VulnSea

CWE-918

CVEs classified under CWE-918, newest first.

838 CVEsRSS

CVE-2026-71303High· 7.7
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_acme_url enforced ACME_DIRECTORY_HOST_ALLOWLIST when an authority was created, but PUT /api/1/authorities/ passed options to lemur/authorities/service.py without applying …

▾ Twilightlemur · lemurEPSS 0.28%via NVD
GHSA-7gww-x7fh-jf9jHigh· 8.1
1mo ago

LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page

LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page

▾ Twilightlibrenms · librenms/librenmsvia GHSA
CVE-2026-63642MediumPoC
1mo ago

MagicMirror² is an open source modular smart mirror platform

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, checkArticleUrl in defaultmodules/newsfeed/node_helper.js accepts the CHECK_ARTICLE_URL notification through the unauthenticated Socket.IO namespace /newsfeed…

▾ Twilightmagicmirror · magicmirrorEPSS 0.50%via NVD
CVE-2026-63643Medium
1mo ago

MagicMirror² is an open source modular smart mirror platform

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, the ADD_CALENDAR handler in defaultmodules/calendar/node_helper.js accepts an attacker-controlled URL, authentication data, and selfSignedCert setting through…

▾ Sunlitmagicmirror · magicmirrorEPSS 0.66%via NVD
CVE-2026-68927Low· 3.0
1mo ago

MobSF is a mobile application security testing tool used

MobSF is a mobile application security testing tool used. Prior to 4.5.1, get_browsable_activities in mobsf/StaticAnalyzer/views/android/manifest_analysis.py validates only an Android manifest android:host value with valid_host before ap…

▾ Sunlitmobsf · mobsfEPSS 0.33%via NVD
CVE-2026-47719High· 8.2
1mo ago

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY Socket.IO handlers in server/runtime/index.js omit isSocketWriteAuthorized and accept attacker-contro…

▾ Twilightfuxa-server · fuxa-serverEPSS 0.59%via NVD
CVE-2026-50143High· 8.1
1mo ago

The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store

The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior to 0.10.11, getActorMCPServerURL in src/mcp/actors.ts concatenates the tru…

▾ Twilightapify · @apify/actors-mcp-serverEPSS 0.49%via NVD
CVE-2026-55162Medium· 6.3
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.2, lemur/certificates/verify.py accepted CRL Distribution Point and OCSP responder URLs from uploaded certificate extensions and used them in crl_verify and ocsp_verify without adequat…

▾ Sunlitlemur · lemurEPSS 0.22%via NVD
CVE-2026-55166Critical· 9.9
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url without an effective server-side destination restriction and trigger AcmeHandler.setup_acme_client to make backend req…

▾ Midnightlemur · lemurEPSS 0.29%via NVD
CVE-2026-75054Medium· 6.3
1mo ago

In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects

In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects

▾ Sunlitjetbrains · intellij_ideaEPSS 0.15%via NVD
CVE-2026-75053Medium· 5.4
1mo ago

In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint

In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint

▾ Sunlitjetbrains · intellij_ideaEPSS 0.24%via NVD
CVE-2026-50775Critical· 9.8
1mo ago

A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the server retrieving an image from a crafted URL, and it fails to return the content or any errors directly.

A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the server retrieving an image from a crafted URL, and it fails to return the content or any errors directly.

▾ MidnightEPSS 0.79%via NVD
CVE-2026-73560Medium· 6.5
1mo ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the MiMoV2OmniMultiModalProcessor in vllm/transformers_utils/processors/mimo_v2_omni.py passes attacker-controlled image and audio strings through _fetch…

▾ Sunlitvllm · vllmEPSS 0.44%via NVD
CVE-2026-73410High· 8.5
1mo ago

Budibase is an open-source low-code platform

Budibase is an open-source low-code platform. Prior to 3.40.0, packages/backend-core/src/utils/outboundFetch.ts pinned a validated address through a Node agent, but the REST integration used getDispatcher from packages/backend-core/src/u…

▾ TwilightEPSS 0.28%via NVD
CVE-2026-75006Medium· 5.8
1mo ago

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts.…

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts.…

▾ Sunlitroundcube · webmailEPSS 0.56%via NVD
CVE-2026-56677High· 8.6
1mo ago

9Router is an AI router & token saver

9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/oidc/test/route.js passes the user-controlled issuerUrl parameter to fetchOidcDiscovery() in src/lib/auth/oidc.js with…

▾ Twilight9router · 9routerEPSS 0.38%via NVD
CVE-2026-64849High· 8.5CISA KEVPoC
1mo ago

mlflow: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS …

A flaw was found in MLflow. An unauthenticated remote attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability by sending a specially crafted request to the webhook test endpoint. This occurs because the system validates onl…

▾ AbyssalRed Hat · Red Hat OpenShift AI 3.4EPSS 9.8%via CSAF
CVE-2026-35219High
1mo ago

Budibase is an open-source low-code platform

Budibase is an open-source low-code platform. Prior to 3.41.3, automation steps in packages/server/src/automations/steps/outgoingWebhook.ts, packages/server/src/automations/steps/zapier.ts, packages/server/src/automations/steps/n8n.ts, p…

▾ Twilightbudibase · @budibase/serverEPSS 0.46%via NVD
CVE-2026-48053Medium· 5.8
1mo ago

Kolibri is an offline-first education platform

Kolibri is an offline-first education platform. Prior to version 0.19.4, several Kolibri API endpoints accept an unvalidated `baseurl` parameter and fetch attacker-controlled URLs from the Kolibri server, reflecting the response body bac…

▾ Sunlitkolibri · kolibriEPSS 0.38%via NVD
CVE-2026-17123High· 8.8
1mo ago

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attack…

▾ TwilightEPSS 0.63%via NVD
CVE-2026-19927Medium· 6.3
1mo ago

A vulnerability was found in OpenBoxes up to 0.9.7

A vulnerability was found in OpenBoxes up to 0.9.7. The impacted element is the function Upload of the file grails-app/controllers/org/pih/warehouse/product/ProductController.groovy of the component Product Upload Endpoint. Performing a …

▾ SunlitEPSS 0.44%via NVD
CVE-2026-73845Medium· 5.3
1mo ago

CKAN MCP Server is a tool for querying CKAN open data portals

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in src/tools/quality.ts use isValidMqaServer to validate the server_url parameter with a pre…

▾ Sunlitaborruso · @aborruso/ckan-mcp-serverEPSS 0.38%via NVD
CVE-2026-46380Medium· 6.7
1mo ago

compliance-trestle is a tooling platform for managing compliance as code

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSFetcher._do_fetch() method passes a user-supplied URL directly to requests.get() without validation. This allows an at…

▾ Sunlitcompliance-trestle · compliance-trestleEPSS 0.14%via NVD
CVE-2026-73530High· 7.7
1mo ago

Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that allows attackers to reach internal services by supplying URLs using the unblocked IPv6 address `::` which the kernel routes to loopback iden…

Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that allows attackers to reach internal services by supplying URLs using the unblocked IPv6 address `::` which the kernel routes to loopback iden…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-72777High· 8.6PoC
1mo ago

Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation that only checks string patterns without DNS resolution

Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation that only checks string patterns without DNS resolution. Unauthenticated attackers can sup…

▾ MidnightDayuanJiang · next-ai-draw-ioEPSS 0.43%via NVD
CVE-2026-73629High· 8.5
1mo ago

Serendipity before 2.6.0 contains a server-side request forgery vulnerability in the serendipity_url_allowed() filter that fails to block hex-encoded IPv4 addresses, IPv6 literals, and link-local ranges

Serendipity before 2.6.0 contains a server-side request forgery vulnerability in the serendipity_url_allowed() filter that fails to block hex-encoded IPv4 addresses, IPv6 literals, and link-local ranges. Authenticated users with adminIma…

▾ TwilightEPSS 0.32%via NVD
CVE-2026-46382None
1mo ago

The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms

The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, a user-supplied private/local URI can be made to be fetched without checks. Version 1.12.2 contains a fix. No known wor…

▾ SunlitEPSS 0.42%via NVD
CVE-2026-54249Medium· 6.8
1mo ago

Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials

Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials

▾ Sunlitpydantic-ai-slim · pydantic-ai-slimEPSS 0.32%via GHSA
CVE-2026-49856Medium· 4.3
1mo ago

@jshookmcp/jshook is an MCP server that gives AI agents tools for JavaScript analysis and security research

@jshookmcp/jshook is an MCP server that gives AI agents tools for JavaScript analysis and security research. In version 0.3.1, he network domain has a central SSRF authorization policy that blocks private, loopback, link-local, and reser…

▾ Sunlitjshookmcp · @jshookmcp/jshookEPSS 0.28%via NVD
CVE-2026-49857High· 7.4
1mo ago

auth-fetch-mcp is an MCP server that lets AI assistants fetch content from authenticated web pages

auth-fetch-mcp is an MCP server that lets AI assistants fetch content from authenticated web pages. Version 3.0.1 implements SSRF protection in `assertSafeUrl()` (`src/security.ts`) to block requests to private and loopback addresses. Ho…

▾ Twilightauth-fetch-mcp · auth-fetch-mcpEPSS 0.49%via NVD
CWE-918 vulnerabilities (CVEs) — page 15 · VulnSea