Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.5
CVE-2026-61430
PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostnames at check time but re-reso…
Mitigation only
HIGH 8.2
CVE-2026-48290
CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the contex…
C2pa
after 0.84.0
MEDIUM 6.3
CVE-2026-15750
A weakness has been identified in mastergo-design mastergo-magic-mcp up to 0.2.0. Impacted is the function z.string of the file src/tools/get-compone…
Mitigation only
HIGH 7.7
CVE-2026-61520
Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery vulnerability in the image p…
Mitigation only
HIGH 7.7
CVE-2026-48332EPSS 11%
ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacke…
Coldfusion
Mitigation only
MEDIUM 6.8
CVE-2026-24234
NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal media fetching functions, where a network-accessible attacker could cause se…
Mitigation only
HIGH 7.3
CVE-2026-15643
AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with AWS HealthLa…
Mitigation only
HIGH 8.6
CVE-2026-48736
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, N…
Symfony
5.4.43 / 6.4.41+
CRITICAL 9.6
CVE-2026-48259
Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the conte…
Experience Manager
after 2020.5.0
CRITICAL 10.0
CVE-2026-15409 KEVEPSS 74%
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attack…
Sma6210 Firmware
Mitigation only
MEDIUM 6.5
CVE-2026-55051
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
Sharepoint Server
16.0.19725.20434+
MEDIUM 5.1
CVE-2026-14645
Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, all…
Mitigation only
CRITICAL 10.0
CVE-2026-62643
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to…
Webmail
1.6.17 / 1.7.2+
MEDIUM 5.3
CVE-2026-7494
Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-trust…
Mitigation only
MEDIUM 6.5
CVE-2026-58478
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated …
Sustainable Irrigation Platform
after 5.2.16
CRITICAL 9.2
CVE-2026-15183
Multiple input validation vulnerabilities in the Snowflake Spark Connector (spark-snowflake) versions prior to 3.2.1 can allow attackers to exfiltrat…
Mitigation only
MEDIUM 6.3
CVE-2026-15668
A vulnerability has been found in louisho5 picobot up to 0.2.0. This vulnerability affects the function WebTool.Execute of the file internal/agent/to…
Mitigation only
MEDIUM 6.3
CVE-2026-15628
A security flaw has been discovered in zhayujie chatgpt-on-wechat CowAgent up to 2.1.1. This issue affects the function Vision._download_to_data_url …
Patch available
MEDIUM 6.3
CVE-2026-15624
A vulnerability has been found in nextlevelbuilder GoClaw 3.13.3-beta.3. Affected by this vulnerability is the function bytePlusDownloadVideo of the …
Mitigation only
MEDIUM 6.3
CVE-2026-15620
A security vulnerability has been detected in mosaxiv clawlet up to 0.2.10. This affects the function tools.webFetch of the file tools/tool_web_fetch…
Mitigation only
MEDIUM 6.3
CVE-2026-15619
A weakness has been identified in mosaxiv clawlet up to 0.2.10. The impacted element is the function web_fetch of the file tools/tool_web_fetch.go of…
Mitigation only
HIGH 7.4
CVE-2026-62240
CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and bloc…
Crewai
1.15.1+
HIGH 8.6
CVE-2026-62242
Spring Boot Admin Server before 4.1.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers to register instance…
Patch available
HIGH 8.5
CVE-2026-62197
OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebSocket URLs. Attackers with lower-tr…
Openclaw
2026.6.6+
HIGH 7.4
CVE-2026-49969
Laravel-Mediable before 7.0.0 contains a server-side request forgery vulnerability that allows remote attackers to issue arbitrary HTTP requests from…
Patch available
HIGH 7.3
CVE-2025-45869
LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server-Side Request Forgery (SSRF). An unauthenticated attacker can exploit th…
Mitigation only
MEDIUM 6.4
CVE-2026-57413
Server-Side Request Forgery (SSRF) vulnerability in bdthemes Instant Image Generator ai-image allows Server Side Request Forgery.This issue affects I…
Mitigation only
HIGH 7.2
CVE-2026-57407
Server-Side Request Forgery (SSRF) vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp allows Server Side Request Forgery.Thi…
Mitigation only
HIGH 7.2
CVE-2026-57372
Server-Side Request Forgery (SSRF) vulnerability in denishua WPJAM Basic wpjam-basic allows Server Side Request Forgery.This issue affects WPJAM Basi…
No fix yet
MEDIUM 6.5
CVE-2026-49876
Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job temp…
Gravitino
1.3.0+