAT64 64:ff9b::/96 and 6to4 2002::/16 w…

▾ Sunlitphanan · phanan/koelEPSS 0.43%via NVD
CVE-2026-54492Medium· 4.3
1mo ago

Koel is a free, open-source music streaming solution

Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible createPodcastChannel.view route accepts an authenticated user's private URL because app/Http/Requests/Subsonic/CreatePodcastChannelRequest.php …

▾ Sunlitphanan · phanan/koelEPSS 0.41%via NVD
CVE-2026-54493High· 7.7
1mo ago

Koel is a free, open-source music streaming solution

Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible createInternetRadioStation.view and updateInternetRadioStation.view routes accept an authenticated user's streamUrl without the SafeUrl and Has…

▾ Twilightphanan · phanan/koelEPSS 0.41%via NVD
CVE-2026-12564Critical· 9.6
1mo ago

A flaw was found in the AAP Controller's HashiCorp Vault credential plugin

A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-c…

▾ MidnightRed Hat · automation-controllerEPSS 0.35%via NVD
CVE-2026-75898High· 8.5PoC
1mo ago

RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py)

RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The component builds an outbound request URL from canvas configuration and runtime template …

▾ Midnightinfiniflow · ragflowEPSS 0.39%via NVD
CVE-2026-65985None
1mo ago

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the device-webapi-request Socket.IO handler in server/runtime/index.js permits an authenticated non-admin runtime user to control property.ad…

▾ SunlitEPSS 0.46%via NVD
CVE-2026-45123Medium· 4.3
1mo ago

MyBB is free and open source forum software

MyBB is free and open source forum software. Prior to 1.8.40, the remote requests feature does not correctly handle IPv6 addresses, resulting in a server-side request forgery vulnerability. The default disallowed remote hosts list does n…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-75856High· 8.6
1mo ago

CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-use attacks

CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-use attacks. Attackers can manipulate DNS responses to fail initial resolution checks an…

▾ Twilightdeepseek-tui · deepseek-tuiEPSS 0.50%via NVD
CVE-2026-70666High· 7.4
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.3, an authority-role member could update acme_url through PUT /api/1/authorities/ without revalidation and direct setup_acme_client_no_retry to an attacker-controlled ACME server. ACME…

▾ Twilightlemur · lemurEPSS 0.22%via NVD
CVE-2026-70667Medium· 6.3
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_revocation_url in lemur/certificates/verify.py checked the original CRL or OCSP URL but the later request could reach a different destination. The CRL requests.get call fo…

▾ Sunlitlemur · lemurEPSS 0.18%via NVD
CWE-918 vulnerabilities (CVEs) — page 14 · VulnSea