Skip to main content

CWE archive

CWE-918 CVEs

Programmatic archive

3,163 CVEs tagged with CWE-918408 Critical, 1,026 High, 1,442 Medium, 279 Low, 8 Unrated.

CVE-2026-44023

Published Jul 16, 2026

Docling Core defines core data types and transformations for the document processing application Docling. In versions 1.5.0 and above, prior to 2.74.1, docling-core did not suffic…

CVSS 8.6 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-46404

Published Jul 16, 2026

BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, the presentation URL validation did not properly restrict access to site local and link local addresses. The re…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-63088

Published Jul 16, 2026

stoatchat before 0.14.0 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated network-accessible attackers to bypass the DNS-based IP blocklist b…

CVSS 7.7 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-63086

Published Jul 16, 2026

text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compatible multimodal chat completions endpoint that allows unaut…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-59867

Published Jul 16, 2026

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota resolved OpenAPI $ref values by fetching remote http(s) URLs and reading local absolute or out-of-tree…

CVSS 7.1 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-63306

Published Jul 16, 2026

stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrary URLs without DNS resolution…

CVSS 9.2 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-53446

Published Jul 15, 2026

Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan webhook integration URLs in models/integrations.js are stored from user input and later fetched by server/notif…

CVSS 6.2 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-56678

Published Jul 15, 2026

9Router is an AI router & token saver. Prior to 0.5.6, the Kiro API-key validation endpoint POST /api/oauth/kiro/api-key builds an upstream URL using a user-controlled region valu…

CVSS 6.4 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-15746

Published Jul 15, 2026

Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the elast…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-47160

Published Jul 15, 2026

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's /icons/{domain}/icon.png endpoint used src/http_client.rs checks including should_bloc…

CVSS 5.8 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-45806

Published Jul 15, 2026

Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot's remote image import passed the user-controlled url from frontend/src/app/main/dat…

CVSS 7.7 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-61835

Published Jul 15, 2026

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, the SSRF protection on Directus's file-import-from-URL feature can be bypassed us…

CVSS 7.7 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-61646

Published Jul 15, 2026

FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta5, FastGPT's shared SSRF guard validates only the initial request URL before handing the request to axios…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-54562

Published Jul 15, 2026

Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, Cloudreve's remote download workflow accepts user-supplied URLs at POST /api/v4/workflow/download a…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-61430

Published Jul 15, 2026

PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostnames at check time but re-resolves them at connection time w…

CVSS 8.4 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-15750

Published Jul 14, 2026

A weakness has been identified in mastergo-design mastergo-magic-mcp up to 0.2.0. Impacted is the function z.string of the file src/tools/get-component-link.ts of the component mc…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-61520

Published Jul 14, 2026

Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery vulnerability in the image proxy that allows authenticated…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
20.4

CVE-2026-48332

Published Jul 14, 2026

ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerab…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-24234

Published Jul 14, 2026

NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal media fetching functions, where a network-accessible attacker could cause server-side request forgery. A s…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-15643

Published Jul 14, 2026

AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with AWS HealthLake FHIR datastores. A server-s…

CVSS 9.2 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-48736

Published Jul 14, 2026

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, NoPrivateNetworkHttpClient and…

CVSS 6.9 · Medium
evidence mentions
6
Buzz score
24.5
Vendor/product tagsBeta · best-effort

CVE-2026-48259

Published Jul 14, 2026

Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-…

CVSS 9.6 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort
Showing 276-300 of 3,163 CVEsPage 12 of 127