Total
3036 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-59552 | 2 Shahadat Hossain, Wordpress | 2 3d Flipbook Pdf Viewer & Embedder, Wordpress | 2026-07-27 | 7.2 High |
| Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions. | ||||
| CVE-2026-65558 | 2 Wordpress, Wpcenter | 2 Wordpress, Affiliatex | 2026-07-27 | 5.4 Medium |
| Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions. | ||||
| CVE-2026-66437 | 2 Themeisle, Wordpress | 2 Feedzy, Wordpress | 2026-07-27 | 4.9 Medium |
| Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions. | ||||
| CVE-2026-17192 | 1 Arista Networks | 1 Velocloud Orchestrator On-prem | 2026-07-27 | 8.5 High |
| A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to internal services that are not otherwise accessible. This vulnerability requires a minimum role of Enterprise Standard Admin. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks. | ||||
| CVE-2026-13192 | 1 Progress | 1 Telerik Ui For Asp.net Ajax | 2026-07-27 | 6.5 Medium |
| In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature may allow an authenticated attacker to trigger server-side requests to arbitrary hosts, resulting in outbound network connections and potential exposure of Windows authentication credentials. | ||||
| CVE-2026-64799 | 1 Regularlabs.com | 2 Articles Anywhere Pro Extension For Joomla, Users Anywhere Pro Extension For Joomla | 2026-07-27 | 7.5 High |
| Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they were images. This could result in SSRF, internal-data access or writing attacker-controlled files into a web-accessible folder. | ||||
| CVE-2026-48978 | 1 Oras-project | 1 Oras-go | 2026-07-27 | 3.1 Low |
| oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's WWW-Authenticate: Bearer challenge without validating the scheme or host, allowing a malicious or compromised registry to cause SSRF to internal networks such as http://169.254.169.254/, http://10.0.0.x/, and http://127.0.0.1/, or to downgrade a registry contacted over https:// to an http:// token endpoint in registry/remote/auth/client.go through Client.Do(), Client.fetchBearerToken(), fetchDistributionToken, and fetchOAuth2Token. This issue is fixed in version 2.6.1. | ||||
| CVE-2026-50151 | 1 Oras-project | 1 Oras-go | 2026-07-27 | 7.5 High |
| oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST request for the subsequent PUT request, allowing a malicious registry to return a cross-host Location and receive the caller's credentials at an attacker-controlled endpoint. This issue is fixed in version 2.6.1. | ||||
| CVE-2026-58478 | 1 Dan-in-ca | 1 Sip | 2026-07-27 | 6.5 Medium |
| Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to make the device issue arbitrary HTTP requests by supplying a malicious callback URL when the optional Node-RED plugin is installed. Attackers can exploit the lack of destination validation and the default passphrase 'opendoor' to send blind HTTP requests to arbitrary internal or external hosts not otherwise directly accessible. | ||||
| CVE-2026-48736 | 1 Symfony | 3 Http-client, Http-foundation, Symfony | 2026-07-27 | N/A |
| Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, NoPrivateNetworkHttpClient and IpUtils::PRIVATE_SUBNETS omitted IPv6 transition prefixes such as 6to4, NAT64, Teredo, and IPv4-compatible IPv6, allowing attacker-supplied URLs to represent private IPv4 targets in forms that IpUtils::isPrivateIp() did not block. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13. | ||||
| CVE-2026-17458 | 1 Mf-yang | 1 Openclaw-cn | 2026-07-27 | 6.3 Medium |
| A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.ts of the component Browser Control HTTP API. Performing a manipulation results in server-side request forgery. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-21653 | 1 Johnsoncontrols | 1 Ccure 9000 And Victor Application Server | 2026-07-27 | N/A |
| Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery. This issue affects CCure 9000 and victor application server: from 2.9 through 3.0. | ||||
| CVE-2026-16870 | 1 Snowflake | 1 Libsnowflakeclient | 2026-07-27 | 8.8 High |
| Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a victim host. An attacker could exploit this by uploading a file with a crafted encryption metadata field to a shared internal stage that a victim process later downloads, and impact would be limited to deployments where principals with different privilege levels share the same internal stage. A related out-of-bounds write in the same download path could allow memory corruption with attacker-controlled write primitives. An attacker may exploit this through a crafted initialization vector metadata field on a shared stage, and impact would be limited by the same stage-write precondition. Improper validation of connection parameters could allow an attacker-controlled input to redirect outbound authentication requests — including credentials and tokens — to an attacker-controlled endpoint. Impact is limited to embedding deployments where a lower-privileged principal can influence connection configuration while higher-privileged service credentials are in use. The fix is available in Snowflake libsnowflakeclient version 2.9.2. The Snowflake PHP PDO Driver and Snowflake ODBC Driver embed the affected library; fixes are available in versions 4.1.0 and 3.19.0 respectively. Users must manually upgrade. | ||||
| CVE-2026-17534 | 1 Moonshotai | 1 Kimi Code | 2026-07-27 | 5.5 Medium |
| Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal denylist in assertSafeFetchTarget, without resolving DNS or re-validating hosts after HTTP redirects. An attacker who can influence a FetchURL call (for example via prompt injection) can supply a crafted public hostname that resolves to loopback or another internal address, or a public URL that redirects to such a target, and thereby reach internal network services that the denylist was intended to block. FetchURL is included in the default auto-approve tool set, so the call does not require interactive user confirmation in manual mode. | ||||
| CVE-2026-10517 | 1 Redhat | 1 Quay | 2026-07-27 | 5.8 Medium |
| Retracted following review by Red Hat Product Security and confirmation from the upstream Clair/Claircore maintainer. This CVE misattributes the described behavior to github.com/quay/claircore: the authentication mechanism in question (optional PSK, HTTP endpoint /indexer/api/v1/index_report) is implemented entirely in github.com/quay/clair; no PSK-related code exists anywhere in claircore's codebase or git history. The unauthenticated indexer API is Clair's documented, intentional design, authentication is an opt-in deployment choice, not a code defect. No fix commit was found in claircore between the version recorded as the affected boundary (1.5.52) and the following release (1.5.53); intervening commits are unrelated dependency and feature changes, so the "fixed in 1.5.52" status is inaccurate. | ||||
| CVE-2026-57211 | 1 Rabbitmq | 1 Rabbitmq-server | 2026-07-26 | 6.5 Medium |
| RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple management extension plugins are enabled, causing outbound DNS and SMB requests to attacker-controlled UNC paths. This issue is fixed in versions 4.1.11 and 4.2.6. | ||||
| CVE-2026-55113 | 2026-07-25 | 7.5 High | ||
| A malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF) vulnerability found in UniFi Talk Application to execute a Denial of Service (DoS) attack and bypass authentication in certain UniFi Talk API endpoints. | ||||
| CVE-2026-65593 | 1 N8n | 1 N8n | 2026-07-24 | N/A |
| n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute URLs in routing configuration to override baseURL restrictions and make the n8n server issue HTTP requests to arbitrary internal targets when SSRF protection is disabled. | ||||
| CVE-2026-64873 | 1 Regularlabs.com | 1 Cache Cleaner Pro Extension For Joomla | 2026-07-24 | 9.8 Critical |
| Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services. | ||||
| CVE-2026-57106 | 1 Microsoft | 1 Office Purview Data Governance | 2026-07-24 | 10 Critical |
| Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. | ||||