Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-5096 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-5096)
SSRF in wordpress (CVE-2026-5096). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55758 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-55758)
SSRF in ssrf (CVE-2026-55758). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59278 |
|
SSRF (Server-Side Request Forgery) in csharp (CVE-2026-59278)
SSRF in csharp (CVE-2026-59278). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45019 |
|
SSRF (Server-Side Request Forgery) in chainlit (CVE-2026-45019)
SSRF in chainlit (CVE-2026-45019). Risk of unauthorized operations or information disclosure. Exploitable via `POST /mcp`. Mitigation: upgrade to `2.12.0` or later.
|
| CVE-2026-77310 |
|
SSRF (Server-Side Request Forgery) in csharp (CVE-2026-77310)
SSRF in csharp (CVE-2026-77310). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76838 |
|
SSRF (Server-Side Request Forgery) in laravel (CVE-2026-76838)
SSRF in laravel (CVE-2026-76838). Confidential information can be exposed externally.
|
| CVE-2026-75975 |
|
Vulnerability in CVE-2026-75975 (CVE-2026-75975)
vulnerability in CVE-2026-75975 (CVE-2026-75975). Data can be tampered with by attackers. Mitigation: upgrade to `2.4.5` or later.
|
| CVE-2026-75899 |
|
Vulnerability in CVE-2026-75899 (CVE-2026-75899)
vulnerability in CVE-2026-75899 (CVE-2026-75899). Data can be tampered with by attackers. Mitigation: upgrade to `2.4.5` or later.
|
| CVE-2026-72860 |
|
Vulnerability in CVE-2026-72860 (CVE-2026-72860)
vulnerability in CVE-2026-72860 (CVE-2026-72860). Confidential information can be exposed externally. Exploitable via `POST /api/provider-nodes/validate`.
|
| CVE-2026-61704 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-61704)
SSRF in ssrf (CVE-2026-61704). Confidential information can be exposed externally.
|
| CVE-2026-64968 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-64968 (CVE-2026-64968)
SSRF in CVE-2026-64968 (CVE-2026-64968). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68558 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-68558 (CVE-2026-68558)
SSRF in CVE-2026-68558 (CVE-2026-68558). Confidential information can be exposed externally.
|
| CVE-2026-62680 |
|
Path Traversal in CVE-2026-62680 (CVE-2026-62680)
path traversal in CVE-2026-62680 (CVE-2026-62680). Confidential information can be exposed externally.
|
| CVE-2026-62668 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-62668 (CVE-2026-62668)
SSRF in CVE-2026-62668 (CVE-2026-62668). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65985 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-65985)
SSRF in ssrf (CVE-2026-65985). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63643 |
|
Vulnerability in magicmirror (CVE-2026-63643)
vulnerability in magicmirror (CVE-2026-63643). Risk of unauthorized operations or information disclosure. Exploitable via ``ADD_CALENDAR``. Mitigation: upgrade to `2.37.0` or later.
|
| CVE-2026-63642 |
|
SSRF (Server-Side Request Forgery) in magicmirror (CVE-2026-63642)
SSRF in magicmirror (CVE-2026-63642). Risk of unauthorized operations or information disclosure. Exploitable via ``CHECK_ARTICLE_URL``. Mitigation: upgrade to `2.37.0` or later.
|
| CVE-2026-45123 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-45123 (CVE-2026-45123)
SSRF in CVE-2026-45123 (CVE-2026-45123). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64849 KEV |
|
[KEV] SSRF (Server-Side Request Forgery) in mlflow (CVE-2026-64849)
SSRF in mlflow (CVE-2026-64849). Confidential information can be exposed externally. Exploitable via `POST /api/2.0/mlflow/webhooks/{id}/test`. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `3.15.0` or later.
|
| CVE-2026-56677 |
|
Vulnerability in 9router (CVE-2026-56677)
vulnerability in 9router (CVE-2026-56677). Data can be tampered with by attackers. Exploitable via `POST /api/auth/oidc/test`.
|
| CVE-2026-46382 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-46382 (CVE-2026-46382)
SSRF in CVE-2026-46382 (CVE-2026-46382). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73247 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-73247 (CVE-2026-73247)
SSRF in CVE-2026-73247 (CVE-2026-73247). Confidential information can be exposed externally.
|
| CVE-2026-73243 |
|
SSRF (Server-Side Request Forgery) in spring (CVE-2026-73243)
SSRF in spring (CVE-2026-73243). Risk of unauthorized operations or information disclosure. Exploitable via `GET /addTask`.
|
| CVE-2026-58612 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-58612)
SSRF in ssrf (CVE-2026-58612). Confidential information can be exposed externally.
|
| CVE-2026-73212 |
|
Vulnerability in c (CVE-2026-73212)
vulnerability in c (CVE-2026-73212). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62902 |
|
Vulnerability in Microsoft.WindowsDesktop.App.Runtime.win-arm64 (CVE-2026-62902)
vulnerability in Microsoft.WindowsDesktop.App.Runtime.win-arm64 (CVE-2026-62902). Confidential information can be exposed externally. Mitigation: upgrade to `8.0.30` or later.
|
| CVE-2026-19075 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-19075 (CVE-2026-19075)
SSRF in CVE-2026-19075 (CVE-2026-19075). Risk of unauthorized operations or information disclosure. Exploitable via ``aiovg_videos``.
|
| CVE-2026-12372 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-12372)
SSRF in ssrf (CVE-2026-12372). Risk of unauthorized operations or information disclosure. Exploitable via ``ipaddress``.
|
| CVE-2026-19340 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-19340 (CVE-2026-19340)
SSRF in CVE-2026-19340 (CVE-2026-19340). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53983 |
|
SSRF (Server-Side Request Forgery) in c (CVE-2026-53983)
SSRF in c (CVE-2026-53983). Confidential information can be exposed externally.
|
| CVE-2026-70605 |
|
SSRF (Server-Side Request Forgery) in electron (CVE-2026-70605)
SSRF in electron (CVE-2026-70605). Confidential information can be exposed externally. Exploitable via ``net``. Mitigation: upgrade to `42.0.0-beta.3` or later.
|
| CVE-2026-70595 |
|
SSRF (Server-Side Request Forgery) in ghost (CVE-2026-70595)
SSRF in ghost (CVE-2026-70595). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.54.1` or later.
|
| CVE-2026-71271 |
|
Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate...
Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate...
|
| CVE-2026-71270 |
|
Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated...
Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated...
|
| CVE-2026-71250 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-71250)
SSRF in ssrf (CVE-2026-71250). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18856 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-18856 (CVE-2026-18856)
SSRF in CVE-2026-18856 (CVE-2026-18856). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70591 |
|
SSRF (Server-Side Request Forgery) in ghost (CVE-2026-70591)
SSRF in ghost (CVE-2026-70591). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.54.1` or later.
|
| CVE-2026-70479 |
|
SSRF (Server-Side Request Forgery) in open-webui (CVE-2026-70479)
SSRF in open-webui (CVE-2026-70479). Confidential information can be exposed externally. Exploitable via ``PLAYWRIGHT_WS_URL``. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-47618 |
|
SSRF (Server-Side Request Forgery) in nvidia (CVE-2026-47618)
SSRF in nvidia (CVE-2026-47618). Confidential information can be exposed externally.
|
| CVE-2026-69257 |
|
SSRF (Server-Side Request Forgery) in flowise (CVE-2026-69257)
SSRF in flowise (CVE-2026-69257). Risk of unauthorized operations or information disclosure. Exploitable via ``httpSecurity.ts``. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-69246 |
|
Vulnerability in guzzlehttp/guzzle (CVE-2026-69246)
vulnerability in guzzlehttp/guzzle (CVE-2026-69246). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Mitigation: upgrade to `7.15.2` or later.
|
| CVE-2026-69192 |
|
Vulnerability in ip-address (CVE-2026-69192)
vulnerability in ip-address (CVE-2026-69192). Risk of unauthorized operations or information disclosure. Exploitable via ``Address4``. Mitigation: upgrade to `10.3.1` or later.
|
| CVE-2026-69198 |
|
Vulnerability in ip-address (CVE-2026-69198)
vulnerability in ip-address (CVE-2026-69198). Risk of unauthorized operations or information disclosure. Exploitable via ``isInSubnet``. Mitigation: upgrade to `10.2.2` or later.
|
| CVE-2026-57232 |
|
SSRF (Server-Side Request Forgery) in symfony (CVE-2026-57232)
SSRF in symfony (CVE-2026-57232). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54729 |
|
SSRF (Server-Side Request Forgery) in dssrf (CVE-2026-54729)
SSRF in dssrf (CVE-2026-54729). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.0.5` or later.
|
| CVE-2026-57862 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-57862)
SSRF in ssrf (CVE-2026-57862). Confidential information can be exposed externally.
|
| CVE-2026-18353 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-18353 (CVE-2026-18353)
SSRF in CVE-2026-18353 (CVE-2026-18353). Risk of unauthorized operations or information disclosure. Exploitable via `POST /v1/upload/sbom`.
|
| CVE-2026-54249 |
|
SSRF (Server-Side Request Forgery) in pydantic-ai-slim (CVE-2026-54249)
SSRF in pydantic-ai-slim (CVE-2026-54249). Confidential information can be exposed externally. Exploitable via ``UploadedFile``. Mitigation: upgrade to `2.0.0b6` or later.
|
| CVE-2026-67436 |
|
Vulnerability in CVE-2026-67436 (CVE-2026-67436)
vulnerability in CVE-2026-67436 (CVE-2026-67436). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67435 |
|
Information Disclosure in linuxfabrik-lib (CVE-2026-67435)
vulnerability in linuxfabrik-lib (CVE-2026-67435). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Mitigation: upgrade to `6.0.0` or later.
|