Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-40346 |
|
SSRF (Server-Side Request Forgery) in @nocobase/plugin-workflow-request (CVE-2026-40346)
SSRF in @nocobase/plugin-workflow-request (CVE-2026-40346). Confidential information can be exposed externally. Exploitable via ``url``. Mitigation: upgrade to `2.0.37` or later.
|
| CVE-2026-41481 |
|
SSRF (Server-Side Request Forgery) in langchain-text-splitters (CVE-2026-41481)
SSRF in langchain-text-splitters (CVE-2026-41481). Confidential information can be exposed externally. Exploitable via ``Document``. Mitigation: upgrade to `1.1.2` or later.
|
| CVE-2026-43995 |
|
SSRF (Server-Side Request Forgery) in flowise (CVE-2026-43995)
SSRF in flowise (CVE-2026-43995). Successful exploitation can lead to full system takeover. Exploitable via ``httpSecurity.ts``. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2026-40500 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-40500)
SSRF in ssrf (CVE-2026-40500). Confidential information can be exposed externally.
|
| CVE-2026-35032 |
|
Vulnerability in ssrf (CVE-2026-35032)
vulnerability in ssrf (CVE-2026-35032). Confidential information can be exposed externally. Exploitable via `POST /LiveTv/TunerHosts`.
|
| CVE-2026-33715 |
|
Vulnerability in symfony (CVE-2026-33715)
vulnerability in symfony (CVE-2026-33715). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34160 |
|
Vulnerability in ssrf (CVE-2026-34160)
vulnerability in ssrf (CVE-2026-34160). Confidential information can be exposed externally.
|
| CVE-2026-39921 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-39921)
SSRF in ssrf (CVE-2026-39921). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40089 |
|
SSRF (Server-Side Request Forgery) in c (CVE-2026-40089)
SSRF in c (CVE-2026-40089). Confidential information can be exposed externally.
|
| CVE-2026-40072 |
|
SSRF (Server-Side Request Forgery) in web3 (CVE-2026-40072)
SSRF in web3 (CVE-2026-40072). Risk of unauthorized operations or information disclosure. Exploitable via ``OffchainLookup``. Mitigation: upgrade to `8.0.0b2` or later.
|
| CVE-2025-62718 |
|
Vulnerability in axios (CVE-2025-62718)
vulnerability in axios (CVE-2025-62718). Confidential information can be exposed externally. Exploitable via ``NO_PROXY``. Mitigation: upgrade to `0.31.0` or later.
|
| CVE-2026-39885 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-39885)
SSRF in ssrf (CVE-2026-39885). Confidential information can be exposed externally. Mitigation: upgrade to `2.3.0` or later.
|
| CVE-2026-31017 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-31017)
SSRF in ssrf (CVE-2026-31017). Confidential information can be exposed externally.
|
| CVE-2026-2377 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-2377)
SSRF in ssrf (CVE-2026-2377). Confidential information can be exposed externally.
|
| CVE-2023-46945 |
|
QD 20230821 is vulnerable to Server-side request forgery (SSRF) via a crafted request
QD 20230821 is vulnerable to Server-side request forgery (SSRF) via a crafted request
|
| CVE-2026-39695 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-39695)
SSRF in ssrf (CVE-2026-39695). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39670 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-39670)
SSRF in ssrf (CVE-2026-39670). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39645 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-39645)
SSRF in ssrf (CVE-2026-39645). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39647 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-39647)
SSRF in ssrf (CVE-2026-39647). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39630 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-39630)
SSRF in ssrf (CVE-2026-39630). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39521 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-39521)
SSRF in ssrf (CVE-2026-39521). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39464 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-39464)
SSRF in ssrf (CVE-2026-39464). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39376 |
|
Vulnerability in fastfeedparser (CVE-2026-39376)
vulnerability in fastfeedparser (CVE-2026-39376). Risk of unauthorized operations or information disclosure. Exploitable via ``ValueError``. Mitigation: upgrade to `0.5.10` or later.
|
| CVE-2026-39370 |
|
SSRF (Server-Side Request Forgery) in WWBN/AVideo (CVE-2026-39370)
SSRF in WWBN/AVideo (CVE-2026-39370). Confidential information can be exposed externally. Exploitable via `POST /objects/aVideoEncoder.json.php`.
|
| CVE-2026-39368 |
|
SSRF (Server-Side Request Forgery) in WWBN/AVideo (CVE-2026-39368)
SSRF in WWBN/AVideo (CVE-2026-39368). Confidential information can be exposed externally. Exploitable via `GET /plugin/Live/view/getRestream.json.php`.
|
| CVE-2026-35409 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-35409)
SSRF in ssrf (CVE-2026-35409). Confidential information can be exposed externally. Mitigation: upgrade to `11.16.0` or later.
|
| CVE-2026-35459 |
|
SSRF (Server-Side Request Forgery) in pyload-ng (CVE-2026-35459)
SSRF in pyload-ng (CVE-2026-35459). Confidential information can be exposed externally. Exploitable via ``CURLOPT_REDIR_PROTOCOLS``.
|
| CVE-2026-32186 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-32186)
SSRF in ssrf (CVE-2026-32186). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31818 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-31818)
SSRF in ssrf (CVE-2026-31818). Confidential information can be exposed externally.
|
| CVE-2026-35540 |
|
Vulnerability in ssrf (CVE-2026-35540)
vulnerability in ssrf (CVE-2026-35540). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-33107 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-33107)
SSRF in ssrf (CVE-2026-33107). Successful exploitation can lead to full system takeover.
|
| CVE-2026-26135 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-26135)
SSRF in ssrf (CVE-2026-26135). Confidential information can be exposed externally.
|
| CVE-2026-34576 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-34576)
SSRF in ssrf (CVE-2026-34576). Confidential information can be exposed externally. Exploitable via `POST /public/v1/upload-from-url`.
|
| CVE-2026-34577 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-34577)
SSRF in ssrf (CVE-2026-34577). Confidential information can be exposed externally. Exploitable via `GET /public/stream`.
|
| CVE-2026-34590 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-34590)
SSRF in ssrf (CVE-2026-34590). Risk of unauthorized operations or information disclosure. Exploitable via `POST /webhooks/`.
|
| CVE-2026-34526 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-34526)
SSRF in ssrf (CVE-2026-34526). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32871 |
|
SSRF (Server-Side Request Forgery) in fastmcp (CVE-2026-32871)
SSRF in fastmcp (CVE-2026-32871). Successful exploitation can lead to full system takeover. Exploitable via `Authorization header`. Mitigation: upgrade to `3.2.0` or later.
|
| CVE-2026-34740 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-34740)
SSRF in ssrf (CVE-2026-34740). Confidential information can be exposed externally.
|
| CVE-2026-34366 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-34366)
SSRF in ssrf (CVE-2026-34366). Confidential information can be exposed externally.
|
| CVE-2026-34367 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-34367)
SSRF in ssrf (CVE-2026-34367). Confidential information can be exposed externally.
|
| CVE-2026-34365 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-34365)
SSRF in ssrf (CVE-2026-34365). Confidential information can be exposed externally.
|
| CVE-2026-34163 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-34163)
SSRF in ssrf (CVE-2026-34163). Confidential information can be exposed externally.
|
| CVE-2026-34881 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-34881)
SSRF in ssrf (CVE-2026-34881). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-22742 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-22742)
SSRF in ssrf (CVE-2026-22742). Confidential information can be exposed externally.
|
| CVE-2026-32857 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-32857)
SSRF in ssrf (CVE-2026-32857). Confidential information can be exposed externally.
|
| CVE-2026-4874 |
|
SSRF (Server-Side Request Forgery) in org.keycloak:keycloak-services (CVE-2026-4874)
SSRF in org.keycloak:keycloak-services (CVE-2026-4874). Risk of unauthorized operations or information disclosure. Exploitable via ``client_session_host``. Mitigation: upgrade to `26.4.13` or later.
|
| CVE-2026-28809 |
|
XXE (XML External Entity) in esaml (CVE-2026-28809)
vulnerability in esaml (CVE-2026-28809). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-21293 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-21293)
SSRF in ssrf (CVE-2026-21293). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-21294 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-21294)
SSRF in ssrf (CVE-2026-21294). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24316 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-24316)
SSRF in ssrf (CVE-2026-24316). Risk of unauthorized operations or information disclosure.
|