Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.3
CVE-2026-74842
A vulnerability was found in Kira-Pgr PromptShopMCP up to 5bc0cd17358e19a5415d11a531088170d7b81452. Affected is the function download_image of the fi…
Fix unknown
MEDIUM 5.9
CVE-2026-13700
The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side request and attaches stored third-part…
Fix unknown
MEDIUM 6.3
CVE-2026-19984
A flaw has been found in jkawamoto mcp-florence2 up to 0.3.13. Affected by this issue is the function get_images of the file src/mcp_florence2/__init…
Fix unknown
MEDIUM 6.3
CVE-2026-19957
A vulnerability was identified in graphlit graphlit-mcp-server 1.0.1. This affects the function fetch of the file src/tools.ts of the component ssrf-…
No fix yet
MEDIUM 6.3
CVE-2026-19956
A vulnerability has been found in gomarble-ai facebook-ads-mcp-server 0.1.0. The impacted element is the function fetch_pagination_url of the file se…
No fix yet
MEDIUM 5.8
CVE-2026-73058
stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blocklist, allowing unauthenticated attackers to bypass …
No fix yet
HIGH 8.8
CVE-2026-17123
The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form …
No fix yet
MEDIUM 6.3
CVE-2026-19927
A vulnerability was found in OpenBoxes up to 0.9.7. The impacted element is the function Upload of the file grails-app/controllers/org/pih/warehouse/…
No fix yet
MEDIUM 5.3
CVE-2026-73845
CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in s…
No fix yet
MEDIUM 6.7
CVE-2026-46380
compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSFetcher._do_fetch() method pas…
No fix yet
MEDIUM 5.3
CVE-2026-19770
A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is the function downloadReport of the file src/smadex-…
No fix yet
MEDIUM 6.3
CVE-2026-19765
A security flaw has been discovered in eyaushev swagger-testcase-mcp 5babb27c951fb404bc2b25ec80593616e49054e5. This vulnerability affects the functio…
No fix yet
HIGH 7.3
CVE-2026-19753
A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of the file src/mcp-rdf-explorer/…
No fix yet
HIGH 8.5
CVE-2026-72855
Budibase before 3.40.0 contains server-side request forgery vulnerabilities in OpenAPI query import and REST query execution that allow authenticated…
No fix yet
MEDIUM 6.3
CVE-2026-19751
A flaw has been found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82. The affected element is the function axios.g…
No fix yet
MEDIUM 6.3
CVE-2026-19752
A vulnerability was found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82. This affects the function parse-pdf of t…
No fix yet
HIGH 7.7
CVE-2026-73530
Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that allows attackers to reach internal services by suppl…
No fix yet
HIGH 8.6
CVE-2026-72777
Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation th…
No fix yet
HIGH 7.5
CVE-2026-59765
SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
No fix yet
MEDIUM 6.3
CVE-2026-58441
SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
No fix yet
MEDIUM 6.5
CVE-2026-58442
Repository migration SSRF via multi-answer DNS allow-list bypass
No fix yet
HIGH 7.7
CVE-2026-58314
Two SSRF findings in Gitea 1.26.2
No fix yet
HIGH 8.5
CVE-2026-57894
Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
No fix yet
HIGH 7.4
CVE-2026-49857
auth-fetch-mcp is an MCP server that lets AI assistants fetch content from authenticated web pages. Version 3.0.1 implements SSRF protection in `asse…
No fix yet
HIGH 7.2
CVE-2026-66704
Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions.
No fix yet
MEDIUM 6.0
CVE-2026-66654
Subscriber Server Side Request Forgery (SSRF) in Vehica Core <= 1.0.104 versions.
No fix yet
HIGH 8.7
CVE-2026-49478
Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly foll…
No fix yet
HIGH 8.5
CVE-2026-73629
Serendipity before 2.6.0 contains a server-side request forgery vulnerability in the serendipity_url_allowed() filter that fails to block hex-encoded…
No fix yet
HIGH 8.7
CVE-2026-46382
The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, a user-supplied private/local U…
No fix yet
HIGH 8.1
CVE-2026-18952
Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user …
No fix yet