| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-15733 | Cri | 0.65 | 9.8 | 0.10 | Aug 6, 2026 | A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attackers to execute arbitrary commands as root. | ||
| CVE-2026-15732 | Cri | 0.57 | 9.8 | 0.01 | Aug 6, 2026 | A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functionality allows authenticated attackers to make arbitrary HTTP requests and retrieve responses. | ||
| CVE-2026-14812 | Cri | 0.65 | 10.0 | 0.01 | Aug 6, 2026 | The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an… | ||
| CVE-2026-11976 | Cri | 0.65 | 10.0 | 0.01 | Aug 6, 2026 | The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-system-check.php`. Three distinct… | ||
| CVE-2025-14561 | — | Cri | 0.52 | 9.0 | 0.00 | Aug 6, 2026 | In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user… | |
| CVE-2026-67261 | Cri | 0.64 | 9.8 | 0.02 | Aug 6, 2026 | Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary… | ||
| CVE-2026-66709 | Cri | 0.59 | 9.1 | 0.01 | Aug 6, 2026 | Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions. | ||
| CVE-2026-66665 | Cri | 0.65 | 10.0 | 0.01 | Aug 6, 2026 | Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions. | ||
| CVE-2026-66662 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions. | ||
| CVE-2026-66447 | Cri | 0.60 | 9.3 | 0.00 | Aug 6, 2026 | Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions. | ||
| CVE-2026-65581 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions. | ||
| CVE-2026-65579 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions. | ||
| CVE-2026-65578 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | Unauthenticated PHP Object Injection in Agora <= 1.9 versions. | ||
| CVE-2026-65577 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions. | ||
| CVE-2026-65576 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions. | ||
| CVE-2026-65575 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions. | ||
| CVE-2026-65574 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | Unauthenticated PHP Object Injection in Abogado <= 1.18 versions. | ||
| CVE-2026-65573 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | Unauthenticated PHP Object Injection in Abelle <= 1.22 versions. | ||
| CVE-2026-65572 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions. | ||
| CVE-2026-65571 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions. | ||
| CVE-2026-65556 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions. | ||
| CVE-2026-65553 | Cri | 0.65 | 10.0 | 0.01 | Aug 6, 2026 | Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions. | ||
| CVE-2026-65552 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions. | ||
| CVE-2026-65548 | Cri | 0.64 | 9.9 | 0.01 | Aug 6, 2026 | Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions. | ||
| CVE-2026-65546 | Cri | 0.60 | 9.3 | 0.00 | Aug 6, 2026 | Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions. | ||
| CVE-2026-65520 | Cri | 0.60 | 9.3 | 0.00 | Aug 6, 2026 | Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions. | ||
| CVE-2026-65508 | Cri | 0.60 | 9.3 | 0.00 | Aug 6, 2026 | Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions. | ||
| CVE-2026-65507 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions. | ||
| CVE-2026-54489 | Cri | 0.59 | 9.1 | 0.01 | Aug 6, 2026 | Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session… | ||
| CVE-2026-53976 | Cri | 0.59 | 9.1 | 0.03 | Aug 6, 2026 | OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an… | ||
| CVE-2026-53975 | Cri | 0.64 | 9.8 | 0.02 | Aug 6, 2026 | OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any… | ||
| CVE-2026-34191 | Cri | 0.59 | 9.1 | 0.01 | Aug 6, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3 | ||
| CVE-2026-32327 | Cri | 0.59 | 9.1 | 0.00 | Aug 6, 2026 | A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue. | ||
| CVE-2026-28139 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions. | ||
| CVE-2026-28005 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions. | ||
| CVE-2026-5134 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. CMS allows SQL Injection. This issue affects CMS: through 06082026. NOTE: The vendor was contacted early about this disclosure… | ||
| CVE-2026-12605 | Cri | 0.62 | 9.6 | 0.00 | Aug 6, 2026 | In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the… | ||
| CVE-2026-68079 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization code MUST NOT be… | ||
| CVE-2026-65583 | Cri | 0.59 | 9.1 | 0.00 | Aug 6, 2026 | Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens. However, note that self-issued ID tokens are not… | ||
| CVE-2026-63687 | Cri | 0.59 | 9.1 | 0.00 | Aug 6, 2026 | Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly-signed request JWT (e.g., one whose client_secret is known or compromised) can… | ||
| CVE-2026-61466 | Cri | 0.59 | 9.1 | 0.01 | Aug 6, 2026 | In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning… | ||
| CVE-2026-66909 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to… | ||
| CVE-2026-64597 | Cri | 0.57 | 9.8 | 0.01 | Aug 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_close_init() fails before the next send, cleanup retains the… | ||
| CVE-2026-5430 | — | Cri | 0.70 | 10.0 | 0.01 | KEV | Aug 6, 2026 | The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful… |
| CVE-2026-1728 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full… | ||
| CVE-2025-15039 | — | Cri | 0.61 | 9.4 | 0.01 | Aug 6, 2026 | The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate… | |
| CVE-2026-16054 | Cri | 0.59 | 9.1 | 0.00 | Aug 6, 2026 | The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attackers to delete files staged in its upload… | ||
| CVE-2026-12713 | Cri | 0.59 | 9.1 | 0.00 | Aug 6, 2026 | The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. This affects a code path distinct from the one addressed by… | ||
| CVE-2026-67873 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment length via FileSegment_GetMaxDataSize() and does not verify the residual capacity of the… | ||
| CVE-2026-67870 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing… |
- risk 0.65cvss 9.8epss 0.10
A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attackers to execute arbitrary commands as root.
- risk 0.57cvss 9.8epss 0.01
A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functionality allows authenticated attackers to make arbitrary HTTP requests and retrieve responses.
- risk 0.65cvss 10.0epss 0.01
The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an…
- risk 0.65cvss 10.0epss 0.01
The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-system-check.php`. Three distinct…
- risk 0.52cvss 9.0epss 0.00
In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user…
- risk 0.64cvss 9.8epss 0.02
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary…
- risk 0.59cvss 9.1epss 0.01
Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
- risk 0.65cvss 10.0epss 0.01
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.
- risk 0.65cvss 10.0epss 0.01
Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.
- risk 0.64cvss 9.8epss 0.01
Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.
- risk 0.64cvss 9.9epss 0.01
Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.
- risk 0.59cvss 9.1epss 0.01
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session…
- risk 0.59cvss 9.1epss 0.03
OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an…
- risk 0.64cvss 9.8epss 0.02
OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any…
- risk 0.59cvss 9.1epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3
- risk 0.59cvss 9.1epss 0.00
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
- risk 0.64cvss 9.8epss 0.00
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. CMS allows SQL Injection. This issue affects CMS: through 06082026. NOTE: The vendor was contacted early about this disclosure…
- risk 0.62cvss 9.6epss 0.00
In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the…
- risk 0.64cvss 9.8epss 0.01
In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization code MUST NOT be…
- risk 0.59cvss 9.1epss 0.00
Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens. However, note that self-issued ID tokens are not…
- risk 0.59cvss 9.1epss 0.00
Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly-signed request JWT (e.g., one whose client_secret is known or compromised) can…
- risk 0.59cvss 9.1epss 0.01
In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning…
- risk 0.64cvss 9.8epss 0.01
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to…
- risk 0.57cvss 9.8epss 0.01
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_close_init() fails before the next send, cleanup retains the…
- risk 0.70cvss 10.0epss 0.01
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful…
- risk 0.64cvss 9.8epss 0.00
Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full…
- risk 0.61cvss 9.4epss 0.01
The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate…
- risk 0.59cvss 9.1epss 0.00
The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attackers to delete files staged in its upload…
- risk 0.59cvss 9.1epss 0.00
The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. This affects a code path distinct from the one addressed by…
- risk 0.64cvss 9.8epss 0.01
A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment length via FileSegment_GetMaxDataSize() and does not verify the residual capacity of the…
- risk 0.64cvss 9.8epss 0.01
In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing…