Skip to main content

CWE archive

CWE-918 CVEs

Programmatic archive

2,978 CVEs tagged with CWE-918398 Critical, 951 High, 1,371 Medium, 256 Low, 2 Unrated.

CVE-2026-55391

Published Jul 28, 2026

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. P…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-54691

Published Jul 28, 2026

datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61.0, src/datamodel_code_generator/http.py http.get_body accepts --url targets an…

CVSS 8.2 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-54690

Published Jul 28, 2026

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. F…

CVSS 8.2 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-4912

Published Jul 28, 2026

The Media Cleaner: Clean your WordPress! plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.0.3. This is due to the `get_url…

CVSS 4.1 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-14869

Published Jul 28, 2026

The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-59931

Published Jul 28, 2026

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, a…

CVSS 7.7 · High
evidence mentions
7
Buzz score
25.8

CVE-2026-54605

Published Jul 28, 2026

OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a…

CVSS 7.2 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-43910

Published Jul 28, 2026

Appium Java Client is the Java language binding for writing Appium tests that conform to the W3C WebDriver protocol. From 8.2.1 until 10.1.1, when directConnect(true) is enabled,…

CVSS 8.2 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-67173

Published Jul 28, 2026

Pivotick did not validate the URL scheme of node imagePath values derived from graph data before assigning them to SVG image resources. An attacker able to supply crafted graph da…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-65442

Published Jul 27, 2026

Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-61953

Published Jul 27, 2026

Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-65925

Published Jul 27, 2026

A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2026-65924

Published Jul 27, 2026

JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is e…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2026-65923

Published Jul 27, 2026

A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side request…

CVSS 6.8 · Medium
evidence mentions
4
Buzz score
27.6

CVE-2026-65618

Published Jul 27, 2026

Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing inter…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2026-64649

Published Jul 27, 2026

Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server Action forwards or redirects a…

CVSS 8.3 · High
evidence mentions
5
Buzz score
22.9

CVE-2026-16481

Published Jul 27, 2026

A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch-page tool of googleapis/mcp-toolbox. The tool takes an un…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-64645

Published Jul 27, 2026

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that builds…

CVSS 8.3 · High
evidence mentions
5
Buzz score
22.9

CVE-2026-54272

Published Jul 27, 2026

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF through misclassification of IPv4…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-48051

Published Jul 27, 2026

Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, Papra's webhook delivery system contains an SSRF protection bypass that allows any aut…

CVSS 3.5 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-17552

Published Jul 27, 2026

Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call. When the rewrite base is a plain string, th…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
27.6

CVE-2026-17192

Published Jul 27, 2026

A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to internal services that are not other…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-66437

Published Jul 27, 2026

Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions.

CVSS 4.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-65558

Published Jul 27, 2026

Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-59552

Published Jul 27, 2026

Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer &amp; Embedder <= 1.4.2 versions.

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 2,978 CVEsPage 1 of 120