VulnSea

CWE-918

CVEs classified under CWE-918, newest first.

840 CVEsRSS

CVE-2026-48146High· 7.7
3mo ago

Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection

Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection

▾ Twilightbudibase · @budibase/serverEPSS 0.34%via GHSA
CVE-2025-58175Medium· 6.5
3mo ago

GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution

GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution

▾ Sunlitgeoserver · org.geoserver.web:gs-web-appEPSS 0.47%via GHSA
CVE-2026-48148Medium
3mo ago

Budibase: Unvalidated VectorDB Host Parameter Enables SSRF

Budibase: Unvalidated VectorDB Host Parameter Enables SSRF

▾ Sunlitbudibase · @budibase/serverEPSS 0.35%via GHSA
CVE-2026-40999High· 8.6
3mo ago

When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServiceMessageSender instances to destinations taken directly from request headers without veri…

When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServiceMessageSender instances to destinations taken directly from request headers without veri…

▾ Twilightbroadcom · spring_web_servicesEPSS 0.43%via NVD
CVE-2026-48998Medium· 5.3
3mo ago

guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation

guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation

▾ Sunlitguzzlehttp · guzzlehttp/psr7EPSS 0.31%via GHSA
CVE-2026-44492High· 8.6PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a request URL us…

▾ Midnightaxios · axiosEPSS 0.78%via NVD
CVE-2026-48051Low· 3.5
3mo ago

Papra HTTP redirect bypass can lead to SSRF via webhook delivery system

Papra HTTP redirect bypass can lead to SSRF via webhook delivery system

▾ Sunlitpapra · @papra/webhooksEPSS 0.26%via GHSA
CVE-2026-47938Critical· 10.0
3mo ago

Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation

Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction…

▾ Midnightadobe · campaignEPSS 0.95%via NVD
CVE-2026-45504High· 8.8PoC
3mo ago

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · exchange_serverEPSS 0.78%via NVD
CVE-2026-45503High· 8.1
3mo ago

Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

▾ Twilightmicrosoft · exchange_serverEPSS 0.86%via NVD
CVE-2026-45502Medium· 5.0
3mo ago

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · exchange_serverEPSS 0.64%via NVD
CVE-2026-45501Medium· 6.5
3mo ago

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

▾ Sunlitmicrosoft · exchange_serverEPSS 0.46%via NVD
CVE-2026-41854Medium· 4.2
3mo ago

Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack. Affected versions: Spring Framework 7.0…

Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack. Affected versions: Spring Framework 7.0…

▾ Sunlitvmware · spring_frameworkEPSS 0.21%via NVD
CVE-2026-39922Medium· 6.3
3mo ago

GeoNode contains a server-side request forgery vulnerability in the service registration endpoint

GeoNode contains a server-side request forgery vulnerability in the service registration endpoint

▾ Sunlitgeonode · geonodeEPSS 0.27%via GHSA
CVE-2026-42965High· 7.7
4mo ago

A flaw was found in the OpenShift Router

A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud metadata endpoin…

▾ Twilightredhat · openshift_container_platformEPSS 0.47%via NVD
CVE-2026-46372High· 8.5PoC
4mo ago

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern exposes /api/search/searx…

▾ MidnightEPSS 1.0%via NVD
CVE-2026-44652None
4mo ago

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, corsProxyMiddleware forwards req.para…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-45660Medium· 5.4
4mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.22 and 6.18.1, the Glide image proxy's URL validation could be bypassed using an IP representation that wasn't normalized before the public-IP check. An…

▾ SunlitEPSS 0.24%via NVD
CVE-2026-9312High· 8.2
4mo ago

A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload…

A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload…

▾ Twilightgithub · enterprise_serverEPSS 0.59%via NVD
CVE-2026-5773High· 7.5PoC
4mo ago

libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connectio…

libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connectio…

▾ Midnighthaxx · curlEPSS 0.66%via NVD
CVE-2026-44578High· 8.6PoC
4mo ago

Next.js is a React framework for building full-stack web applications

Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted…

▾ Midnightvercel · next.jsEPSS 1.9%via NVD
CVE-2026-8328Medium· 5.3
4mo ago

The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed

The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpeername()[0]), ftpcp() still calls parse…

▾ SunlitRed Hat · Red Hat Hardened ImagesEPSS 0.68%via NVD
CVE-2026-34647High· 7.4
4mo ago

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. An attacker could lev…

▾ Twilightadobe · commerceEPSS 0.92%via NVD
CVE-2026-3048Low· 3.8
4mo ago

An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be able to initiate unintended server-side connections when interacting with a malicious LDAP…

An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be able to initiate unintended server-side connections when interacting with a malicious LDAP…

▾ Sunlitsonatype · nexus_repository_managerEPSS 0.29%via NVD
CVE-2026-42188Low· 2.4
4mo ago

Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition

Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition. Prior to 2.9.3, a server-side request forgery (SSRF) vulnerability exists in Geyser’s handling of Bedrock player head texture data. By supplying a crafted…

▾ Sunlitgeysermc · geyserEPSS 0.28%via NVD
CVE-2026-44117Medium· 5.8
4mo ago

OpenClaw < 2026.4.20 - Server-Side Request Forgery in QQBot Direct Media Upload

OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in QQBot direct media upload that skips URL validation. Attackers can bypass SSRF protections by sending crafted image URLs to uploadC2CMedia and uploadGroupM…

▾ SunlitOpenClaw · OpenClawEPSS 0.40%via CVEORG
CVE-2026-44116High· 8.6
4mo ago

OpenClaw < 2026.4.22 - Server-Side Request Forgery in Zalo Photo URL Validation

OpenClaw before 2026.4.22 contains a server-side request forgery vulnerability in the Zalo plugin's sendPhoto function that fails to validate outbound photo URLs through the SSRF guard. Attackers can bypass SSRF protection by providing m…

▾ TwilightOpenClaw · OpenClawEPSS 0.47%via CVEORG
CVE-2026-20035High· 7.2
4mo ago

A vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to conduct SSRF attacks through an affected device. This vulnerability is due to improper input validation for specific …

A vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to conduct SSRF attacks through an affected device. This vulnerability is due to improper input validation for specific …

▾ Twilightcisco · unity_connectionEPSS 0.30%via NVD
CVE-2026-6229High· 7.2
4mo ago

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1057

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1057. This is due to insufficient validation of user-supplied URLs in the render_csv_data() function, whic…

▾ TwilightEPSS 0.48%via NVD
CVE-2026-23773Medium· 4.3
5mo ago

Dell Disk Library for Mainframe, version(s) DLm 8700/2700 contain(s) a Server-Side Request Forgery (SSRF) vulnerability

Dell Disk Library for Mainframe, version(s) DLm 8700/2700 contain(s) a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side re…

▾ SunlitEPSS 0.24%via NVD
CWE-918 vulnerabilities (CVEs) — page 25 · VulnSea