Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-72904 |
|
Command Injection in ssrf (CVE-2026-72904)
command injection in ssrf (CVE-2026-72904). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72761 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-72761)
SSRF in ssrf (CVE-2026-72761). Risk of unauthorized operations or information disclosure. Exploitable via ``ip.is_global``.
|
| CVE-2026-72591 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-72591)
SSRF in ssrf (CVE-2026-72591). Confidential information can be exposed externally. Exploitable via `PATCH /apis/web/v1/album/{id}/image`.
|
| CVE-2026-72581 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-72581)
SSRF in ssrf (CVE-2026-72581). Confidential information can be exposed externally.
|
| CVE-2026-72566 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-72566)
SSRF in ssrf (CVE-2026-72566). Confidential information can be exposed externally.
|
| CVE-2026-12372 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-12372)
SSRF in ssrf (CVE-2026-12372). Risk of unauthorized operations or information disclosure. Exploitable via ``ipaddress``.
|
| CVE-2026-67620 |
|
Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard...
Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard...
|
| CVE-2026-19246 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-19246)
SSRF in ssrf (CVE-2026-19246). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17597 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-17597)
SSRF in ssrf (CVE-2026-17597). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16637 |
|
Vulnerability in ssrf (CVE-2026-16637)
vulnerability in ssrf (CVE-2026-16637). Confidential information can be exposed externally.
|
| CVE-2026-16027 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-16027)
SSRF in ssrf (CVE-2026-16027). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70332 |
|
Cross-Site Scripting (XSS) in ssrf (CVE-2026-70332)
cross-site scripting in ssrf (CVE-2026-70332). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53983 |
|
SSRF (Server-Side Request Forgery) in c (CVE-2026-53983)
SSRF in c (CVE-2026-53983). Confidential information can be exposed externally.
|
| CVE-2026-48080 |
|
Information Disclosure in ssrf (CVE-2026-48080)
vulnerability in ssrf (CVE-2026-48080). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/tenants/{id}`.
|
| CVE-2026-12605 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-12605)
SSRF in ssrf (CVE-2026-12605). Successful exploitation can lead to full system takeover. Exploitable via ``gfresttoken``.
|
| CVE-2026-18597 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-18597)
SSRF in ssrf (CVE-2026-18597). Confidential information can be exposed externally.
|
| CVE-2026-34966 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-34966)
SSRF in ssrf (CVE-2026-34966). Confidential information can be exposed externally.
|
| CVE-2026-55524 |
|
Vulnerability in praisonaiagents (CVE-2026-55524)
vulnerability in praisonaiagents (CVE-2026-55524). Confidential information can be exposed externally. Mitigation: upgrade to `1.6.58` or later.
|
| CVE-2026-55523 |
|
SSRF (Server-Side Request Forgery) in praisonaiagents (CVE-2026-55523)
SSRF in praisonaiagents (CVE-2026-55523). Risk of unauthorized operations or information disclosure. Exploitable via ``web_crawl``. Mitigation: upgrade to `1.6.58` or later.
|
| CVE-2026-9081 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-9081)
SSRF in ssrf (CVE-2026-9081). Confidential information can be exposed externally.
|
| CVE-2026-7657 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-7657)
SSRF in ssrf (CVE-2026-7657). Confidential information can be exposed externally.
|
| CVE-2026-17617 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-17617)
SSRF in ssrf (CVE-2026-17617). Confidential information can be exposed externally.
|
| CVE-2026-71280 |
|
go-shiori's DownloadBookmark() (internal/core/download.go) fetches a caller-supplied bookmark URL...
go-shiori's DownloadBookmark() (internal/core/download.go) fetches a caller-supplied bookmark URL...
|
| CVE-2026-71272 |
|
Memos' webhook dispatch function safeDialContext() (internal/webhook/webhook.go) resolves the...
Memos' webhook dispatch function safeDialContext() (internal/webhook/webhook.go) resolves the...
|
| CVE-2026-71270 |
|
Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated...
Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated...
|
| CVE-2026-71250 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-71250)
SSRF in ssrf (CVE-2026-71250). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71246 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-71246)
SSRF in ssrf (CVE-2026-71246). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71235 |
|
Code Injection in ssrf (CVE-2026-71235)
code injection in ssrf (CVE-2026-71235). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71211 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-71211)
SSRF in ssrf (CVE-2026-71211). Confidential information can be exposed externally.
|
| CVE-2026-71210 |
|
Vulnerability in ssrf (CVE-2026-71210)
vulnerability in ssrf (CVE-2026-71210). Confidential information can be exposed externally.
|
| CVE-2026-70367 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-70367)
SSRF in ssrf (CVE-2026-70367). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-69250 |
|
Vulnerability in flowise (CVE-2026-69250)
vulnerability in flowise (CVE-2026-69250). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/oauth2-credential/refresh/`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-66325 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-66325)
SSRF in ssrf (CVE-2026-66325). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48331 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-48331)
SSRF in ssrf (CVE-2026-48331). Successful exploitation can lead to full system takeover.
|
| CVE-2026-69192 |
|
Vulnerability in ip-address (CVE-2026-69192)
vulnerability in ip-address (CVE-2026-69192). Risk of unauthorized operations or information disclosure. Exploitable via ``Address4``. Mitigation: upgrade to `10.3.1` or later.
|
| CVE-2026-69198 |
|
Vulnerability in ip-address (CVE-2026-69198)
vulnerability in ip-address (CVE-2026-69198). Risk of unauthorized operations or information disclosure. Exploitable via ``isInSubnet``. Mitigation: upgrade to `10.2.2` or later.
|
| CVE-2026-52371 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-52371)
SSRF in ssrf (CVE-2026-52371). Confidential information can be exposed externally.
|
| CVE-2026-57232 |
|
SSRF (Server-Side Request Forgery) in symfony (CVE-2026-57232)
SSRF in symfony (CVE-2026-57232). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54729 |
|
SSRF (Server-Side Request Forgery) in dssrf (CVE-2026-54729)
SSRF in dssrf (CVE-2026-54729). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.0.5` or later.
|
| CVE-2026-18446 |
|
Vulnerability in fast-uri (CVE-2026-18446)
vulnerability in fast-uri (CVE-2026-18446). Data can be tampered with by attackers. Exploitable via ``URL``. Mitigation: upgrade to `4.1.2` or later.
|
| CVE-2026-14540 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-14540)
SSRF in ssrf (CVE-2026-14540). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15974 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-15974)
SSRF in ssrf (CVE-2026-15974). Confidential information can be exposed externally.
|
| CVE-2026-67530 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-67530)
SSRF in ssrf (CVE-2026-67530). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57862 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-57862)
SSRF in ssrf (CVE-2026-57862). Confidential information can be exposed externally.
|
| CVE-2026-54722 |
|
Vulnerability in dssrf (CVE-2026-54722)
vulnerability in dssrf (CVE-2026-54722). Risk of unauthorized operations or information disclosure. Exploitable via ``is_url_safe``. Mitigation: upgrade to `1.0.4` or later.
|
| CVE-2026-14980 |
|
Privilege Escalation in ssrf (CVE-2026-14980)
vulnerability in ssrf (CVE-2026-14980). Confidential information can be exposed externally.
|
| CVE-2026-18369 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-18369)
SSRF in ssrf (CVE-2026-18369). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67428 |
|
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
|
| CVE-2026-67426 |
|
Vulnerability in flyto-core (CVE-2026-67426)
vulnerability in flyto-core (CVE-2026-67426). Confidential information can be exposed externally. Exploitable via `POST /run`. Mitigation: upgrade to `2.26.7` or later.
|
| CVE-2026-67201 |
|
V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass...
V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass...
|