Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.9
CVE-2026-73297
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, _is_blocked_ip in ufo/utils/url_security…
No fix yet
HIGH 8.8
CVE-2026-65941
In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitra…
No fix yet
MEDIUM 5.1
CVE-2026-73432
Vulnerability-Lookup contains a server-side request forgery (SSRF) vulnerability in the remote-instance synchronization functionality. Remote instanc…
No fix yet
HIGH 7.6
CVE-2026-73264
Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration access could supply an unvalidate…
No fix yet
MEDIUM 6.4
CVE-2026-19050
The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the capability or nonce of the requ…
No fix yet
HIGH 7.1
CVE-2026-16294
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode URL settings before performi…
No fix yet
HIGH 8.6
CVE-2026-73247
Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/functions/Ht…
No fix yet
MEDIUM 5.4
CVE-2026-48762
TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI "Create Transcription" action handler fetches a user-supplied audio URL using …
No fix yet
MEDIUM 5.8
CVE-2026-73243
kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated GET /addTask endpoint in kkFileView i…
No fix yet
MEDIUM 5.8
CVE-2026-73212
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.1, good_peer_addr() in src/server/ns_turn_server.c uses ioa_addr_i…
No fix yet
MEDIUM 5.3
CVE-2026-73082
Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the POST /api/v1/projects/:projectId/mcp-server/validate-agent-mcp-t…
No fix yet
HIGH 8.8
CVE-2026-70324
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Sharepoint Server
16.0.19725.20522+
HIGH 8.8
CVE-2026-70326
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Sharepoint Server
16.0.19725.20522+
CRITICAL 9.1
CVE-2026-69223
Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF).
This issue affects Apache Allura: before 1.19.1.
Users are recommend…
Allura
No fix yet
HIGH 8.8
CVE-2026-65813
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Exchange Server
No fix yet
MEDIUM 6.5
CVE-2026-62902
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
Visual Studio 2022
8.0.30 / 9.0.19+
MEDIUM 6.5
CVE-2026-58639
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Sharepoint Server
16.0.19725.20522+
HIGH 7.5
CVE-2026-58612
Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.
Powershell
No fix yet
MEDIUM 5.4
CVE-2026-48483
TypeBot is a chatbot builder tool. Prior to version 3.17.0, Typebot's WhatsApp status forwarding feature stores a workspace-configured webhook forwar…
No fix yet
CRITICAL 9.3
CVE-2026-73080
SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a caller-supp…
No fix yet
MEDIUM 5.1
CVE-2026-73210
A Server-Side Request Forgery (SSRF) vulnerability existed in Lookyloo's PlaywrightCapture when the only_global_lookup option was enabled.
Playwrigh…
No fix yet
HIGH 8.5
CVE-2026-51583
An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF) via the Webhook validation …
No fix yet
MEDIUM 5.4
CVE-2026-72784
Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulnerability in the GraphQL save<…
No fix yet
MEDIUM 6.4
CVE-2026-72768
n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node that allows authenticated use…
No fix yet
HIGH 7.5
CVE-2026-72606
A server-side request forgery vulnerability in Pinry through 2.1.13 allows unauthenticated remote attackers to make the server issue HTTP requests to…
No fix yet
MEDIUM 6.5
CVE-2026-72597
A server-side request forgery vulnerability in Friendica through the 2026.08-dev branch allows authenticated users with a free self-registered accoun…
No fix yet
MEDIUM 6.5
CVE-2026-72598
A server-side request forgery vulnerability in Apioo Fusio 8.8.3 allows authenticated consumer-role users to make the server issue HTTP requests to i…
No fix yet
MEDIUM 6.5
CVE-2026-72560
A server-side request forgery vulnerability in HumanSignal Label Studio through 1.24.0.dev0 exists because SSRF_PROTECTION_ENABLED is set to false by…
No fix yet
HIGH 7.5
CVE-2026-72552
A server-side request forgery vulnerability in Dub as of 2026-07-10 allows unauthenticated remote attackers to make the server issue HTTP requests to…
No fix yet
HIGH 8.8
CVE-2026-13739
A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrar…
No fix yet