Skip to main content

CWE archive

CWE-918 CVEs

Programmatic archive

2,938 CVEs tagged with CWE-918396 Critical, 930 High, 1,355 Medium, 255 Low, 2 Unrated.

CVE-2026-60105

Published Jul 8, 2026

Monsta FTP before 2.14.5 contains a server-side request forgery vulnerability in the fetchRemoteFile action caused by an incomplete IP blocklist check in the isBlockedIP() functio…

CVSS 7.7 · High
evidence mentions
4
Buzz score
31.1

CVE-2026-59806

Published Jul 8, 2026

Gradio before 6.20.0 contains an open redirect and server-side request forgery vulnerability that allows attackers to redirect users to arbitrary URLs or perform client-side SSRF…

CVSS 4.9 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-58501

Published Jul 8, 2026

Zeep is a Python SOAP client. From 4.0.0 before 4.3.3, Settings.forbid_external is defined but not enforced when parsing WSDL or XSD documents, allowing transitive xsd:import, xsd…

CVSS 5.9 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-59702

Published Jul 8, 2026

repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that allows unauthenticated attackers to make arbitrary outbound requests. The endpoint…

CVSS 9.2 · Critical
evidence mentions
4
Buzz score
22.6

CVE-2026-54607

Published Jul 7, 2026

FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta4, the HTTP-tool OpenAPI schema importer validates only the top-level URL before passing it to SwaggerPar…

CVSS 7.7 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-45796

Published Jul 7, 2026

Coder allows organizations to provision remote development environments via Terraform. Versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 are vulnerable to una…

CVSS 6.5 · Medium
evidence mentions
9
Buzz score
28.0
Vendor/product tagsBeta · best-effort

CVE-2026-59707

Published Jul 7, 2026

LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint that allows attackers to fetch arbitrary internal URLs. The endpoi…

CVSS 9.2 · Critical
evidence mentions
4
Buzz score
22.6

CVE-2026-58468

Published Jul 7, 2026

NocoBase through 2.1.20 contains a server-side request forgery vulnerability in the serverRequest wrapper that allows authenticated administrators to issue arbitrary outbound HTTP…

CVSS 5.1 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-42147

Published Jul 7, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, S3 storage endpoint validation only checks URL format…

CVSS 4.9 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-34170

Published Jul 7, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the GithubApp api_url field is used as the base URL fo…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-57573

Published Jul 6, 2026

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF destination check on the non-streaming /crawl path but not…

CVSS 8.6 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-58404

Published Jul 6, 2026

Hugo is a static site generator. From v0.162.0 through v0.163.0, the default security.http.urls policy denies requests to loopback, internal, and cloud-metadata IPv4 literals, but…

CVSS 4.6 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-50134

Published Jul 6, 2026

Hugo is a static site generator. From 0.91.0 until 0.162.0, resources.GetRemote enforces security.http.urls on the URL it is called with, but it did not re-validate intermediate U…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-53830

Published Jul 6, 2026

Anti-Virus for ownCloud is an anti-virus application for file storage, synchronization, and sharing application ownCloud. Versions of Anti-Virus for ownCloud before 1.2.3 are vuln…

CVSS 9.1 · Critical

CVE-2025-53828

Published Jul 6, 2026

SharePoint for ownCloud is an application for using SharePoint with the file storage, synchronization, and sharing application ownCloud Classic. In SharePoint for ownCloud prior t…

CVSS 8.5 · High

CVE-2026-44937

Published Jul 6, 2026

Potential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.5…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44936

Published Jul 6, 2026

Missing filtering when the helmRepoURLRegex field isn't set on a GitRepo resource in SUSE Rancher Fleet's bundle reader in 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-55994

Published Jul 6, 2026

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel in Iggy component. The cam…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-55993

Published Jul 6, 2026

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel in Atmosphere Websocket Com…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-48205

Published Jul 6, 2026

Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component. The camel-dns producers read DNS operation parameters - the resolver to…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-48203

Published Jul 6, 2026

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-46726

Published Jul 6, 2026

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel in Vertx Websocket componen…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-14748

Published Jul 5, 2026

A flaw has been found in AIAnytime Awesome-MCP-Server up to a884bb51bcd99e08e14fd712c749d55d9d9a13ab. Affected by this issue is some unknown functionality of the file mcp-wiki/src…

CVSS 2.1 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-58418

Published Jul 3, 2026

SSRF via HTTP Redirect in Repository Migration

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
26.1

CVE-2026-58278

Published Jul 3, 2026

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS 5.4 · Medium
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort
Showing 126-150 of 2,938 CVEsPage 6 of 118