VulnSea

CWE-918

CVEs classified under CWE-918, newest first.

838 CVEsRSS

CVE-2026-79723Medium· 5.0
2w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-controlled API endpoints.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-controlled API endpoints.

▾ Sunlitlangflow · langflowEPSS 0.35%via NVD
CVE-2026-81213High· 8.6
2w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs.

▾ Twilightlangflow · langflowEPSS 0.49%via NVD
CVE-2026-88056High· 8.6PoC
2w ago

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular Server-Side Rendering in @angular/platform-server processe…

▾ Midnightangular · angularEPSS 0.61%via NVD
CVE-2026-82097High· 8.8
2w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.64%via NVD
CVE-2026-88892Medium· 5.0PoC
2w ago

OpenPanel is an analytics platform

OpenPanel is an analytics platform. In all versions (no patched release available at time of publication), the data importer fetches a caller-supplied URL with plain fetch instead of the project's existing SSRF guard (apps/api/src/utils/…

▾ TwilightOpenpanel-dev · openpanelEPSS 0.28%via NVD
CVE-2026-54054Medium· 6.5
2w ago

Transmute has full-read SSRF in URL file import (POST /api/files/url) — no host/IP validation, follows redirects

Transmute is a free, open-source, self-hosted file conversion and compression tool. Prior to version 1.3.0, Transmute's URL import endpoint, `POST /api/files/url`, is vulnerable to Server-Side Request Forgery (SSRF). The HTTP downloader …

▾ Sunlittransmute-app · transmuteEPSS 0.35%via CVEORG
CVE-2026-89049Critical· 9.9
2w ago

Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent

A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms …

▾ MidnightAWS · Amazon SSM AgentEPSS 0.66%via CVEORG
CVE-2026-9667Medium· 5.3
2w ago

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints.

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints.

▾ Sunlitibm · websphere_application_serverEPSS 0.43%via NVD
CVE-2026-81265High· 7.5
2w ago

IBM Langflow OSS 1.0.0 through 1.11.5.

IBM Langflow OSS 1.0.0 through 1.11.5.

▾ Twilightlangflow · langflowEPSS 0.39%via NVD
CVE-2026-81207High· 8.5
2w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body …

IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body …

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.29%via NVD
GHSA-wfgq-w7cq-qj7jHigh· 7.2
2w ago

mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url

mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url

▾ Twilightmistralrs-server-core · mistralrs-server-corevia GHSA
CVE-2026-88896Medium· 5.3
2w ago

EspoCRM before 10.0.4 is vulnerable to server-side request forgery

EspoCRM before 10.0.4 is vulnerable to server-side request forgery. HostCheck::ipAddressIsNotInternal(), which validates outbound URLs to block requests to internal/private IP addresses, strips ::ffff: (IPv4-mapped IPv6) prefixes but doe…

▾ Sunlitespocrm · espocrmEPSS 0.37%via NVD
CVE-2026-79635High· 7.3
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Server-Side Request Forgery (SSRF) vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially …

▾ TwilightDell · Secure Connect Gateway 5.0 - ApplicationEPSS 0.31%via CVEORG
CVE-2026-88001Medium· 5.0PoC
2w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 until 0.11.1, server-side web fetches did not reapply WEB_FETCH_FILTER_LIST or private-address controls to HTTP redirect destinations when A…

▾ Twilightopenwebui · open_webuiEPSS 0.38%via NVD
CVE-2026-86771High· 7.6PoC
2w ago

Snipe-IT versions before 8.7.0 fail to HTML-escape the employee_num field in the acceptance PDF generator, allowing attackers with users.edit permission to inject img tags into TCPDF's writeHTML() function

Snipe-IT versions before 8.7.0 fail to HTML-escape the employee_num field in the acceptance PDF generator, allowing attackers with users.edit permission to inject img tags into TCPDF's writeHTML() function. Attackers can craft a maliciou…

▾ Midnightsnipeitapp · snipe-itEPSS 0.32%via NVD
CVE-2026-57866High· 8.8
2w ago

Server side request forgery in Apache Impala versions 4.4.x and 4.5.x.  Authenticated Impala users with permissions to execute the ai_generate_text() function can exfiltrate secrets provided by the credential providers configured in the …

Server side request forgery in Apache Impala versions 4.4.x and 4.5.x.  Authenticated Impala users with permissions to execute the ai_generate_text() function can exfiltrate secrets provided by the credential providers configured in the …

▾ Twilightapache · impalaEPSS 0.58%via NVD
CVE-2026-54048Medium· 5.3
2w ago

Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but th…

Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but th…

▾ Sunlitapache · impalaEPSS 0.54%via NVD
CVE-2026-87999High· 7.1PoC
2w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.1, POST /api/v1/retrieval/process/web and POST /api/v1/retrieval/process/web/search in backend/open_webui/retrieval/web/utils.py treated …

▾ Midnightopenwebui · open_webuiEPSS 0.36%via NVD
CVE-2026-19733Medium· 5.3
2w ago

Server-Side request forgery (SSRF) vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc

Server-Side request forgery (SSRF) vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Server Side Request Forgery…

▾ SunlitYordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. · Library Information and Document Automation ProgramEPSS 0.19%via NVD
GHSA-hxjg-93wc-h8p8High· 8.8
2w ago

Komari: Management Interface CSRF

Komari: Management Interface CSRF

▾ Twilightkomari-monitor · github.com/komari-monitor/komarivia OSV
CVE-2026-87996High· 7.7
2w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.1, SafePlaywrightURLLoader in backend/open_webui/retrieval/web/utils.py validated a user-controlled hostname in Python and then l…

▾ Twilightopenwebui · open_webuiEPSS 0.35%via NVD
CVE-2025-24979Medium· 5.5
2w ago

LF Edge eKuiper: SSRF in External Service

LF Edge eKuiper: SSRF in External Service

▾ Sunlitlf-edge · github.com/lf-edge/ekuiper/v2via OSV
CVE-2026-19233High· 8.6
2w ago

CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized command execution and disclosure of server data when an attacker with a privileged account sends crafted, unvalidated parameters to a server e…

CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized command execution and disclosure of server data when an attacker with a privileged account sends crafted, unvalidated parameters to a server e…

▾ TwilightSchneider Electric · EcoStruxure™ IT Data Center Expert (Formerly known as StruxureWare Data Center Expert)EPSS 0.70%via NVD
CVE-2026-87821High· 7.1PoC
2w ago

Lara Dashboard through 1.3.1 contains a server-side request forgery vulnerability in the POST /api/admin/builder/markdown/fetch endpoint that allows any authenticated user to fetch arbitrary URLs and read the response body

Lara Dashboard through 1.3.1 contains a server-side request forgery vulnerability in the POST /api/admin/builder/markdown/fetch endpoint that allows any authenticated user to fetch arbitrary URLs and read the response body. Attackers can…

▾ Midnightlaradashboard · laradashboardEPSS 0.47%via NVD
CVE-2026-80123High· 7.3
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Server-Side Request Forgery (SSRF) vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially …

▾ Twilightdell · secure_connect_gatewayEPSS 0.34%via NVD
CVE-2026-87084High· 7.7
2w ago

Tanium addressed a server-side request forgery vulnerability in Enforce.

Tanium addressed a server-side request forgery vulnerability in Enforce.

▾ Twilighttanium · enforceEPSS 0.34%via NVD
CVE-2026-87595Critical· 9.8⚖ disputed
2w ago

Server-side request forgery in Mobile in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page

Server-side request forgery in Mobile in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

▾ Midnightgoogle · chromeEPSS 0.42%via NVD
CVE-2026-86082Medium· 6.5
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the OpenAI Chat Model node enforced credential allowed-domain restrictions for normal calls but not for the model-search dropdown. A workflow edit…

▾ Sunlitn8n · n8nEPSS 0.41%via NVD
GHSA-8m3c-c648-2xjjMedium· 5.9
2w ago

Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature

Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature

▾ Sunlitnodemailer · nodemailervia GHSA
CVE-2026-86806High· 7.3
2w ago

A weakness has been identified in opengeos GeoLibre up to 2.3.0

A weakness has been identified in opengeos GeoLibre up to 2.3.0. Impacted is the function _is_within_roots. This manipulation causes server-side request forgery. The attack can be initiated remotely. Upgrading to version 2.4.0 is recomme…

▾ Twilightopengeos · GeoLibreEPSS 0.60%via NVD
CWE-918 vulnerabilities (CVEs) — page 8 · VulnSea