Skip to main content

CWE archive

CWE-918 CVEs

Programmatic archive

3,185 CVEs tagged with CWE-918409 Critical, 1,033 High, 1,456 Medium, 284 Low, 3 Unrated.

CVE-2026-34884

Published Aug 18, 2026

SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommen…

CVSS N/A · Unrated
evidence mentions
2
Buzz score
17.5

CVE-2026-64849

Published Aug 17, 2026

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks…

CVSS 9.3 · Critical
evidence mentions
5
Buzz score
22.9

CVE-2026-56677

Published Aug 17, 2026

9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/oidc/test/route.js passes the user-controlled issuerUrl para…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-73560

Published Aug 17, 2026

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the MiMoV2OmniMultiModalProcessor in vllm/transformers_utils/processors/mimo_v2_omni.py passes…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-73410

Published Aug 17, 2026

Budibase is an open-source low-code platform. Prior to 3.40.0, packages/backend-core/src/utils/outboundFetch.ts pinned a validated address through a Node agent, but the REST integ…

CVSS 8.5 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-35219

Published Aug 17, 2026

Budibase is an open-source low-code platform. Prior to 3.41.3, automation steps in packages/server/src/automations/steps/outgoingWebhook.ts, packages/server/src/automations/steps/…

CVSS 7.1 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-48053

Published Aug 17, 2026

Kolibri is an offline-first education platform. Prior to version 0.19.4, several Kolibri API endpoints accept an unvalidated `baseurl` parameter and fetch attacker-controlled URLs…

CVSS 5.8 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-75054

Published Aug 17, 2026

In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-75053

Published Aug 17, 2026

In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-74858

Published Aug 17, 2026

A vulnerability has been found in jae-jae fetcher-mcp up to 0.3.9. Impacted is the function fetch_url/fetch_urls of the file /latest/meta-data/iam/security-credentials/ of the com…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-75006

Published Aug 17, 2026

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosur…

CVSS 5.8 · Medium
evidence mentions
7
Buzz score
30.8

CVE-2026-74842

Published Aug 17, 2026

A vulnerability was found in Kira-Pgr PromptShopMCP up to 5bc0cd17358e19a5415d11a531088170d7b81452. Affected is the function download_image of the file server.py of the component…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-13700

Published Aug 17, 2026

The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side request and attaches stored third-party integration credentials to e…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-19984

Published Aug 17, 2026

A flaw has been found in jkawamoto mcp-florence2 up to 0.3.13. Affected by this issue is the function get_images of the file src/mcp_florence2/__init__.py. This manipulation of th…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-19957

Published Aug 16, 2026

A vulnerability was identified in graphlit graphlit-mcp-server 1.0.1. This affects the function fetch of the file src/tools.ts of the component ssrf-test Endpoint. Such manipulati…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-19956

Published Aug 16, 2026

A vulnerability has been found in gomarble-ai facebook-ads-mcp-server 0.1.0. The impacted element is the function fetch_pagination_url of the file server.py. Such manipulation lea…

CVSS 5.3 · Medium
evidence mentions
8
Buzz score
28.5

CVE-2026-73058

Published Aug 16, 2026

stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blocklist, allowing unauthenticated attackers to bypass protections via the /proxy and…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-17123

Published Aug 16, 2026

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url'…

CVSS 8.8 · High
evidence mentions
7
Buzz score
27.3

CVE-2026-19927

Published Aug 16, 2026

A vulnerability was found in OpenBoxes up to 0.9.7. The impacted element is the function Upload of the file grails-app/controllers/org/pih/warehouse/product/ProductController.groo…

CVSS 2.1 · Low
evidence mentions
10
Buzz score
32.0

CVE-2026-74247

Published Aug 14, 2026

A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability within the b…

CVSS 4.2 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-73845

Published Aug 14, 2026

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in src/tools/quality.ts use isVali…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-46380

Published Aug 14, 2026

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSFetcher._do_fetch() method passes a user-supplied URL direct…

CVSS 6.7 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-19770

Published Aug 14, 2026

A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is the function downloadReport of the file src/smadex-reporting/src/index.ts of the…

CVSS 1.9 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-19765

Published Aug 14, 2026

A security flaw has been discovered in eyaushev swagger-testcase-mcp 5babb27c951fb404bc2b25ec80593616e49054e5. This vulnerability affects the function loadSource of the file src/u…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-19753

Published Aug 13, 2026

A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of the file src/mcp-rdf-explorer/server.py of the component MCP…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
24.4
Showing 1-25 of 3,185 CVEsPage 1 of 128