VulnSea

CWE-918

CVEs classified under CWE-918, newest first.

698 CVEsRSS

CVE-2026-54507High· 8.4
4d ago

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, the oEmbedProxy() handler in admin/controller/editor/editor.php accepts an attacker-controlled url parameter and pa…

Twilightgivanz · VvvebEPSS 0.32%via NVD
CVE-2026-93384Low· 3.7
4d ago

Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic

Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security sev…

Sunlitgoogle · chromeEPSS 0.24%via NVD
CVE-2026-54339High· 7.7PoC
4d ago

Glean is a self-hosted RSS reader and personal knowledge management tool

Glean is a self-hosted RSS reader and personal knowledge management tool. Prior to 0.2.6, POST /api/feeds/discover passes an attacker-supplied feed_url to discover_feed(feed_url), creates a subscription through FeedService.create_subscri…

MidnightLeslieLeung · gleanEPSS 0.34%via NVD
CVE-2026-54918Medium· 5.3
4d ago

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. In the affected repository revisions, NETBOX_DT_LIBRARY_URL in tests/test_configuration.py is a free-form tracked constant th…

Sunlitnetbox-community · devicetype-libraryEPSS 0.30%via NVD
CVE-2026-54565Medium· 4.7
4d ago

rhwp is an HWP viewer and editor implemented in Rust and WebAssembly

rhwp is an HWP viewer and editor implemented in Rust and WebAssembly. Prior to rhwp 0.7.15 and rhwp Chrome and Firefox extension 0.2.4, the browser extensions use an all-URLs host permission to detect HWP and HWPX links on visited pages,…

Sunlitedwardkim · rhwpEPSS 0.13%via NVD
CVE-2026-45723Low· 2.7
4d ago

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementServer.CreateSchematic in internal/backend/grpc/schematics.go passes the caller-controlled TalosVersion field to imageFactoryClie…

Sunlitsiderolabs · omniEPSS 0.39%via NVD
CVE-2026-86862Medium· 6.5
4d ago

pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbname option given to pg_restore and psql

pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbname option given to pg_restore and psql. libpq expands a database name containing an equals sign into a full connecti…

Sunlitpgadmin · pgadmin_4EPSS 0.20%via NVD
CVE-2026-81446High· 7.4
4d ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Server…

TwilightDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.37%via NVD
CVE-2026-61793Medium· 6.9PoC
4d ago

Nuxt OG Image generates OG Images with Vue templates in Nuxt

Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthenticated /_og/d/** route when the documented defaults security.strict = false and security.secret = "" are used, and b…

Twilightnuxt-modules · og-imageEPSS 0.46%via NVD
CVE-2026-81443Medium· 6.4
4d ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-s…

SunlitDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.23%via NVD
CVE-2026-66608Medium· 6.4
4d ago

Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions.

Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions.

SunlitUnlimited Elements · unlimited-elements-for-elementorEPSS 0.17%via NVD
CVE-2026-92932Medium· 5.1
4d ago

In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in the conditional that gates network-based XML fetching

In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in the conditional that gates network-based XML fetching. The original condition was written as: $options['readFile'] &…

Sunlitmisp · sachertortephpEPSS 0.23%via NVD
CVE-2026-54546Medium· 5.0PoC
4d ago

CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK

CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to 13.22.1, the authenticated PUT /api/basemap endpoint passes an attacker-controlled URL through importBasemapURL() in api/ro…

Twilightdfpc-coe · CloudTAKEPSS 0.27%via NVD
CVE-2026-92576High· 8.6PoC
5d ago

HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses

HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instruc…

MidnightHKUDS · nanobotEPSS 0.40%via NVD
CVE-2026-92527Medium· 6.3
5d ago

A vulnerability has been found in chatwoot up to 4.17.1

A vulnerability has been found in chatwoot up to 4.17.1. This impacts an unknown function of the file callbacks_controller.rb of the component Shopify OAuth. The manipulation leads to server-side request forgery. Remote exploitation of t…

SunlitEPSS 0.35%via NVD
CVE-2025-56563Critical· 9.8PoC
5d ago

A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0

A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0. The script accepts an attacker-controlled address URL parameter and passes it to curl_setopt(CURLOPT_URL) without host or scheme validat…

AbyssalEPSS 0.40%via NVD
CVE-2026-92775Medium· 6.5PoC
5d ago

Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches arbitrary URLs without protocol, host, or address validation

Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches arbitrary URLs without protocol, host, or address validation. Attackers with page editing permissions can inject img…

Twilightrequarks · Wiki.jsEPSS 0.30%via NVD
CVE-2026-92789Medium· 6.5
5d ago

Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after following HTTP redirects

Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after following HTTP redirects. Attackers with lookup table or event notification permissions can craft allowlisted endpoi…

SunlitGraylog2 · graylog2-serverEPSS 0.30%via NVD
CVE-2026-92795Medium· 6.5PoC
5d ago

Coze Studio through 0.5.1 fails to restrict the server URL supplied when registering plugin tools, allowing authenticated users to make the backend fetch internal services

Coze Studio through 0.5.1 fails to restrict the server URL supplied when registering plugin tools, allowing authenticated users to make the backend fetch internal services. Attackers can construct plugin requests to access cloud metadata…

Twilightcoze-dev · coze-studioEPSS 0.24%via NVD
CVE-2026-92804High· 7.1
5d ago

Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token and proxy URL templates

Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token and proxy URL templates. Authenticated attackers can supply malicious configuration values to direct server requests …

TwilightNangoHQ · NangoEPSS 0.28%via NVD
CVE-2026-92815High· 7.5PoC
5d ago

changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attackers to access internal addresses

changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attackers to access internal addresses. Attackers can supply arbitrary internal URLs in the optional_value parameter to re…

Midnightdgtlmoon · changedetection.ioEPSS 0.41%via NVD
CVE-2026-92813Medium· 4.9PoC
5d ago

Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing unauthenticated attackers to reach loopback services

Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing unauthenticated attackers to reach loopback services. Attackers can save a malicious GeoJSON entry with 0.0.0.0 and trig…

Twilightmetabase · MetabaseEPSS 0.29%via NVD
CVE-2026-92808Critical· 10.0
5d ago

A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server

A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unauthenticated network attacker can cause the server to issue outbound HTTP requests to a destination of the attacker'…

MidnightAltium · Altium Enterprise ServerEPSS 0.32%via NVD
CVE-2026-87116Medium· 6.5
5d ago

Tanium addressed a server-side request forgery vulnerability in Threat Response.

Tanium addressed a server-side request forgery vulnerability in Threat Response.

SunlitTanium · Threat ResponseEPSS 0.25%via NVD
CVE-2026-59823Medium· 5.3
5d ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.9, an authenticated LiteLLM Proxy caller with a valid virtual key can place api_base inside the user_config request body to bypass is_req…

SunlitBerriAI · litellmEPSS 0.44%via NVD
CVE-2026-68536Critical· 9.8
5d ago

Server-Side Request Forgery / Local File Inclusion in Apache MyFace Core. Older unsupported versions may also be affected.  Users are recommended to upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which fix this issue.

Server-Side Request Forgery / Local File Inclusion in Apache MyFace Core. Older unsupported versions may also be affected.  Users are recommended to upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which fix this issue.

MidnightApache Software Foundation · org.apache.myfaces.core:myfaces-implEPSS 0.47%via NVD
CVE-2026-92719High· 7.5PoC
5d ago

Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, allowing attackers to make the node issue requests to arbitrary internal addresses

Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, allowing attackers to make the node issue requests to arbitrary internal addresses. Attackers can supply a malicious queue_url t…

Midnightquickwit-oss · quickwitEPSS 0.42%via NVD
CVE-2026-92602High· 7.1PoC
5d ago

TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigController

TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigController. Authenticated attackers can attach webhooks to other users' forms and exfiltrate submissions to arbitrary exter…

MidnightTDuckCloud · tduck-survey-formEPSS 0.30%via NVD
CVE-2026-85732Medium· 4.7PoC
5d ago

oras-go is a Go library for managing OCI artifacts

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/utils.go accepts an absolute URL from a registry-controlled Link response header without validating its scheme, host, or port. …

Twilightoras-project · oras-goEPSS 0.38%via NVD
CVE-2026-92380High· 7.3PoC
5d ago

A flaw has been found in WuzhiCMS up to 4.1.0

A flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is the function ckditor::saveRemote of the file coreframe/app/attachment/index.php of the component Remote Image Fetch. This manipulation of the argument source[] causes…

MidnightEPSS 0.47%via NVD
CWE-918 vulnerabilities (CVEs) — page 2 · VulnSea