VulnSea

CWE-918

CVEs classified under CWE-918, newest first.

834 CVEsRSS

CVE-2026-95656High· 7.3PoC
5d ago

A vulnerability was found in dgtlmoon changedetection.io up to 50389b07

A vulnerability was found in dgtlmoon changedetection.io up to 50389b07. This vulnerability affects the function add_watch_ui_snapshot of the file changedetectionio/blueprint/add_watch_ui/__init__.py of the component Preview Endpoint. Pe…

▾ Midnightdgtlmoon · changedetection.ioEPSS 0.51%via NVD
CVE-2026-77274High· 8.8PoC
5d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, validate_url_for_ssrf has a backslash authority confusion because it interprets the authority differently from the Requ…

▾ Midnightsooperset · mcp-atlassianEPSS 0.47%via NVD
CVE-2026-82443Critical· 9.6
5d ago

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal reso…

▾ Midnightadobe · campaignEPSS 0.35%via NVD
CVE-2026-82013Critical· 9.9
5d ago

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal reso…

▾ Midnightadobe · campaignEPSS 0.82%via NVD
CVE-2026-83660Critical· 9.9
5d ago

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.

▾ Midnightadobe · campaignEPSS 0.34%via NVD
CVE-2026-77265Medium· 5.9
5d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, header-supplied Jira or Confluence URLs are resolved and validated before the HTTP client resolves the hostname again f…

▾ Sunlitsooperset · mcp-atlassianEPSS 0.26%via NVD
CVE-2026-77267High· 8.3
5d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url headers are processed by _process_authentication_headers and us…

▾ Twilightsooperset · mcp-atlassianEPSS 0.34%via NVD
CVE-2026-85740High· 7.1
5d ago

LightRAG provides simple and fast retrieval-augmented generation

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, _validated_addresses in lightrag/parser/markdown/parser.py evaluates the literal resolved address with ipaddress.is_global without consistently classifying…

▾ TwilightHKUDS · LightRAGEPSS 0.22%via NVD
CVE-2026-84301Medium· 6.3PoC
5d ago

FastGPT is an open-source LLM platform for building AI applications on a knowledge base

FastGPT is an open-source LLM platform for building AI applications on a knowledge base. Prior to 4.15.2, the safe Axios request interceptor in packages/service/common/api/axios.ts validates a hostname with isInternalAddress() before a l…

▾ Twilightlabring · FastGPTEPSS 0.36%via NVD
CVE-2026-80150High· 7.5
5d ago

Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet liste…

Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet liste…

▾ TwilightLANTRONIX · SLC8000EPSS 0.58%via NVD
CVE-2026-80148High· 8.6
5d ago

Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet liste…

Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet liste…

▾ TwilightLANTRONIX · SLC8000EPSS 0.58%via NVD
CVE-2026-79913Medium· 6.5
5d ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, the ValidateExternalURL server-side request forgery guard in pkg/request/ssrf.go passes resolved addresses to checkIP without decoding NAT64, IPv4-compatible…

▾ Sunlitcloudreve · cloudreveEPSS 0.40%via NVD
CVE-2026-80149High· 8.6
5d ago

Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet liste…

Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet liste…

▾ TwilightLANTRONIX · SLC8000EPSS 0.58%via NVD
CVE-2026-75511Medium· 5.3
5d ago

Novu provides an API for sending notifications through multiple channels

Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu accepts chat webhook URLs from subscriber credentials.webhookUrl, channel endpoint endpoint.url, event payload.webhookUrl, and event override…

▾ Sunlitnovuhq · novuEPSS 0.46%via NVD
CVE-2026-95679Medium· 6.9
5d ago

MISP's RequestHandlerComponent automatically decodes XML request bodies on all write requests

MISP's RequestHandlerComponent automatically decodes XML request bodies on all write requests. The underlying Xml::build() library contains a logic error in its readFile guard condition (readFile && http || https), where PHP operator pre…

▾ SunlitMISP · MISPEPSS 0.60%via NVD
CVE-2026-95623Medium· 5.6
5d ago

The Tauri HTTP plugin validates requested URLs against the application's configured scope allowlist only once, on the initial request

The Tauri HTTP plugin validates requested URLs against the application's configured scope allowlist only once, on the initial request. When the remote server responds with an HTTP 3xx redirect, reqwest follows the redirect internally wit…

▾ SunlitTauri · tauri-plugin-httpEPSS 0.24%via NVD
CVE-2026-88403Medium· 6.5PoC
6d ago

A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobase v2.1.21 allows authenticated attackers to scan internal resources via a crafted HTTP request.

A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobase v2.1.21 allows authenticated attackers to scan internal resources via a crafted HTTP request.

▾ TwilightEPSS 0.40%via NVD
CVE-2026-77522Medium· 4.3PoC
6d ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the knowledge web-document import and synchronization crawler passes an authenticated workspace user's URL to Fork.fork, which calls requests.get wit…

▾ Twilight1Panel-dev · MaxKBEPSS 0.30%via NVD
CVE-2026-61749Medium· 6.5
6d ago

InvenTree is an Open Source Inventory Management System

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, privileged staff users who can author report or label templates can cause WeasyPrint report rendering to retrieve attacker-selected resources through the HTTP and H…

▾ Sunlitinventree · InvenTreeEPSS 0.48%via NVD
CVE-2026-55473Medium· 6.0
6d ago

HomeBox is a home inventory and organization system

HomeBox is a home inventory and organization system. Prior to 0.26.0, the default-on BlockBogonNets and BlockCloudMetadata notifier SSRF protections in backend/internal/sys/validate/notifier_url.go do not inspect IPv4 destinations embedd…

▾ Sunlitsysadminsmedia · homeboxEPSS 0.41%via NVD
CVE-2026-61612Medium· 5.7
6d ago

CKAN MCP Server is a tool for querying CKAN open data portals

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to version 0.4.108, the SSRF guard `validateServerUrl` (added for CVE-2026-33060, extended for CVE-2026-53509) validates only the hostname string and never resolves DNS…

▾ Sunlitondata · ckan-mcp-serverEPSS 0.23%via NVD
CVE-2026-63334Medium· 6.8PoC
6d ago

draw.io is a configurable diagramming and whiteboarding application

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, deployments with ENABLE_DRAWIO_PROXY=1 are vulnerable to server-side request forgery because src/main/java/com/mxgraph/online/Utils.java perfor…

▾ Twilightjgraph · drawioEPSS 0.32%via NVD
CVE-2026-76898High· 7.7PoC
6d ago

draw.io is a configurable diagramming and whiteboarding application

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.3.8, src/main/java/com/mxgraph/online/Utils.java checks IPv6 Unique Local Addresses in Utils.sanitizeUrl() by comparing the text prefixes fc00:: and…

▾ Midnightjgraph · drawioEPSS 0.35%via NVD
CVE-2026-36469Critical· 9.1
6d ago

CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) in core/modules/media.php -- upload_from_inet (Media Manager's "Upload by URL" functionality).

CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) in core/modules/media.php -- upload_from_inet (Media Manager's "Upload by URL" functionality).

▾ MidnightEPSS 0.27%via NVD
CVE-2026-61681Medium· 4.1
6d ago

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, the SNS UnsubscribeConfirmation handler in internal/integrations/ingestors/sns/sns.go calls http.Get() on payload.Unsub…

▾ Sunlithatchet-dev · hatchetEPSS 0.31%via NVD
CVE-2026-94401High· 8.3
6d ago

MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access internal network services. When importing an XML file, MISP did not properly verify that the uploaded content was act…

MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access internal network services. When importing an XML file, MISP did not properly verify that the uploaded content was act…

▾ TwilightMISP · MISPEPSS 0.38%via NVD
CVE-2026-94051Medium· 6.3PoC
1w ago

A vulnerability was found in 0717376 cowork_bench up to d943e75bc0fc8e3b27141979300cd8cbcd1e890d

A vulnerability was found in 0717376 cowork_bench up to d943e75bc0fc8e3b27141979300cd8cbcd1e890d. Affected by this vulnerability is the function ControlFlowNode of the file local_servers/pdf-tools-mcp/pdf_tools_mcp/server.py of the compo…

▾ Twilight0717376 · cowork_benchEPSS 0.37%via NVD
CVE-2026-94040Medium· 5.3PoC
1w ago

A flaw has been found in vas3k TaxHacker up to 0.8.5

A flaw has been found in vas3k TaxHacker up to 0.8.5. Affected by this vulnerability is the function testLLMProviderAction of the file app/(app)/apps/settings/actions.ts. Executing a manipulation of the argument provider/apiKey/model/bas…

▾ Twilightvas3k · TaxHackerEPSS 0.53%via NVD
CVE-2026-94039High· 7.3
1w ago

A vulnerability was detected in vas3k TaxHacker up to 0.8.5

A vulnerability was detected in vas3k TaxHacker up to 0.8.5. Affected is the function generateInvoicePDF of the file /apps/invoices/actions.ts of the component Invoice PDF Renderer. Performing a manipulation of the argument businessLogo …

▾ Twilightvas3k · TaxHackerEPSS 0.50%via NVD
CVE-2026-94038High· 7.3PoC
1w ago

A security vulnerability has been detected in NonceGeek dim-sum-app

A security vulnerability has been detected in NonceGeek dim-sum-app. This impacts the function textSearchV2Handler of the file deno/main.tsx of the component Deno Backend. Such manipulation of the argument supabase_url leads to server-si…

▾ MidnightNonceGeek · dim-sum-appEPSS 0.51%via NVD
CWE-918 vulnerabilities (CVEs) — page 3 · VulnSea