VulnSea

CWE-918

CVEs classified under CWE-918, newest first.

838 CVEsRSS

CVE-2026-55374Medium· 4.8
1w ago

canto-saas-api is a PHP library for interacting with the Canto SaaS API

canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, Request::buildRequestUrl() joins values returned by Request::getPathVariables() without encoding individual path segments, including the sch…

▾ Sunlitjleehr · canto-saas-apiEPSS 0.36%via NVD
CVE-2026-55591Medium· 5.8PoC
1w ago

Signal K Server is a server application that runs on a central hub in a boat

Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.28.0, makeRemoteRequest() in src/serverroutes.ts accepted attacker-controlled host, port, useTLS, and selfsignedcert parameters from the testSignalK…

▾ TwilightSignalK · signalk-serverEPSS 0.30%via NVD
CVE-2026-91199Medium· 5.0
1w ago

Refly through 1.1.0 contains a server-side request forgery vulnerability in the POST /v1/misc/scrape endpoint that fetches caller-supplied URLs without validating the scheme, host, or resolved address

Refly through 1.1.0 contains a server-side request forgery vulnerability in the POST /v1/misc/scrape endpoint that fetches caller-supplied URLs without validating the scheme, host, or resolved address. Authenticated attackers can make th…

▾ Sunlitrefly-ai · reflyEPSS 0.34%via NVD
CVE-2026-12944Critical· 9.6PoC
1w ago

IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports

IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential…

▾ AbyssalIBM · Langflow OSSEPSS 0.39%via NVD
CVE-2026-90818Medium· 4.3PoC
1w ago

A security flaw has been discovered in netease-youdao LobsterAI 2026.6.15/2026.8.28/2026.9.3/2026.9.4

A security flaw has been discovered in netease-youdao LobsterAI 2026.6.15/2026.8.28/2026.9.3/2026.9.4. Impacted is the function OpenClawConfigSync.buildBrowserConfig of the file src/main/libs/openclawConfigSync.ts of the component Browse…

▾ Twilightnetease-youdao · LobsterAIEPSS 0.54%via NVD
CVE-2026-12767Medium· 6.5
1w ago

IBM Langflow OSS 1.0.0 through 1.11.5 is vulnerable to server-side request forgery (SSRF)

IBM Langflow OSS 1.0.0 through 1.11.5 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitati…

▾ SunlitIBM · Langflow OSSEPSS 0.22%via NVD
CVE-2026-12765Medium· 6.5
1w ago

IBM Langflow OSS 1.0.0 through 1.10.2 is vulnerable to server-side request forgery (SSRF)

IBM Langflow OSS 1.0.0 through 1.10.2 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitati…

▾ SunlitIBM · Langflow OSSEPSS 0.22%via NVD
CVE-2026-12766Medium· 5.4
1w ago

IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF)

IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating…

▾ SunlitIBM · Langflow OSSEPSS 0.18%via NVD
CVE-2026-90814Medium· 6.3PoC
1w ago

A flaw has been found in cosmicstack-labs mercury-agent up to 1.1.13

A flaw has been found in cosmicstack-labs mercury-agent up to 1.1.13. Affected by this vulnerability is the function githubRequest of the file src/utils/github.ts of the component GitHub API Handler. This manipulation of the argument pat…

▾ Twilightcosmicstack-labs · mercury-agentEPSS 0.37%via NVD
CVE-2026-73497Medium· 6.5
1w ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). From 0.17.0 until 0.22.0, validate_url_for_ssrf resolves the attacker-controlled X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url hea…

▾ Sunlitsooperset · mcp-atlassianEPSS 0.38%via NVD
CVE-2026-15887Medium· 5.4
1w ago

IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requests.

IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requests.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.18%via NVD
CVE-2026-91081Medium· 5.8
1w ago

Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous attackers to make outbound requests by providing a public document UUID

Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous attackers to make outbound requests by providing a public document UUID. Attackers can exploit DNS time-of-check-tim…

▾ Sunlitsuitenumerique · docsEPSS 0.43%via NVD
CVE-2026-91079High· 8.5
1w ago

Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation

Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply arbitrary URLs to the print endpoint, which …

▾ Twilighthcengineering · platformEPSS 0.37%via NVD
CVE-2026-90710High· 7.3PoC
1w ago

A vulnerability was determined in taisan tarzan-cms 1.0.0

A vulnerability was determined in taisan tarzan-cms 1.0.0. This issue affects the function openConnection of the file com/tarzan/cms/modules/admin/service/biz/ThemeService.java of the component Theme Download Function. Executing a manipu…

▾ Midnighttaisan · tarzan-cmsEPSS 0.50%via NVD
CVE-2026-90790Medium· 6.3
1w ago

A security vulnerability has been detected in a2aproject a2a-python up to 1.1.3

A security vulnerability has been detected in a2aproject a2a-python up to 1.1.3. This affects the function _dispatch_notification of the file src/a2a/server/tasks/base_push_notification_sender.py of the component Push Notification Sender…

▾ Sunlita2aproject · a2a-pythonEPSS 0.37%via NVD
CVE-2026-71198High· 7.0
1w ago

In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image

In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image. Unlike the web-download import path, the location API only checks the URL scheme and does not apply the imp…

▾ TwilightOpenStack · GlanceEPSS 0.45%via NVD
CVE-2026-55073Medium· 6.2PoC
1w ago

WeasyPrint helps web developers to create PDF documents

WeasyPrint helps web developers to create PDF documents. Prior to 70.0, server-side applications that configure a restrictive url_fetcher and pass attacker-influenced values to HTML.write_pdf() can have the restriction bypassed through t…

▾ TwilightKozea · WeasyPrintEPSS 0.22%via NVD
CVE-2026-53708Medium· 6.6PoC
1w ago

ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC APIs

ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC APIs. Prior to 1.0.3, the /admin/gateways/test call site in mcpgateway/admin.py calls valid…

▾ TwilightIBM · mcp-context-forgeEPSS 0.35%via NVD
CVE-2026-57126High· 8.5PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _host_is_blocked, which checks literal host encodings but does not resolve DNS names before scrape_page, crawl, extract_links, extr…

▾ MidnightMervinPraison · PraisonAIEPSS 0.38%via NVD
CVE-2026-57115Medium· 6.5
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, SpiderTools.scrape_page validates only the initial URL and lets requests.Session.get follow redirects automatically, so a public-looking URL can redirect to a loop…

▾ SunlitMervinPraison · PraisonAIEPSS 0.43%via NVD
CVE-2026-54452Medium· 6.3
1w ago

safeurl is a server-side request forgery protection library

safeurl is a server-side request forgery protection library. Prior to 0.2.4, the privateNetworks list in ip.go omits the IPv6 ranges 64:ff9b:1::/48, 5f00::/16, 3fff::/20, and 100:0:0:1::/64. When an application enables IPv6 with EnableIP…

▾ Sunlitdoyensec · safeurlEPSS 0.52%via NVD
CVE-2026-54628High· 8.6PoC
1w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes URL-capable SQLite virtual table modules such as json_reader and log_reader through its unauthenticated MySQL-compatible server port without …

▾ Midnightjulien040 · anyqueryEPSS 0.60%via NVD
CVE-2026-90769High· 7.7PoC
2w ago

Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services

Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata,…

▾ Midnightlfnovo · open-notebookEPSS 0.41%via NVD
CVE-2026-90580Medium· 6.3PoC
2w ago

A vulnerability was found in FlowiseAI Flowise up to 3.0.2

A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the file packages/server/src/controllers/evaluations/index.ts of the component Evaluations Endpoint. The manipulation of th…

▾ Twilightflowiseai · flowiseEPSS 0.41%via NVD
CVE-2026-90486Medium· 6.3
2w ago

A vulnerability has been found in openstatusHQ openstatus up to f04c827112f30a11d571ebdad3892826034d6265

A vulnerability has been found in openstatusHQ openstatus up to f04c827112f30a11d571ebdad3892826034d6265. Affected by this vulnerability is an unknown functionality of the file apps/status-page/src/lib/proxy/resolve-custom-domain-rewrite…

▾ SunlitopenstatusHQ · openstatusEPSS 0.40%via NVD
CVE-2026-54166High· 7.1
2w ago

Shelf is a platform for tracking physical assets

Shelf is a platform for tracking physical assets. Prior to version 1.20.3, authenticated users with the `asset:import` permission can trigger server-side HTTP requests to attacker-controlled URLs through the Asset CSV Content Import feat…

▾ TwilightShelf-nu · shelf.nuEPSS 0.43%via NVD
CVE-2026-90446Medium· 5.3
2w ago

An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and analytics data store, without restricting its contents

An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and analytics data store, without restricting its contents. This allows …

▾ SunlitCISA · MalcolmEPSS 0.35%via NVD
CVE-2026-89242High· 7.2PoC
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a server-side request forgery vulnerability in the _json_decode function that fetches remote URLs and local file paths without SSRF validation

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a server-side request forgery vulnerability in the _json_decode function that fetches remote URLs and local file paths without SSRF validation. Unauthenticated …

▾ MidnightWWBN · AVideoEPSS 0.28%via NVD
CVE-2026-19486High· 8.7
2w ago

A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default s…

A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default s…

▾ TwilightGoogle Cloud · Gemini Enterprise Agent Platform App BuilderEPSS 0.27%via NVD
CVE-2026-49865Medium· 5.3PoC
2w ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain a server-side request forgery vulnerability in their invoice PDF preview and generation workflow. If an attacker can control Markdown content that is lat…

▾ Twilightkimai · kimaiEPSS 0.35%via NVD
CWE-918 vulnerabilities (CVEs) — page 7 · VulnSea