Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-54745 |
|
Vulnerability in CVE-2026-54745 (CVE-2026-54745)
vulnerability in CVE-2026-54745 (CVE-2026-54745). Successful exploitation can lead to full system takeover. Exploitable via `Referer header`.
|
| CVE-2026-75332 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-75332)
SSRF in ssrf (CVE-2026-75332). Confidential information can be exposed externally.
|
| CVE-2026-75340 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-75340)
SSRF in ssrf (CVE-2026-75340). Confidential information can be exposed externally.
|
| CVE-2026-76193 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-76193)
SSRF in ssrf (CVE-2026-76193). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55976 |
|
SSRF (Server-Side Request Forgery) in apache (CVE-2026-55976)
SSRF in apache (CVE-2026-55976). Confidential information can be exposed externally.
|
| CVE-2026-78003 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-78003)
SSRF in wordpress (CVE-2026-78003). Successful exploitation can lead to full system takeover.
|
| CVE-2026-69502 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-69502)
SSRF in ssrf (CVE-2026-69502). Confidential information can be exposed externally.
|
| CVE-2026-59085 |
|
SSRF (Server-Side Request Forgery) in apache (CVE-2026-59085)
SSRF in apache (CVE-2026-59085). Confidential information can be exposed externally.
|
| CVE-2026-69851 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-69851)
SSRF in ssrf (CVE-2026-69851). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65801 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-65801)
SSRF in ssrf (CVE-2026-65801). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71428 |
|
Open Redirect in CVE-2026-71428 (CVE-2026-71428)
vulnerability in CVE-2026-71428 (CVE-2026-71428). Confidential information can be exposed externally.
|
| CVE-2026-66794 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-66794 (CVE-2026-66794)
SSRF in CVE-2026-66794 (CVE-2026-66794). Confidential information can be exposed externally.
|
| CVE-2026-12564 |
|
SSRF (Server-Side Request Forgery) in django (CVE-2026-12564)
SSRF in django (CVE-2026-12564). Confidential information can be exposed externally.
|
| CVE-2026-34884 |
|
SSRF (Server-Side Request Forgery) in apache (CVE-2026-34884)
SSRF in apache (CVE-2026-34884). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64849 KEV |
|
[KEV] SSRF (Server-Side Request Forgery) in mlflow (CVE-2026-64849)
SSRF in mlflow (CVE-2026-64849). Confidential information can be exposed externally. Exploitable via `POST /api/2.0/mlflow/webhooks/{id}/test`. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `3.15.0` or later.
|
| CVE-2026-50775 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-50775)
SSRF in ssrf (CVE-2026-50775). Successful exploitation can lead to full system takeover.
|
| CVE-2026-69223 |
|
SSRF (Server-Side Request Forgery) in apache (CVE-2026-69223)
SSRF in apache (CVE-2026-69223). Confidential information can be exposed externally.
|
| CVE-2026-73080 |
|
SSRF (Server-Side Request Forgery) in github.com/seaweedfs/seaweedfs (CVE-2026-73080)
SSRF in github.com/seaweedfs/seaweedfs (CVE-2026-73080). Confidential information can be exposed externally. Exploitable via ``VolumeServer.FetchAndWriteNeedle``. Mitigation: upgrade to `0.0.0-20260512171120-69da20bdaec9` or later.
|
| CVE-2026-19516 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-19516 (CVE-2026-19516)
SSRF in CVE-2026-19516 (CVE-2026-19516). Confidential information can be exposed externally.
|
| CVE-2026-70332 |
|
Cross-Site Scripting (XSS) in ssrf (CVE-2026-70332)
cross-site scripting in ssrf (CVE-2026-70332). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15732 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-15732 (CVE-2026-15732)
SSRF in CVE-2026-15732 (CVE-2026-15732). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12605 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-12605)
SSRF in ssrf (CVE-2026-12605). Successful exploitation can lead to full system takeover. Exploitable via ``gfresttoken``.
|
| CVE-2026-48331 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-48331)
SSRF in ssrf (CVE-2026-48331). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54725 |
|
SSRF (Server-Side Request Forgery) in github.com/bank-vaults/vault-secrets-webhook (CVE-2026-54725)
SSRF in github.com/bank-vaults/vault-secrets-webhook (CVE-2026-54725). Confidential information can be exposed externally. Exploitable via ``VaultAddrAnnotation``. Mitigation: upgrade to `1.23.1` or later.
|
| CVE-2026-67426 |
|
Vulnerability in flyto-core (CVE-2026-67426)
vulnerability in flyto-core (CVE-2026-67426). Confidential information can be exposed externally. Exploitable via `POST /run`. Mitigation: upgrade to `2.26.7` or later.
|
| CVE-2026-54735 |
|
SSRF (Server-Side Request Forgery) in github.com/prebid/prebid-server/v4 (CVE-2026-54735)
SSRF in github.com/prebid/prebid-server/v4 (CVE-2026-54735). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.4.0` or later.
|
| CVE-2026-17552 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-17552 (CVE-2026-17552)
SSRF in CVE-2026-17552 (CVE-2026-17552). Confidential information can be exposed externally.
|
| CVE-2026-57106 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-57106)
SSRF in ssrf (CVE-2026-57106). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64873 |
|
Custom query URLs could access internal or reserved network services.
Custom query URLs could access internal or reserved network services.
|
| CVE-2026-65057 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-65057 (CVE-2026-65057)
SSRF in CVE-2026-65057 (CVE-2026-65057). Confidential information can be exposed externally.
|
| CVE-2026-48259 |
|
SSRF (Server-Side Request Forgery) in c (CVE-2026-48259)
SSRF in c (CVE-2026-48259). Confidential information can be exposed externally.
|
| CVE-2026-15409 KEV |
|
[KEV] SSRF (Server-Side Request Forgery) in Sonicwall ssrf (CVE-2026-15409)
SSRF in Sonicwall ssrf (CVE-2026-15409). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-15143 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-15143 (CVE-2026-15143)
SSRF in CVE-2026-15143 (CVE-2026-15143). Confidential information can be exposed externally.
|
| CVE-2026-15378 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-15378)
SSRF in ssrf (CVE-2026-15378). Confidential information can be exposed externally.
|
| CVE-2026-59702 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-59702 (CVE-2026-59702)
SSRF in CVE-2026-59702 (CVE-2026-59702). Confidential information can be exposed externally. Exploitable via `POST /api/pack`.
|
| CVE-2026-53513 |
|
Vulnerability in @better-auth/sso (CVE-2026-53513)
vulnerability in @better-auth/sso (CVE-2026-53513). Confidential information can be exposed externally. Exploitable via `POST /sso/register`. Mitigation: upgrade to `1.6.11` or later.
|
| CVE-2025-53830 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2025-53830)
SSRF in ssrf (CVE-2025-53830). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48205 |
|
Vulnerability in org.apache.camel:camel-dns (CVE-2026-48205)
vulnerability in org.apache.camel:camel-dns (CVE-2026-48205). Confidential information can be exposed externally. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-48203 |
|
Vulnerability in org.apache.camel:camel-solr (CVE-2026-48203)
vulnerability in org.apache.camel:camel-solr (CVE-2026-48203). Confidential information can be exposed externally. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-22874 |
|
SSRF (Server-Side Request Forgery) in code.gitea.io/gitea (CVE-2026-22874)
SSRF in code.gitea.io/gitea (CVE-2026-22874). Confidential information can be exposed externally. Exploitable via ``MatchBuiltinExternal``. Mitigation: upgrade to `1.26.3` or later.
|
| CVE-2026-45499 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-45499)
SSRF in ssrf (CVE-2026-45499). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57100 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-57100)
SSRF in ssrf (CVE-2026-57100). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55115 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-55115)
SSRF in ssrf (CVE-2026-55115). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49869 |
|
OS Command Injection in kestra (CVE-2026-49869)
OS command injection in kestra (CVE-2026-49869). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.0.45` or later.
|
| CVE-2026-55166 |
|
Vulnerability in lemur (CVE-2026-55166)
vulnerability in lemur (CVE-2026-55166). Confidential information can be exposed externally. Exploitable via `POST /api/1/authorities`. Mitigation: upgrade to `1.9.2` or later.
|
| CVE-2026-55455 |
|
SSRF (Server-Side Request Forgery) in appsmith (CVE-2026-55455)
SSRF in appsmith (CVE-2026-55455). Confidential information can be exposed externally. Mitigation: upgrade to `2.1` or later.
|
| CVE-2026-54157 |
|
SSRF (Server-Side Request Forgery) in @lobehub/lobehub (CVE-2026-54157)
SSRF in @lobehub/lobehub (CVE-2026-54157). Confidential information can be exposed externally. Exploitable via `POST /webapi/proxy`. Mitigation: upgrade to `2.1.57` or later.
|
| CVE-2026-50887 |
|
SSRF (Server-Side Request Forgery) in shlinkio/shlink (CVE-2026-50887)
SSRF in shlinkio/shlink (CVE-2026-50887). Confidential information can be exposed externally.
|
| CVE-2026-47938 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-47938)
SSRF in ssrf (CVE-2026-47938). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43986 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-43986)
SSRF in ssrf (CVE-2026-43986). Confidential information can be exposed externally. Exploitable via ``image_hash_lookup``.
|