Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-16084 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-16084 (CVE-2026-16084)
SSRF in CVE-2026-16084 (CVE-2026-16084). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16074 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-16074 (CVE-2026-16074)
SSRF in CVE-2026-16074 (CVE-2026-16074). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7754 |
|
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery ...
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery ...
|
| CVE-2026-51833 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-51833)
SSRF in ssrf (CVE-2026-51833). Confidential information can be exposed externally.
|
| CVE-2026-63096 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-63096 (CVE-2026-63096)
SSRF in CVE-2026-63096 (CVE-2026-63096). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16016 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-16016 (CVE-2026-16016)
SSRF in CVE-2026-16016 (CVE-2026-16016). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62234 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-62234 (CVE-2026-62234)
SSRF in CVE-2026-62234 (CVE-2026-62234). Confidential information can be exposed externally.
|
| CVE-2026-62227 |
|
SSRF (Server-Side Request Forgery) in openclaw (CVE-2026-62227)
SSRF in openclaw (CVE-2026-62227). Confidential information can be exposed externally.
|
| CVE-2026-62226 |
|
SSRF (Server-Side Request Forgery) in openclaw (CVE-2026-62226)
SSRF in openclaw (CVE-2026-62226). Confidential information can be exposed externally.
|
| CVE-2026-62216 |
|
SSRF (Server-Side Request Forgery) in openclaw (CVE-2026-62216)
SSRF in openclaw (CVE-2026-62216). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62201 |
|
SSRF (Server-Side Request Forgery) in openclaw (CVE-2026-62201)
SSRF in openclaw (CVE-2026-62201). Confidential information can be exposed externally.
|
| CVE-2026-46404 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-46404 (CVE-2026-46404)
SSRF in CVE-2026-46404 (CVE-2026-46404). Confidential information can be exposed externally.
|
| CVE-2026-63088 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-63088)
SSRF in ssrf (CVE-2026-63088). Confidential information can be exposed externally.
|
| CVE-2026-63086 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-63086)
SSRF in ssrf (CVE-2026-63086). Confidential information can be exposed externally.
|
| CVE-2026-59867 |
|
Path Traversal in Microsoft.OpenApi.Kiota (CVE-2026-59867)
path traversal in Microsoft.OpenApi.Kiota (CVE-2026-59867). Confidential information can be exposed externally. Exploitable via ``REMOTE_KIOTA_PROP``. Mitigation: upgrade to `1.29.1` or later.
|
| CVE-2026-63306 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-63306 (CVE-2026-63306)
SSRF in CVE-2026-63306 (CVE-2026-63306). Confidential information can be exposed externally.
|
| CVE-2026-53446 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-53446 (CVE-2026-53446)
SSRF in CVE-2026-53446 (CVE-2026-53446). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54457 |
|
Vulnerability in tensorzero (CVE-2026-54457)
vulnerability in tensorzero (CVE-2026-54457). Confidential information can be exposed externally. Exploitable via ``storage_path``. Mitigation: upgrade to `2026.6.0` or later.
|
| CVE-2026-56678 |
|
Vulnerability in CVE-2026-56678 (CVE-2026-56678)
vulnerability in CVE-2026-56678 (CVE-2026-56678). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/oauth/kiro/api-key`.
|
| CVE-2026-15746 |
|
SSRF (Server-Side Request Forgery) in Amazon aws (CVE-2026-15746)
SSRF in Amazon aws (CVE-2026-15746). Confidential information can be exposed externally. Exploitable via `Authorization header`.
|
| CVE-2026-54494 |
|
SSRF (Server-Side Request Forgery) in phanan/koel (CVE-2026-54494)
SSRF in phanan/koel (CVE-2026-54494). Risk of unauthorized operations or information disclosure. Exploitable via `GET /secret`. Mitigation: upgrade to `9.7.1` or later.
|
| CVE-2026-54491 |
|
SSRF (Server-Side Request Forgery) in phanan/koel (CVE-2026-54491)
SSRF in phanan/koel (CVE-2026-54491). Confidential information can be exposed externally. Exploitable via `POST /api/podcasts`. Mitigation: upgrade to `9.7.1` or later.
|
| CVE-2026-54493 |
|
SSRF (Server-Side Request Forgery) in phanan/koel (CVE-2026-54493)
SSRF in phanan/koel (CVE-2026-54493). Confidential information can be exposed externally. Exploitable via ``SafeUrl``. Mitigation: upgrade to `9.7.0` or later.
|
| CVE-2026-54492 |
|
SSRF (Server-Side Request Forgery) in phanan/koel (CVE-2026-54492)
SSRF in phanan/koel (CVE-2026-54492). Risk of unauthorized operations or information disclosure. Exploitable via ``SafeUrl``. Mitigation: upgrade to `9.7.0` or later.
|
| CVE-2026-47160 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-47160)
SSRF in ssrf (CVE-2026-47160). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45806 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-45806 (CVE-2026-45806)
SSRF in CVE-2026-45806 (CVE-2026-45806). Confidential information can be exposed externally.
|
| CVE-2026-61835 |
|
SSRF (Server-Side Request Forgery) in directus (CVE-2026-61835)
SSRF in directus (CVE-2026-61835). Confidential information can be exposed externally. Exploitable via ``IMPORT_IP_DENY_LIST``. Mitigation: upgrade to `12.0.0` or later.
|
| CVE-2026-61646 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-61646)
SSRF in ssrf (CVE-2026-61646). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54562 |
|
SSRF (Server-Side Request Forgery) in github.com/cloudreve/Cloudreve/v4 (CVE-2026-54562)
SSRF in github.com/cloudreve/Cloudreve/v4 (CVE-2026-54562). Confidential information can be exposed externally. Exploitable via `POST /api/v4/workflow/download`. Mitigation: upgrade to `4.0.0-20260606025411-aaebf317a78f` or later.
|
| CVE-2026-61430 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-61430)
SSRF in ssrf (CVE-2026-61430). Confidential information can be exposed externally.
|
| CVE-2026-48290 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-48290)
SSRF in ssrf (CVE-2026-48290). Confidential information can be exposed externally.
|
| CVE-2026-15750 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-15750 (CVE-2026-15750)
SSRF in CVE-2026-15750 (CVE-2026-15750). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24234 |
|
SSRF (Server-Side Request Forgery) in dos (CVE-2026-24234)
SSRF in dos (CVE-2026-24234). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48259 |
|
SSRF (Server-Side Request Forgery) in c (CVE-2026-48259)
SSRF in c (CVE-2026-48259). Confidential information can be exposed externally.
|
| CVE-2026-61520 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-61520 (CVE-2026-61520)
SSRF in CVE-2026-61520 (CVE-2026-61520). Confidential information can be exposed externally.
|
| CVE-2026-48332 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-48332)
SSRF in ssrf (CVE-2026-48332). Confidential information can be exposed externally.
|
| CVE-2026-15643 |
|
SSRF (Server-Side Request Forgery) in Amazon aws (CVE-2026-15643)
SSRF in Amazon aws (CVE-2026-15643). Confidential information can be exposed externally.
|
| CVE-2026-55051 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-55051)
SSRF in ssrf (CVE-2026-55051). Confidential information can be exposed externally.
|
| CVE-2026-14646 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-14646)
SSRF in ssrf (CVE-2026-14646). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14645 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-14645 (CVE-2026-14645)
SSRF in CVE-2026-14645 (CVE-2026-14645). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7494 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-7494)
SSRF in ssrf (CVE-2026-7494). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62643 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-62643)
SSRF in ssrf (CVE-2026-62643). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52840 |
|
SSRF (Server-Side Request Forgery) in alextselegidis/easyappointments (CVE-2026-52840)
SSRF in alextselegidis/easyappointments (CVE-2026-52840). Risk of unauthorized operations or information disclosure. Exploitable via ``caldav_url``.
|
| CVE-2026-58478 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-58478)
SSRF in ssrf (CVE-2026-58478). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15183 |
|
SQL Injection in privilege-escalation (CVE-2026-15183)
SQL injection in privilege-escalation (CVE-2026-15183). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15668 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-15668 (CVE-2026-15668)
SSRF in CVE-2026-15668 (CVE-2026-15668). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15628 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-15628 (CVE-2026-15628)
SSRF in CVE-2026-15628 (CVE-2026-15628). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15624 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-15624 (CVE-2026-15624)
SSRF in CVE-2026-15624 (CVE-2026-15624). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15620 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-15620 (CVE-2026-15620)
SSRF in CVE-2026-15620 (CVE-2026-15620). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15619 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-15619 (CVE-2026-15619)
SSRF in CVE-2026-15619 (CVE-2026-15619). Risk of unauthorized operations or information disclosure.
|