Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: cwe-918 Clear
ID Title
CVE-2026-54729 SSRF (Server-Side Request Forgery) in dssrf (CVE-2026-54729)
SSRF in dssrf (CVE-2026-54729). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.0.5` or later.
CVE-2026-59231 SSRF (Server-Side Request Forgery) in CVE-2026-59231 (CVE-2026-59231)
SSRF in CVE-2026-59231 (CVE-2026-59231). Risk of unauthorized operations or information disclosure.
CVE-2026-14540 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-14540)
SSRF in ssrf (CVE-2026-14540). Risk of unauthorized operations or information disclosure.
CVE-2026-66415 SSRF (Server-Side Request Forgery) in path-traversal (CVE-2026-66415)
SSRF in path-traversal (CVE-2026-66415). Confidential information can be exposed externally.
CVE-2026-15974 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-15974)
SSRF in ssrf (CVE-2026-15974). Confidential information can be exposed externally.
CVE-2026-67530 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-67530)
SSRF in ssrf (CVE-2026-67530). Risk of unauthorized operations or information disclosure.
CVE-2026-64870 SSRF (Server-Side Request Forgery) in CVE-2026-64870 (CVE-2026-64870)
SSRF in CVE-2026-64870 (CVE-2026-64870). Risk of unauthorized operations or information disclosure.
CVE-2026-57862 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-57862)
SSRF in ssrf (CVE-2026-57862). Confidential information can be exposed externally.
CVE-2026-67346 SSRF (Server-Side Request Forgery) in CVE-2026-67346 (CVE-2026-67346)
SSRF in CVE-2026-67346 (CVE-2026-67346). Confidential information can be exposed externally.
CVE-2026-54885 SSRF (Server-Side Request Forgery) in CVE-2026-54885 (CVE-2026-54885)
SSRF in CVE-2026-54885 (CVE-2026-54885). Risk of unauthorized operations or information disclosure.
CVE-2026-18378 SSRF (Server-Side Request Forgery) in redhat (CVE-2026-18378)
SSRF in redhat (CVE-2026-18378). Confidential information can be exposed externally.
CVE-2026-18381 SSRF (Server-Side Request Forgery) in redhat (CVE-2026-18381)
SSRF in redhat (CVE-2026-18381). Confidential information can be exposed externally.
CVE-2026-18382 SSRF (Server-Side Request Forgery) in redhat (CVE-2026-18382)
SSRF in redhat (CVE-2026-18382). Confidential information can be exposed externally.
CVE-2026-18369 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-18369)
SSRF in ssrf (CVE-2026-18369). Risk of unauthorized operations or information disclosure.
CVE-2026-18353 SSRF (Server-Side Request Forgery) in CVE-2026-18353 (CVE-2026-18353)
SSRF in CVE-2026-18353 (CVE-2026-18353). Risk of unauthorized operations or information disclosure. Exploitable via `POST /v1/upload/sbom`.
CVE-2026-54249 SSRF (Server-Side Request Forgery) in pydantic-ai-slim (CVE-2026-54249)
SSRF in pydantic-ai-slim (CVE-2026-54249). Confidential information can be exposed externally. Exploitable via ``UploadedFile``. Mitigation: upgrade to `2.0.0b6` or later.
CVE-2026-67436 Vulnerability in CVE-2026-67436 (CVE-2026-67436)
vulnerability in CVE-2026-67436 (CVE-2026-67436). Risk of unauthorized operations or information disclosure.
CVE-2026-67435 Information Disclosure in linuxfabrik-lib (CVE-2026-67435)
vulnerability in linuxfabrik-lib (CVE-2026-67435). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Mitigation: upgrade to `6.0.0` or later.
CVE-2026-67428 Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
CVE-2026-67424 Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
CVE-2026-67426 Vulnerability in flyto-core (CVE-2026-67426)
vulnerability in flyto-core (CVE-2026-67426). Confidential information can be exposed externally. Exploitable via `POST /run`. Mitigation: upgrade to `2.26.7` or later.
CVE-2026-16328 In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address...
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address...
CVE-2026-54735 SSRF (Server-Side Request Forgery) in github.com/prebid/prebid-server/v4 (CVE-2026-54735)
SSRF in github.com/prebid/prebid-server/v4 (CVE-2026-54735). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.4.0` or later.
CVE-2026-54663 Vulnerability in swagger-typescript-api (CVE-2026-54663)
vulnerability in swagger-typescript-api (CVE-2026-54663). Risk of unauthorized operations or information disclosure. Exploitable via `GET /INTERNAL_ONLY_PATH/secret.json`. Mitigation: upgrade to `13.12.2` or later.
CVE-2026-54660 Information Disclosure in swagger-typescript-api (CVE-2026-54660)
vulnerability in swagger-typescript-api (CVE-2026-54660). Confidential information can be exposed externally. Exploitable via `GET /exfil-endpoint/data.json`. Mitigation: upgrade to `13.12.2` or later.
CVE-2026-6089 SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-6089)
SSRF in wordpress (CVE-2026-6089). Confidential information can be exposed externally.
CVE-2026-58189 SSRF (Server-Side Request Forgery) in apache (CVE-2026-58189)
SSRF in apache (CVE-2026-58189). Risk of unauthorized operations or information disclosure.
CVE-2026-55391 Vulnerability in datamodel-code-generator (CVE-2026-55391)
vulnerability in datamodel-code-generator (CVE-2026-55391). Confidential information can be exposed externally. Exploitable via ``httpx``. Mitigation: upgrade to `0.63.0` or later.
CVE-2026-54690 SSRF (Server-Side Request Forgery) in datamodel-code-generator (CVE-2026-54690)
SSRF in datamodel-code-generator (CVE-2026-54690). Confidential information can be exposed externally. Exploitable via ``None``. Mitigation: upgrade to `0.61.0` or later.
CVE-2026-54691 SSRF (Server-Side Request Forgery) in datamodel-code-generator (CVE-2026-54691)
SSRF in datamodel-code-generator (CVE-2026-54691). Confidential information can be exposed externally. Exploitable via ``http.get_body``. Mitigation: upgrade to `0.61.0` or later.
CVE-2026-4912 SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-4912)
SSRF in wordpress (CVE-2026-4912). Risk of unauthorized operations or information disclosure.
CVE-2026-14869 SSRF (Server-Side Request Forgery) in CVE-2026-14869 (CVE-2026-14869)
SSRF in CVE-2026-14869 (CVE-2026-14869). Confidential information can be exposed externally.
CVE-2026-54605 Information Disclosure in oauth (CVE-2026-54605)
vulnerability in oauth (CVE-2026-54605). Risk of unauthorized operations or information disclosure. Exploitable via ``Location``. Mitigation: upgrade to `1.1.6` or later.
CVE-2026-67173 SSRF (Server-Side Request Forgery) in CVE-2026-67173 (CVE-2026-67173)
SSRF in CVE-2026-67173 (CVE-2026-67173). Risk of unauthorized operations or information disclosure.
CVE-2026-43910 Vulnerability in io.appium:java-client (CVE-2026-43910)
vulnerability in io.appium:java-client (CVE-2026-43910). Confidential information can be exposed externally. Exploitable via `POST /wd/hub/session`. Mitigation: upgrade to `10.1.1` or later.
CVE-2026-65442 Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
CVE-2026-61953 Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
CVE-2026-65925 SSRF (Server-Side Request Forgery) in jfrog (CVE-2026-65925)
SSRF in jfrog (CVE-2026-65925). Confidential information can be exposed externally.
CVE-2026-65923 SSRF (Server-Side Request Forgery) in jfrog (CVE-2026-65923)
SSRF in jfrog (CVE-2026-65923). Confidential information can be exposed externally.
CVE-2026-65924 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-65924)
SSRF in ssrf (CVE-2026-65924). Confidential information can be exposed externally.
CVE-2026-65618 SSRF (Server-Side Request Forgery) in jfrog (CVE-2026-65618)
SSRF in jfrog (CVE-2026-65618). Confidential information can be exposed externally.
CVE-2026-16481 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-16481)
SSRF in ssrf (CVE-2026-16481). Risk of unauthorized operations or information disclosure.
CVE-2026-17192 SSRF (Server-Side Request Forgery) in CVE-2026-17192 (CVE-2026-17192)
SSRF in CVE-2026-17192 (CVE-2026-17192). Confidential information can be exposed externally.
CVE-2026-54272 Vulnerability in ip-address (CVE-2026-54272)
vulnerability in ip-address (CVE-2026-54272). Risk of unauthorized operations or information disclosure. Exploitable via ``Address6``. Mitigation: upgrade to `10.2.1` or later.
CVE-2026-17552 SSRF (Server-Side Request Forgery) in CVE-2026-17552 (CVE-2026-17552)
SSRF in CVE-2026-17552 (CVE-2026-17552). Confidential information can be exposed externally.
CVE-2026-65558 Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.
Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.
CVE-2026-66437 Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions.
Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions.
CVE-2026-59552 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-59552)
SSRF in ssrf (CVE-2026-59552). Risk of unauthorized operations or information disclosure.
CVE-2026-17534 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-17534)
SSRF in ssrf (CVE-2026-17534). Confidential information can be exposed externally.
CVE-2025-15662 SSRF (Server-Side Request Forgery) in wordpress (CVE-2025-15662)
SSRF in wordpress (CVE-2025-15662). Confidential information can be exposed externally.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →