Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-76389 |
|
SSRF (Server-Side Request Forgery) in cisco (CVE-2026-76389)
SSRF in cisco (CVE-2026-76389). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76361 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-76361)
SSRF in ssrf (CVE-2026-76361). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76351 |
|
SSRF (Server-Side Request Forgery) in splunk (CVE-2026-76351)
SSRF in splunk (CVE-2026-76351). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76347 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-76347)
SSRF in ssrf (CVE-2026-76347). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53549 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-53549 (CVE-2026-53549)
SSRF in CVE-2026-53549 (CVE-2026-53549). Confidential information can be exposed externally. Exploitable via `POST /host/db/proxy/test`.
|
| CVE-2026-68558 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-68558 (CVE-2026-68558)
SSRF in CVE-2026-68558 (CVE-2026-68558). Confidential information can be exposed externally.
|
| CVE-2026-66794 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-66794 (CVE-2026-66794)
SSRF in CVE-2026-66794 (CVE-2026-66794). Confidential information can be exposed externally.
|
| CVE-2026-62680 |
|
Path Traversal in CVE-2026-62680 (CVE-2026-62680)
path traversal in CVE-2026-62680 (CVE-2026-62680). Confidential information can be exposed externally.
|
| CVE-2026-75583 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-75583)
SSRF in ssrf (CVE-2026-75583). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62668 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-62668 (CVE-2026-62668)
SSRF in CVE-2026-62668 (CVE-2026-62668). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20314 |
|
SSRF (Server-Side Request Forgery) in Cisco ssrf (CVE-2026-20314)
SSRF in Cisco ssrf (CVE-2026-20314). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76239 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-76239)
SSRF in ssrf (CVE-2026-76239). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76225 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-76225 (CVE-2026-76225)
SSRF in CVE-2026-76225 (CVE-2026-76225). Confidential information can be exposed externally.
|
| CVE-2026-54794 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-54794)
SSRF in ssrf (CVE-2026-54794). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76164 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-76164)
SSRF in ssrf (CVE-2026-76164). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17565 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-17565)
SSRF in wordpress (CVE-2026-17565). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71303 |
|
SSRF (Server-Side Request Forgery) in lemur (CVE-2026-71303)
SSRF in lemur (CVE-2026-71303). Confidential information can be exposed externally. Exploitable via `PUT /api/1/authorities/`. Mitigation: upgrade to `1.9.3` or later.
|
| CVE-2026-70666 |
|
SSRF (Server-Side Request Forgery) in lemur (CVE-2026-70666)
SSRF in lemur (CVE-2026-70666). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /authorities/`. Mitigation: upgrade to `1.9.3` or later.
|
| CVE-2026-65985 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-65985)
SSRF in ssrf (CVE-2026-65985). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70667 |
|
Vulnerability in lemur (CVE-2026-70667)
vulnerability in lemur (CVE-2026-70667). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/1/certificates/upload`. Mitigation: upgrade to `1.9.3` or later.
|
| CVE-2026-68927 |
|
SSRF (Server-Side Request Forgery) in mobsf (CVE-2026-68927)
SSRF in mobsf (CVE-2026-68927). Risk of unauthorized operations or information disclosure. Exploitable via ``rebind.example``. Mitigation: upgrade to `4.5.1` or later.
|
| CVE-2026-63643 |
|
Vulnerability in magicmirror (CVE-2026-63643)
vulnerability in magicmirror (CVE-2026-63643). Risk of unauthorized operations or information disclosure. Exploitable via ``ADD_CALENDAR``. Mitigation: upgrade to `2.37.0` or later.
|
| CVE-2026-63642 |
|
SSRF (Server-Side Request Forgery) in magicmirror (CVE-2026-63642)
SSRF in magicmirror (CVE-2026-63642). Risk of unauthorized operations or information disclosure. Exploitable via ``CHECK_ARTICLE_URL``. Mitigation: upgrade to `2.37.0` or later.
|
| CVE-2026-75856 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-75856)
SSRF in ssrf (CVE-2026-75856). Confidential information can be exposed externally.
|
| CVE-2026-71365 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-71365)
SSRF in ssrf (CVE-2026-71365). Confidential information can be exposed externally. Exploitable via `Authorization header`.
|
| CVE-2026-45123 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-45123 (CVE-2026-45123)
SSRF in CVE-2026-45123 (CVE-2026-45123). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12564 |
|
SSRF (Server-Side Request Forgery) in django (CVE-2026-12564)
SSRF in django (CVE-2026-12564). Confidential information can be exposed externally.
|
| CVE-2026-75898 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-75898 (CVE-2026-75898)
SSRF in CVE-2026-75898 (CVE-2026-75898). Confidential information can be exposed externally.
|
| CVE-2026-32473 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-32473)
SSRF in ssrf (CVE-2026-32473). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32553 |
|
Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions.
Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions.
|
| CVE-2026-32467 |
|
Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions.
Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions.
|
| CVE-2026-75844 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-75844 (CVE-2026-75844)
SSRF in CVE-2026-75844 (CVE-2026-75844). Confidential information can be exposed externally.
|
| CVE-2026-74905 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-74905)
SSRF in ssrf (CVE-2026-74905). Confidential information can be exposed externally.
|
| CVE-2026-34884 |
|
SSRF (Server-Side Request Forgery) in apache (CVE-2026-34884)
SSRF in apache (CVE-2026-34884). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64849 KEV |
|
[KEV] SSRF (Server-Side Request Forgery) in mlflow (CVE-2026-64849)
SSRF in mlflow (CVE-2026-64849). Confidential information can be exposed externally. Exploitable via `POST /api/2.0/mlflow/webhooks/{id}/test`. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `3.15.0` or later.
|
| CVE-2026-56677 |
|
Vulnerability in 9router (CVE-2026-56677)
vulnerability in 9router (CVE-2026-56677). Data can be tampered with by attackers. Exploitable via `POST /api/auth/oidc/test`.
|
| CVE-2026-73560 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-73560 (CVE-2026-73560)
SSRF in CVE-2026-73560 (CVE-2026-73560). Confidential information can be exposed externally.
|
| CVE-2026-50775 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-50775)
SSRF in ssrf (CVE-2026-50775). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75054 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-75054)
SSRF in ssrf (CVE-2026-75054). Confidential information can be exposed externally.
|
| CVE-2026-75053 |
|
In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint
In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint
|
| CVE-2026-74858 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-74858 (CVE-2026-74858)
SSRF in CVE-2026-74858 (CVE-2026-74858). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75006 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-75006)
SSRF in ssrf (CVE-2026-75006). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74842 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-74842 (CVE-2026-74842)
SSRF in CVE-2026-74842 (CVE-2026-74842). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19984 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-19984)
SSRF in ssrf (CVE-2026-19984). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13700 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-13700)
SSRF in wordpress (CVE-2026-13700). Confidential information can be exposed externally.
|
| CVE-2026-19957 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-19957)
SSRF in ssrf (CVE-2026-19957). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19956 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-19956 (CVE-2026-19956)
SSRF in CVE-2026-19956 (CVE-2026-19956). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73058 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-73058)
SSRF in ssrf (CVE-2026-73058). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17123 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-17123)
SSRF in wordpress (CVE-2026-17123). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19927 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-19927 (CVE-2026-19927)
SSRF in CVE-2026-19927 (CVE-2026-19927). Risk of unauthorized operations or information disclosure.
|