Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: cwe-918 Clear
ID Title
CVE-2026-9203 SSRF (Server-Side Request Forgery) in CVE-2026-9203 (CVE-2026-9203)
SSRF in CVE-2026-9203 (CVE-2026-9203). Successful exploitation can lead to full system takeover.
CVE-2026-70605 SSRF (Server-Side Request Forgery) in electron (CVE-2026-70605)
SSRF in electron (CVE-2026-70605). Confidential information can be exposed externally. Exploitable via ``net``. Mitigation: upgrade to `42.0.0-beta.3` or later.
CVE-2026-70595 SSRF (Server-Side Request Forgery) in ghost (CVE-2026-70595)
SSRF in ghost (CVE-2026-70595). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.54.1` or later.
CVE-2026-71280 go-shiori's DownloadBookmark() (internal/core/download.go) fetches a caller-supplied bookmark URL...
go-shiori's DownloadBookmark() (internal/core/download.go) fetches a caller-supplied bookmark URL...
CVE-2026-71271 Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate...
Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate...
CVE-2026-71270 Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated...
Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated...
CVE-2026-71250 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-71250)
SSRF in ssrf (CVE-2026-71250). Risk of unauthorized operations or information disclosure.
CVE-2026-71244 SSRF (Server-Side Request Forgery) in CVE-2026-71244 (CVE-2026-71244)
SSRF in CVE-2026-71244 (CVE-2026-71244). Confidential information can be exposed externally.
CVE-2026-71246 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-71246)
SSRF in ssrf (CVE-2026-71246). Risk of unauthorized operations or information disclosure.
CVE-2026-71211 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-71211)
SSRF in ssrf (CVE-2026-71211). Confidential information can be exposed externally.
CVE-2026-71208 SSRF (Server-Side Request Forgery) in CVE-2026-71208 (CVE-2026-71208)
SSRF in CVE-2026-71208 (CVE-2026-71208). Confidential information can be exposed externally.
CVE-2026-18856 SSRF (Server-Side Request Forgery) in CVE-2026-18856 (CVE-2026-18856)
SSRF in CVE-2026-18856 (CVE-2026-18856). Risk of unauthorized operations or information disclosure.
CVE-2026-70620 SSRF (Server-Side Request Forgery) in CVE-2026-70620 (CVE-2026-70620)
SSRF in CVE-2026-70620 (CVE-2026-70620). Confidential information can be exposed externally.
CVE-2026-70591 SSRF (Server-Side Request Forgery) in ghost (CVE-2026-70591)
SSRF in ghost (CVE-2026-70591). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.54.1` or later.
CVE-2026-66901 Vulnerability in CVE-2026-66901 (CVE-2026-66901)
vulnerability in CVE-2026-66901 (CVE-2026-66901). Confidential information can be exposed externally.
CVE-2026-54020 Vulnerability in open-webui (CVE-2026-54020)
vulnerability in open-webui (CVE-2026-54020). Confidential information can be exposed externally. Exploitable via ``image_url``. Mitigation: upgrade to `0.11.0` or later.
CVE-2026-70485 SSRF (Server-Side Request Forgery) in open-webui (CVE-2026-70485)
SSRF in open-webui (CVE-2026-70485). Confidential information can be exposed externally. Exploitable via `POST /api/v1/retrieval/process/web`. Mitigation: upgrade to `0.11.0` or later.
CVE-2026-70480 SSRF (Server-Side Request Forgery) in open-webui (CVE-2026-70480)
SSRF in open-webui (CVE-2026-70480). Risk of unauthorized operations or information disclosure. Exploitable via ``vega``. Mitigation: upgrade to `5278eb906` or later.
CVE-2026-70479 SSRF (Server-Side Request Forgery) in open-webui (CVE-2026-70479)
SSRF in open-webui (CVE-2026-70479). Confidential information can be exposed externally. Exploitable via ``PLAYWRIGHT_WS_URL``. Mitigation: upgrade to `0.11.0` or later.
CVE-2026-47618 SSRF (Server-Side Request Forgery) in nvidia (CVE-2026-47618)
SSRF in nvidia (CVE-2026-47618). Confidential information can be exposed externally.
CVE-2026-47617 SSRF (Server-Side Request Forgery) in nvidia (CVE-2026-47617)
SSRF in nvidia (CVE-2026-47617). Confidential information can be exposed externally.
CVE-2026-47613 SSRF (Server-Side Request Forgery) in nvidia (CVE-2026-47613)
SSRF in nvidia (CVE-2026-47613). Confidential information can be exposed externally.
CVE-2026-47614 SSRF (Server-Side Request Forgery) in nvidia (CVE-2026-47614)
SSRF in nvidia (CVE-2026-47614). Confidential information can be exposed externally.
CVE-2026-47616 SSRF (Server-Side Request Forgery) in nvidia (CVE-2026-47616)
SSRF in nvidia (CVE-2026-47616). Confidential information can be exposed externally.
CVE-2026-47615 SSRF (Server-Side Request Forgery) in nvidia (CVE-2026-47615)
SSRF in nvidia (CVE-2026-47615). Confidential information can be exposed externally.
CVE-2026-15307 Vulnerability in django (CVE-2026-15307)
vulnerability in django (CVE-2026-15307). Successful exploitation can lead to full system takeover. Exploitable via ``django.contrib.gis.gdal.GDALRaster``.
CVE-2026-18775 SSRF (Server-Side Request Forgery) in CVE-2026-18775 (CVE-2026-18775)
SSRF in CVE-2026-18775 (CVE-2026-18775). Risk of unauthorized operations or information disclosure.
CVE-2026-18774 SSRF (Server-Side Request Forgery) in CVE-2026-18774 (CVE-2026-18774)
SSRF in CVE-2026-18774 (CVE-2026-18774). Risk of unauthorized operations or information disclosure.
CVE-2026-69257 SSRF (Server-Side Request Forgery) in flowise (CVE-2026-69257)
SSRF in flowise (CVE-2026-69257). Risk of unauthorized operations or information disclosure. Exploitable via ``httpSecurity.ts``. Mitigation: upgrade to `3.1.3` or later.
CVE-2026-70367 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-70367)
SSRF in ssrf (CVE-2026-70367). Risk of unauthorized operations or information disclosure.
CVE-2026-16536 SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-16536)
SSRF in wordpress (CVE-2026-16536). Risk of unauthorized operations or information disclosure.
CVE-2026-14939 SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-14939)
SSRF in wordpress (CVE-2026-14939). Confidential information can be exposed externally.
CVE-2026-10526 SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-10526)
SSRF in wordpress (CVE-2026-10526). Risk of unauthorized operations or information disclosure.
CVE-2026-66325 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-66325)
SSRF in ssrf (CVE-2026-66325). Risk of unauthorized operations or information disclosure.
CVE-2026-48331 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-48331)
SSRF in ssrf (CVE-2026-48331). Successful exploitation can lead to full system takeover.
CVE-2026-18736 SSRF (Server-Side Request Forgery) in CVE-2026-18736 (CVE-2026-18736)
SSRF in CVE-2026-18736 (CVE-2026-18736). Risk of unauthorized operations or information disclosure.
CVE-2026-18647 SSRF (Server-Side Request Forgery) in CVE-2026-18647 (CVE-2026-18647)
SSRF in CVE-2026-18647 (CVE-2026-18647). Risk of unauthorized operations or information disclosure.
CVE-2026-69246 Vulnerability in guzzlehttp/guzzle (CVE-2026-69246)
vulnerability in guzzlehttp/guzzle (CVE-2026-69246). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Mitigation: upgrade to `7.15.2` or later.
CVE-2026-69192 Vulnerability in ip-address (CVE-2026-69192)
vulnerability in ip-address (CVE-2026-69192). Risk of unauthorized operations or information disclosure. Exploitable via ``Address4``. Mitigation: upgrade to `10.3.1` or later.
CVE-2026-69198 Vulnerability in ip-address (CVE-2026-69198)
vulnerability in ip-address (CVE-2026-69198). Risk of unauthorized operations or information disclosure. Exploitable via ``isInSubnet``. Mitigation: upgrade to `10.2.2` or later.
CVE-2026-69078 SSRF (Server-Side Request Forgery) in CVE-2026-69078 (CVE-2026-69078)
SSRF in CVE-2026-69078 (CVE-2026-69078). Risk of unauthorized operations or information disclosure.
CVE-2026-67311 SSRF (Server-Side Request Forgery) in CVE-2026-67311 (CVE-2026-67311)
SSRF in CVE-2026-67311 (CVE-2026-67311). Confidential information can be exposed externally.
CVE-2026-13604 SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-13604)
SSRF in wordpress (CVE-2026-13604). Risk of unauthorized operations or information disclosure.
CVE-2026-52371 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-52371)
SSRF in ssrf (CVE-2026-52371). Confidential information can be exposed externally.
CVE-2026-57232 SSRF (Server-Side Request Forgery) in symfony (CVE-2026-57232)
SSRF in symfony (CVE-2026-57232). Risk of unauthorized operations or information disclosure.
CVE-2026-53500 SSRF (Server-Side Request Forgery) in thumbor (CVE-2026-53500)
SSRF in thumbor (CVE-2026-53500). Confidential information can be exposed externally. Exploitable via ``ALLOWED_SOURCES``. Mitigation: upgrade to `7.8.0` or later.
CVE-2026-54725 SSRF (Server-Side Request Forgery) in github.com/bank-vaults/vault-secrets-webhook (CVE-2026-54725)
SSRF in github.com/bank-vaults/vault-secrets-webhook (CVE-2026-54725). Confidential information can be exposed externally. Exploitable via ``VaultAddrAnnotation``. Mitigation: upgrade to `1.23.1` or later.
CVE-2026-54729 SSRF (Server-Side Request Forgery) in dssrf (CVE-2026-54729)
SSRF in dssrf (CVE-2026-54729). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.0.5` or later.
CVE-2026-59231 SSRF (Server-Side Request Forgery) in CVE-2026-59231 (CVE-2026-59231)
SSRF in CVE-2026-59231 (CVE-2026-59231). Risk of unauthorized operations or information disclosure.
CVE-2026-14540 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-14540)
SSRF in ssrf (CVE-2026-14540). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →