Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.6
CVE-2026-14869
The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an…
No fix yet
HIGH 7.7
CVE-2026-59931
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through …
No fix yet
HIGH 7.2
CVE-2026-54605
OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parse…
No fix yet
HIGH 8.2
CVE-2026-43910
Appium Java Client is the Java language binding for writing Appium tests that conform to the W3C WebDriver protocol. From 8.2.1 until 10.1.1, when di…
Java Client
10.1.1+
MEDIUM 5.1
CVE-2026-67173
Pivotick did not validate the URL scheme of node imagePath values derived from graph data before assigning them to SVG image resources. An attacker a…
No fix yet
HIGH 7.2
CVE-2026-65442
Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
No fix yet
HIGH 7.2
CVE-2026-61953
Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
No fix yet
MEDIUM 6.5
CVE-2026-65618
Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifacto…
Artifactory
7.133.6+
MEDIUM 6.8
CVE-2026-65923
A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause …
Artifactory
7.111.18 / 7.117.25+
MEDIUM 6.5
CVE-2026-65924
JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user …
Artifactory
7.111.18 / 7.117.25+
MEDIUM 6.5
CVE-2026-65925
A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.
Artifactory
7.111.18 / 7.117.25+
MEDIUM 6.5
CVE-2026-64649
Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server A…
Next.js
15.5.21 / 16.2.11+
HIGH 8.4
CVE-2026-16481
A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch-page tool of googleapis/mcp-…
No fix yet
MEDIUM 6.1
CVE-2026-64645
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a
rewrites() o…
Next.js
15.5.21 / 16.2.11+
MEDIUM 6.9
CVE-2026-54272
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF thr…
No fix yet
CRITICAL 9.1
CVE-2026-17552
Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call.
When the rewr…
No fix yet
HIGH 8.5
CVE-2026-17192
A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to intern…
No fix yet
MEDIUM 5.4
CVE-2026-65558
Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.
No fix yet
HIGH 7.2
CVE-2026-59552
Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions.
No fix yet
MEDIUM 5.5
CVE-2026-17534
Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal denylist in assertSafeFetchTa…
No fix yet
HIGH 8.6
CVE-2025-15662
The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it se…
No fix yet
MEDIUM 6.3
CVE-2026-17458
A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.t…
No fix yet
CRITICAL 10.0
CVE-2026-57106
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
Purview Data Governance
No fix yet
MEDIUM 5.5
CVE-2026-16910
A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers accept user-supplied URLs withou…
No fix yet
HIGH 8.8
CVE-2026-16870
Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltrati…
No fix yet
HIGH 8.8
CVE-2026-56167
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
Azure Ai Search
No fix yet
HIGH 7.7
CVE-2026-63313
9Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The endpoint accepts a user-controll…
No fix yet
HIGH 7.2
CVE-2026-21653
Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery.
This issue affects CCure …
No fix yet
HIGH 7.2
CVE-2026-65516
Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.
No fix yet
CRITICAL 9.8
CVE-2026-64873
Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services.
No fix yet