Known Vulnerabilities for Server by Microchip
Listed below are 10 of the newest known vulnerabilities associated with "Server" by "Microchip".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-91771 json | Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download function, all... | Not Provided | 2026-09-15 | 2026-09-15 |
| CVE-2026-91199 json | Refly through 1.1.0 contains a server-side request forgery vulnerability in the POST /v1/misc/scrape endpoint that fetches ca... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-91081 json | Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous atta... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-91079 json | Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostna... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-90938 json | LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket server on 0.0.0.0:5401 (/plugin... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-90937 json | froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customer... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-90935 json | Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver allowlist in the M... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-90928 json | File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-90927 json | filebrowser through 2.63.23 fails to limit WebSocket message size in the /api/command handler before checking permissions, al... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-90919 json | LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_register... | Not Provided | 2026-09-14 | 2026-09-14 |