VulnSea

CWE-918

CVEs classified under CWE-918, newest first.

834 CVEsRSS

CVE-2026-54546Medium· 5.0PoC
1w ago

CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK

CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to 13.22.1, the authenticated PUT /api/basemap endpoint passes an attacker-controlled URL through importBasemapURL() in api/ro…

▾ Twilightdfpc-coe · CloudTAKEPSS 0.37%via NVD
CVE-2026-92576High· 8.6PoC
1w ago

HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses

HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instruc…

▾ MidnightHKUDS · nanobotEPSS 0.45%via NVD
CVE-2026-92595Medium· 5.9PoC
1w ago

Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` us…

Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` us…

▾ Twilightnodemailer · nodemailerEPSS 0.29%via NVD
CVE-2026-92527Medium· 6.3
1w ago

A vulnerability has been found in chatwoot up to 4.17.1

A vulnerability has been found in chatwoot up to 4.17.1. This impacts an unknown function of the file callbacks_controller.rb of the component Shopify OAuth. The manipulation leads to server-side request forgery. Remote exploitation of t…

▾ SunlitEPSS 0.37%via NVD
CVE-2025-56563Critical· 9.8PoC
1w ago

A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0

A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0. The script accepts an attacker-controlled address URL parameter and passes it to curl_setopt(CURLOPT_URL) without host or scheme validat…

▾ AbyssalEPSS 0.40%via NVD
CVE-2026-92775Medium· 6.5PoC
1w ago

Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches arbitrary URLs without protocol, host, or address validation

Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches arbitrary URLs without protocol, host, or address validation. Attackers with page editing permissions can inject img…

▾ Twilightrequarks · Wiki.jsEPSS 0.41%via NVD
CVE-2026-92789Medium· 6.5
1w ago

Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after following HTTP redirects

Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after following HTTP redirects. Attackers with lookup table or event notification permissions can craft allowlisted endpoi…

▾ SunlitGraylog2 · graylog2-serverEPSS 0.41%via NVD
CVE-2026-92795Medium· 6.5PoC
1w ago

Coze Studio through 0.5.1 fails to restrict the server URL supplied when registering plugin tools, allowing authenticated users to make the backend fetch internal services

Coze Studio through 0.5.1 fails to restrict the server URL supplied when registering plugin tools, allowing authenticated users to make the backend fetch internal services. Attackers can construct plugin requests to access cloud metadata…

▾ Twilightcoze-dev · coze-studioEPSS 0.41%via NVD
CVE-2026-92804High· 7.1
1w ago

Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token and proxy URL templates

Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token and proxy URL templates. Authenticated attackers can supply malicious configuration values to direct server requests …

▾ TwilightNangoHQ · NangoEPSS 0.37%via NVD
CVE-2026-92815High· 7.5PoC
1w ago

changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attackers to access internal addresses

changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attackers to access internal addresses. Attackers can supply arbitrary internal URLs in the optional_value parameter to re…

▾ Midnightdgtlmoon · changedetection.ioEPSS 0.54%via NVD
CVE-2026-92813Medium· 4.9PoC
1w ago

Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing unauthenticated attackers to reach loopback services

Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing unauthenticated attackers to reach loopback services. Attackers can save a malicious GeoJSON entry with 0.0.0.0 and trig…

▾ Twilightmetabase · MetabaseEPSS 0.47%via NVD
CVE-2026-92808Critical· 10.0
1w ago

A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server

A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unauthenticated network attacker can cause the server to issue outbound HTTP requests to a destination of the attacker'…

▾ MidnightAltium · Altium Enterprise ServerEPSS 0.56%via NVD
CVE-2026-87116Medium· 6.5
1w ago

Tanium addressed a server-side request forgery vulnerability in Threat Response.

Tanium addressed a server-side request forgery vulnerability in Threat Response.

▾ SunlitTanium · Threat ResponseEPSS 0.34%via NVD
CVE-2026-59823Medium· 5.3
1w ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.9, an authenticated LiteLLM Proxy caller with a valid virtual key can place api_base inside the user_config request body to bypass is_req…

▾ SunlitBerriAI · litellmEPSS 0.44%via NVD
CVE-2026-68536Critical· 9.8⚖ disputed
1w ago

Server-Side Request Forgery / Local File Inclusion in Apache MyFace Core. Older unsupported versions may also be affected.  Users are recommended to upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which fix this issue.

Server-Side Request Forgery / Local File Inclusion in Apache MyFace Core. Older unsupported versions may also be affected.  Users are recommended to upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which fix this issue.

▾ MidnightApache Software Foundation · org.apache.myfaces.core:myfaces-implEPSS 0.49%via NVD
CVE-2026-92719High· 7.5PoC
1w ago

Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, allowing attackers to make the node issue requests to arbitrary internal addresses

Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, allowing attackers to make the node issue requests to arbitrary internal addresses. Attackers can supply a malicious queue_url t…

▾ Midnightquickwit-oss · quickwitEPSS 0.48%via NVD
CVE-2026-92602High· 7.1PoC
1w ago

TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigController

TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigController. Authenticated attackers can attach webhooks to other users' forms and exfiltrate submissions to arbitrary exter…

▾ MidnightTDuckCloud · tduck-survey-formEPSS 0.40%via NVD
CVE-2026-85732Medium· 4.7PoC
1w ago

oras-go is a Go library for managing OCI artifacts

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/utils.go accepts an absolute URL from a registry-controlled Link response header without validating its scheme, host, or port. …

▾ Twilightoras-project · oras-goEPSS 0.35%via NVD
CVE-2026-92380High· 7.3PoC
1w ago

A flaw has been found in WuzhiCMS up to 4.1.0

A flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is the function ckditor::saveRemote of the file coreframe/app/attachment/index.php of the component Remote Image Fetch. This manipulation of the argument source[] causes…

▾ MidnightEPSS 0.50%via NVD
CVE-2026-92568Medium· 5.4PoC
1w ago

MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows authenticated users to make the API server send arbitrary HTTP requests to internal addresses

MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows authenticated users to make the API server send arbitrary HTTP requests to internal addresses. Attackers can update …

▾ Twilightmlrun · mlrunEPSS 0.33%via NVD
CVE-2026-92569Medium· 4.3PoC
1w ago

Hippo4j through 1.5.0 contains a server-side request forgery vulnerability in four ThreadPoolController endpoints that fail to validate the clientAddress parameter

Hippo4j through 1.5.0 contains a server-side request forgery vulnerability in four ThreadPoolController endpoints that fail to validate the clientAddress parameter. Authenticated attackers can supply arbitrary hostnames and ports to trig…

▾ Twilightopengoofy · hippo4jEPSS 0.34%via NVD
CVE-2026-92566High· 8.2PoC
1w ago

DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that allows unauthenticated attackers to execute arbitrary HTTP requests by supplying a caller-controlled URI

DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that allows unauthenticated attackers to execute arbitrary HTTP requests by supplying a caller-controlled URI. Attackers ca…

▾ Midnightdatageartech · datagearEPSS 0.54%via NVD
CVE-2026-92139Medium· 6.5
1w ago

Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URLs, allowing attackers to capture Bit…

Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URLs, allowing attackers to capture Bit…

▾ SunlitJenkins Project · Jenkins Bitbucket Push and Pull Request PluginEPSS 0.25%via NVD
CVE-2026-76559Medium· 4.1
1w ago

The WP Import Export Lite WordPress plugin before 3.9.33 does not properly validate URLs before requesting them during the import process, allowing users with the import capability, which administrators hold by default, to make the site …

The WP Import Export Lite WordPress plugin before 3.9.33 does not properly validate URLs before requesting them during the import process, allowing users with the import capability, which administrators hold by default, to make the site …

▾ SunlitEPSS 0.30%via NVD
CVE-2026-92215High· 7.3
1w ago

A vulnerability has been found in a2ui-project a2ui up to 0.10.7

A vulnerability has been found in a2ui-project a2ui up to 0.10.7. Affected by this vulnerability is the function httpx.get of the file agent_sdks/python/a2ui_agent/src/a2ui/extensions/file_resolve/file_resolver.py of the component FileRe…

▾ Twilighta2ui-project · a2uiEPSS 0.51%via NVD
CVE-2026-92184Medium· 6.3
1w ago

A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0

A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. Affected is the function urllib.request.urlopen of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component Multimodal Content. The manipulati…

▾ Sunlitag-ui-protocol · ag-uiEPSS 0.37%via NVD
CVE-2026-61559Critical· 9.6PoC
1w ago

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, the server reads the `X-GitLab-API-URL` HTTP…

▾ Abyssalzereight · gitlab-mcpEPSS 0.43%via NVD
CVE-2026-54544High· 7.2PoC
1w ago

Fireshare facilitates self-hosted media and link sharing

Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.16, two API endpoints that trigger outbound HTTP requests are missing the @login_required decorator. An unauthenticated attacker can call POST /api/test-disco…

▾ MidnightShaneIsrael · fireshareEPSS 0.41%via NVD
CVE-2026-76820High· 7.7
1w ago

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260701.0, the synchronizerFetch GraphQL query called fetchRemoteStreams after checking only that a remote stream URL used HTT…

▾ TwilightOpenCTI-Platform · openctiEPSS 0.41%via NVD
CVE-2026-18424High· 7.1⚖ disputed
1w ago

Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Server-Side Request Forgery iremote file import via cross-port reuse of a host's validated DNS pin

Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Server-Side Request Forgery iremote file import via cross-port reuse of a host's validated DNS pin. When multiple remote URLs share the same host, only the first `ValidatedRemoteUrl` is retain…

▾ Twilightconcretecms · concrete_cmsEPSS 0.24%via NVD
CWE-918 vulnerabilities (CVEs) — page 5 · VulnSea