VulnSea

CWE-918

CVEs classified under CWE-918, newest first.

838 CVEsRSS

CVE-2026-49478High· 8.7⚖ disputed
1mo ago

Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity

Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discover…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.28%via NVD
CVE-2026-73297None
1mo ago

Microsoft UFO open-source framework for intelligent automation across devices and platforms

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, _is_blocked_ip in ufo/utils/url_security.py did not block NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48, the 6to4 prefix 2002::…

▾ SunlitEPSS 2.9%via NVD
CVE-2026-73264High· 7.6
1mo ago

Prowler is a cloud security platform

Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration access could supply an unvalidated base_url for the openai_compatible provider through POST /api/v1/lighthouse/providers …

▾ TwilightEPSS 0.43%via NVD
CVE-2026-73307None
1mo ago

Budibase is an open-source low-code platform

Budibase is an open-source low-code platform. Prior to 3.39.4, uploadUrl in packages/server/src/utilities/fileUtils.ts used a bare server-side fetch for string attachment values passed by processAttachments in packages/server/src/sdk/wor…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-70467Low· 3.8
1mo ago

A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6…

A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6…

▾ Sunlitfortinet · fortisiemEPSS 0.26%via NVD
CVE-2026-65941High· 8.8
1mo ago

In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.

In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.

▾ TwilightEPSS 0.68%via NVD
CVE-2026-18952High· 8.1
1mo ago

Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter …

Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter …

▾ TwilightEPSS 0.52%via NVD
CVE-2026-49262Low· 3.0
1mo ago

In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is vulnerable to a Server-Side Request Forgery (SSRF) attack via DNS Rebinding

In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is vulnerable to a Server-Side Request Forgery (SSRF) attack via DNS Rebinding. A Time-of-Check to Time-of-Use (TOCTOU) …

▾ Sunlitaimeos · aimeos/pagibleEPSS 0.17%via NVD
CVE-2026-73247High· 8.6
1mo ago

Kestra is an open-source, event-driven orchestration platform

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/functions/HttpFunction.java passes the user-controlled http() uri argument to URI.create() and the s…

▾ Twilightkestra · io.kestra:coreEPSS 0.41%via NVD
CVE-2026-48762Medium· 5.4
1mo ago

TypeBot is a chatbot builder tool

TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI "Create Transcription" action handler fetches a user-supplied audio URL using `fetch()` without applying the SSRF protection that exists elsewhere in the codebase. An…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-73243Medium· 5.8
1mo ago

kkFileView is a universal file online preview project based on Spring Boot

kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated GET /addTask endpoint in kkFileView is omitted from TrustHostFilter and TrustDirFilter in server/src/main/java/cn/keking/conf…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-73212None
1mo ago

Coturn is a free open source implementation of TURN and STUN Server

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.1, good_peer_addr() in src/server/ns_turn_server.c uses ioa_addr_in_range() in src/client/ns_turn_ioaddr.c without canonicalizing IPv4-compatible, 6to4, a…

▾ SunlitEPSS 0.50%via NVD
CVE-2026-73082None
1mo ago

Activepieces is an open source AI workflow automation platform

Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the POST /api/v1/projects/:projectId/mcp-server/validate-agent-mcp-tool endpoint makes an outbound HTTP or SSE request to a user-supplied serverUrl without …

▾ SunlitEPSS 0.43%via NVD
CVE-2026-48483Medium· 5.4
1mo ago

TypeBot is a chatbot builder tool

TypeBot is a chatbot builder tool. Prior to version 3.17.0, Typebot's WhatsApp status forwarding feature stores a workspace-configured webhook forwarding URL and later POSTs WhatsApp marketing/error status events to it from the server. T…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-13739Critical· 9.8
1mo ago

A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs

A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance release. Update Comm…

▾ Midnightcommvault · commvaultEPSS 0.39%via NVD
CVE-2026-72784Medium· 5.4
1mo ago

Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulnerability in the GraphQL save<Volume>Asset mutation, which fetches an attacker-supplied URL server-side

Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulnerability in the GraphQL save<Volume>Asset mutation, which fetches an attacker-supplied URL server-side. The anti-SSRF…

▾ SunlitEPSS 0.24%via NVD
CVE-2026-70324High· 8.8
1mo ago

Microsoft SharePoint Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.94%via CVEORG
CVE-2026-70326High· 8.8
1mo ago

Microsoft SharePoint Server Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Microsoft SharePoint Server Subscription EditionEPSS 0.78%via CVEORG
CVE-2026-73087Low
1mo ago

Dozzle is a realtime log viewer for docker containers

Dozzle is a realtime log viewer for docker containers. From 10.5.2 until 10.6.15, the isBlockedIP SSRF guard in internal/notification/dispatcher/webhook.go, used by safeDialContext for webhook notification URLs, does not inspect IPv4 add…

▾ Sunlitamir20 · github.com/amir20/dozzleEPSS 0.46%via NVD
CVE-2026-58612High· 7.4
1mo ago

PowerShell Information Disclosure Vulnerability

Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.

▾ TwilightMicrosoft · PowerShell 7.4EPSS 0.87%via CVEORG
CVE-2026-65813Medium· 6.5
1mo ago

Microsoft Exchange Server Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

▾ SunlitMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 0.94%via CVEORG
CVE-2026-58639Medium· 6.5
1mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.91%via CVEORG
CVE-2026-50237High· 7.4
1mo ago

A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy

A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches server-side, bypassin…

▾ TwilightRed Hat · openshift4/ose-consoleEPSS 0.47%via NVD
CVE-2026-50236High· 7.4
1mo ago

An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers

An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full resp…

▾ TwilightRed Hat · openshift4/ose-consoleEPSS 0.47%via NVD
CVE-2026-62902Medium· 6.5
1mo ago

.NET Information Disclosure Vulnerability

Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.

▾ SunlitMicrosoft · .NET 8.0EPSS 0.87%via CVEORG
CVE-2026-73080Critical· 9.3
1mo ago

SeaweedFS is a distributed storage system

SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a caller-supplied remote endpoint through weed/remote_storage/s3/s3_storage_client.go and writes the …

▾ Midnightseaweedfs · github.com/seaweedfs/seaweedfsEPSS 0.53%via NVD
CVE-2026-72916None
1mo ago

Mastodon is a free, open-source social network server based on ActivityPub

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, PrivateAddressCheck.private_address? in app/lib/private_address_check.rb normalized IPv4-mapped IPv6 addresses …

▾ SunlitEPSS 0.59%via NVD
CVE-2026-72591High· 7.7
1mo ago

A server-side request forgery (SSRF) vulnerability in gabehf/Koito through v0.3.2 allows an authenticated user to make the server perform HTTP requests to arbitrary internal or external hosts by supplying a crafted image_url value in the…

A server-side request forgery (SSRF) vulnerability in gabehf/Koito through v0.3.2 allows an authenticated user to make the server perform HTTP requests to arbitrary internal or external hosts by supplying a crafted image_url value in the…

▾ TwilightEPSS 0.37%via NVD
CVE-2026-72581High· 8.6
1mo ago

A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to make the Xiaomi smart speaker perform HTTP requests to arbitrary internal or external URLs

A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to make the Xiaomi smart speaker perform HTTP requests to arbitrary internal or external URLs. The /auth endpoint in…

▾ TwilightEPSS 0.50%via NVD
CVE-2026-72566High· 7.7
1mo ago

A server-side request forgery (SSRF) vulnerability in automatisch through commit 41f3c56 allows a low-privileged authenticated user with 'manage Flow' permission to make the server fetch arbitrary URLs and retrieve the full response body…

A server-side request forgery (SSRF) vulnerability in automatisch through commit 41f3c56 allows a low-privileged authenticated user with 'manage Flow' permission to make the server fetch arbitrary URLs and retrieve the full response body…

▾ TwilightEPSS 0.35%via NVD
CWE-918 vulnerabilities (CVEs) — page 16 · VulnSea