Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2026-55994
Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…
Camel
4.18.3 / 4.21.0+
HIGH 7.5
CVE-2026-55993
Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…
Camel
4.14.8 / 4.18.3+
HIGH 7.5
CVE-2026-46726
Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…
Camel
4.14.8 / 4.18.3+
CRITICAL 9.1
CVE-2026-48203
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Validation, Server-Side Request Fo…
Camel
4.14.8 / 4.18.3+
CRITICAL 9.1
CVE-2026-48205
Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component.
The camel-dns producers read DNS operatio…
Camel
4.14.8 / 4.18.3+
MEDIUM 6.3
CVE-2026-14748
A flaw has been found in AIAnytime Awesome-MCP-Server up to a884bb51bcd99e08e14fd712c749d55d9d9a13ab. Affected by this issue is some unknown function…
Mitigation only
MEDIUM 6.5
CVE-2026-58418
SSRF via HTTP Redirect in Repository Migration
Patch available
HIGH 7.4
CVE-2026-57993
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Edge Chromium
150.0.4078.48+
MEDIUM 5.4
CVE-2026-58278
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Edge Chromium
150.0.4078.48+
MEDIUM 6.5
CVE-2026-57987
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Edge Chromium
150.0.4078.48+
CRITICAL 9.6
CVE-2026-22874
Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.
Patch available
HIGH 8.5
CVE-2026-10055
In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the …
Mitigation only
MEDIUM 5.5
CVE-2026-11397
The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and including 3.9.30 via the wpie_i…
No fix yet
HIGH 8.8
CVE-2026-45499
Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
Azure Openai
Mitigation only
HIGH 8.8
CVE-2026-57100
Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a ne…
Entra Provisioning Service
Mitigation only
MEDIUM 5.8
CVE-2026-59101
AutoBangumi before 3.2.8 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated remote attackers to probe internal n…
Patch available
HIGH 7.7
CVE-2026-59095
LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attackers to direct internal HTTP req…
Patch available
HIGH 7.5
CVE-2026-55113
A malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF) vulnerability found in UniFi Talk Application to exec…
Unifi Talk Application
5.2.2+
CRITICAL 9.9
CVE-2026-55115
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to es…
Unifi Protect
7.1.83+
HIGH 8.8
CVE-2026-54401
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such…
Unifi Os Server
after 5.1.15
MEDIUM 6.4
CVE-2026-57681
Subscriber Server Side Request Forgery (SSRF) in GeoDirectory <= 2.8.161 versions.
Mitigation only
HIGH 7.2
CVE-2026-57348
Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions.
Mitigation only
MEDIUM 5.1
CVE-2026-54430
liboauth2 is vulnerable to Server-Side Request Forgery in oauth2_jose_jwks_aws_alb_resolve() function. The AWS ALB verifier reads both signer and kid…
Patch available
HIGH 8.2
CVE-2026-14336
PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith(' https://ci.eclipse.org ') in is_issuer_known, pia…
Mitigation only
MEDIUM 6.9
CVE-2026-55791
Craft CMS is a content management system (CMS). Versions 4.0.0-RC1 and above, prior to 4.18.0 and 5.0.0-RC1, and above, prior to 5.10.0, are vulnerab…
Patch available
HIGH 7.8
CVE-2026-24242
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause server-side request forgery. A successful exploit of this vul…
Nemo Megatron Bridge
0.4.1+
CRITICAL 9.0
CVE-2026-13603
The payment integration pretix-oppwa provides support
for the payment providers VR Payment, Hobex, and potentially others
based on Oppwa's technolo…
Mitigation only
MEDIUM 5.0
CVE-2026-56399
Open WebUI before 0.6.27 contains a server-side request forgery vulnerability in the /api/v1/retrieval/process/web endpoint that allows authenticated…
Patch available
CRITICAL 10.0
CVE-2026-13773
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.…
Websphere Extreme Scale
after 8.6.1.6
CRITICAL 9.8
CVE-2026-11714
IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.
Websphere Application Server
26.0.0.8+