VulnSea

CWE-918

CVEs classified under CWE-918, newest first.

840 CVEsRSS

CVE-2026-42043High· 7.2PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to complet…

▾ Midnightaxios · axiosEPSS 0.58%via NVD
CVE-2026-32210Critical· 9.3
5mo ago

Microsoft Dynamics 365 (online) Spoofing Vulnerability

Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.

▾ MidnightMicrosoft · Microsoft Dynamics 365 (online)EPSS 0.73%via CVEORG
CVE-2026-26150High· 8.6
5mo ago

Microsoft Purview eDiscovery Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Microsoft Purview eDiscoveryEPSS 1.1%via CVEORG
CVE-2026-35431Critical· 10.0
5mo ago

Microsoft Entra ID Entitlement Management Spoofing Vulnerability

Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.

▾ MidnightMicrosoft · Microsoft EntraEPSS 0.90%via CVEORG
CVE-2026-33626High· 7.5PoC
5mo ago

LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading

LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading

▾ Midnightlmdeploy · lmdeployEPSS 1.5%via GHSA
CVE-2026-6587Medium· 6.3
5mo ago

A security flaw has been discovered in vibrantlabsai RAGAS up to 0.4.3

A security flaw has been discovered in vibrantlabsai RAGAS up to 0.4.3. The affected element is the function _try_process_local_file/_try_process_url of the file src/ragas/metrics/collections/multi_modal_faithfulness/util.py of the compo…

▾ SunlitEPSS 0.36%via NVD
CVE-2026-56275Medium· 7.1
5mo ago

Flowise Execute Flow function has an SSRF vulnerability

Flowise Execute Flow function has an SSRF vulnerability

▾ Sunlitflowise · flowiseEPSS 0.32%via GHSA
CVE-2026-40500Medium· 6.8
5mo ago

ProcessWire CMS version 3.0.255 and prior contain a server-side request forgery vulnerability in the admin panel's 'Add Module From URL' feature that allows authenticated administrators to supply arbitrary URLs to the module download par…

ProcessWire CMS version 3.0.255 and prior contain a server-side request forgery vulnerability in the admin panel's 'Add Module From URL' feature that allows authenticated administrators to supply arbitrary URLs to the module download par…

▾ SunlitEPSS 0.39%via NVD
CVE-2026-5936High· 8.5
5mo ago

An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations

An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. This behavior may be exploited to probe internal network services, access otherwise unreach…

▾ Twilightfoxit · pdf_services_apiEPSS 0.34%via NVD
CVE-2026-40175Medium· 4.8PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leveraged to inje…

▾ Twilightaxios · axiosEPSS 1.3%via NVD
CVE-2025-62718Critical· 9.9PoC⚖ disputed
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a tra…

▾ Abyssalaxios · axiosEPSS 1.2%via NVD
CVE-2026-31017Critical· 9.1
5mo ago

A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered into PDF

A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered into PDF. When genera…

▾ Midnightfrappe · erpnextEPSS 0.42%via NVD
CVE-2023-46945Critical· 9.1
5mo ago

QD 20230821 is vulnerable to Server-side request forgery (SSRF) via a crafted request

QD 20230821 is vulnerable to Server-side request forgery (SSRF) via a crafted request

▾ Midnightqd-today · qdEPSS 0.24%via NVD
CVE-2026-1343High· 7.2
5mo ago

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 allows an att…

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 allows an att…

▾ Twilightibm · security_verify_accessEPSS 0.20%via NVD
CVE-2026-32591Medium· 5.2
5mo ago

A flaw was found in Red Hat Quay's Proxy Cache configuration feature

A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy caching, Quay makes a network connection to the specified registry hostname without verify…

▾ Sunlitredhat · mirror_registry_for_red_hat_openshiftEPSS 0.46%via NVD
CVE-2026-2377Medium· 6.5
5mo ago

A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift

A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products allows an authenticated user to specify an arbitrary callback URL. A backend process then makes server-side HTTP request…

▾ Sunlitredhat · mirror_registry_for_red_hat_openshiftEPSS 0.40%via NVD
CVE-2026-5633High· 7.3
5mo ago

A vulnerability was determined in assafelovic gpt-researcher up to 3.4.3

A vulnerability was determined in assafelovic gpt-researcher up to 3.4.3. Affected is an unknown function of the component ws Endpoint. Executing a manipulation of the argument source_urls can lead to server-side request forgery. It is p…

▾ TwilightEPSS 0.47%via NVD
CVE-2026-5623Medium· 6.3
5mo ago

A vulnerability was identified in hcengineering Huly Platform 0.7.382

A vulnerability was identified in hcengineering Huly Platform 0.7.382. This affects an unknown part of the file server/front/src/index.ts of the component Import Endpoint. Such manipulation leads to server-side request forgery. The attac…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-5618Medium· 5.6
5mo ago

A vulnerability was detected in kalcaddle kodbox up to 1.64

A vulnerability was detected in kalcaddle kodbox up to 1.64. This affects an unknown function of the component shareMake/shareCheck. Performing a manipulation of the argument siteFrom/siteTo results in server-side request forgery. The at…

▾ SunlitEPSS 0.40%via NVD
CVE-2026-5607Medium· 6.3
5mo ago

A security vulnerability has been detected in imprvhub mcp-browser-agent up to 0.8.0

A security vulnerability has been detected in imprvhub mcp-browser-agent up to 0.8.0. This impacts the function CallToolRequestSchema of the file src/handlers.ts of the component URL Parameter Handler. The manipulation of the argument re…

▾ SunlitEPSS 0.45%via NVD
CVE-2026-5530Medium· 6.3PoC
5mo ago

A flaw has been found in Ollama up to 0.18.1

A flaw has been found in Ollama up to 0.18.1. This issue affects some unknown processing of the file server/download.go of the component Model Pull API. Executing a manipulation can lead to server-side request forgery. The attack can be …

▾ TwilightEPSS 0.35%via NVD
CVE-2026-22664High· 7.7
5mo ago

prompts.chat prior to commit 30a8f04 contains a server-side request forgery vulnerability in the Fal.ai media status polling feature that allows authenticated users to perform arbitrary outbound requests by supplying attacker-controlled …

prompts.chat prior to commit 30a8f04 contains a server-side request forgery vulnerability in the Fal.ai media status polling feature that allows authenticated users to perform arbitrary outbound requests by supplying attacker-controlled …

▾ Twilightfka · prompts.chatEPSS 0.30%via NVD
CVE-2026-22662Medium· 4.3
5mo ago

prompts.chat prior to commit 1464475 contains a blind server-side request forgery vulnerability in the Wiro media generator that allows authenticated users to perform server-side fetches of user-controlled inputImageUrl parameters

prompts.chat prior to commit 1464475 contains a blind server-side request forgery vulnerability in the Wiro media generator that allows authenticated users to perform server-side fetches of user-controlled inputImageUrl parameters. Attac…

▾ Sunlitfka · prompts.chatEPSS 0.19%via NVD
CVE-2026-28798Critical· 9.0
5mo ago

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. Prior to version 1.5.3, a proxy endpoint (/v1/sys/proxy) exposed by ZimaOS's web interface can be abused (via an externally reachable domain u…

▾ Midnightzimaspace · zimaosEPSS 0.53%via NVD
CVE-2026-32186Critical· 10.0
5mo ago

Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.

Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · bingEPSS 0.90%via NVD
CVE-2026-31818Critical· 9.6
5mo ago

Budibase is an open-source low-code platform

Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector. The platform's SSRF protection mechanism (IP blacklist) is rendered…

▾ Midnightbudibase · budibaseEPSS 0.43%via NVD
CVE-2026-33107Critical· 10.0
5mo ago

Azure Databricks Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure DatabricksEPSS 0.90%via CVEORG
CVE-2026-26135Critical· 9.6
5mo ago

Azure Custom Locations Resource Provider (RP) Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure Custom Locations Resource ProviderEPSS 0.75%via CVEORG
CVE-2026-32871Critical· 10.0
5mo ago

FastMCP is a Pythonic way to build MCP servers and clients

FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The RequestDirector class is responsible for const…

▾ Midnightjlowin · fastmcpEPSS 1.4%via NVD
CVE-2026-34443Medium· 5.3
6mo ago

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, checkIpByMask() in app/Misc/Helper.php checks whether the input IP contains a / character. Plain IP addresses never contain /, s…

▾ Sunlitfreescout · freescoutEPSS 0.40%via NVD
CWE-918 vulnerabilities (CVEs) — page 26 · VulnSea