| CVE-2026-16870 |
2026-07-24 |
Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file downl… |
| CVE-2026-56167 |
2026-07-23 |
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-63313 |
2026-07-23 |
9Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The endpoint accepts a user-controlled url parameter and passes it to a configured exte… |
| CVE-2026-48013 |
2026-07-23 |
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint allows authenticated admin users to make server-side HTTP HEAD requests to arbit… |
| CVE-2026-65516 |
2026-07-23 |
Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions. |
| CVE-2026-65496 |
2026-07-23 |
Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions. |
| CVE-2026-65467 |
2026-07-23 |
Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions. |
| CVE-2026-65466 |
2026-07-23 |
Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions. |
| CVE-2026-24639 |
2026-07-23 |
Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions. |
| CVE-2026-64873 |
2026-07-23 |
Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services. |
| CVE-2026-64799 |
2026-07-23 |
Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network servic… |
| CVE-2026-13192 |
2026-07-22 |
In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature may allow an authenticated attacker to trigger server-side requ… |
| CVE-2026-65593 |
2026-07-22 |
n8n versions before 1.123.64 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute UR… |
| CVE-2026-65318 |
2026-07-21 |
Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET request… |
| CVE-2026-65317 |
2026-07-21 |
Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server i… |
| CVE-2026-65057 |
2026-07-21 |
Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supplying attacker-controlled host… |
| CVE-2026-65056 |
2026-07-21 |
mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to t… |
| CVE-2026-63764 |
2026-07-21 |
LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private-I… |
| CVE-2026-47695 |
2026-07-21 |
CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to version 1.119.0, CC-Tweaked's HTTP API (`http.request`, `http.websocket`) blocks requests … |
| CVE-2026-46556 |
2026-07-21 |
FlaskBB is a Forum Software written in Python using the micro framework Flask. Prior to version 2.2.1, a Server-Side Request Forgery (SSRF) vulnerability in get_image_info() allows any authenticated u… |