121 CVEs — updated 2026-09-18 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-92808 | A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An un | CRITICAL | 10.0 | 25%ile | NVD | 2026-09-16 |
| CVE-2026-54734 | Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-suppl | CRITICAL | 10.0 | 30%ile | NVD | 2026-09-17 |
| CVE-2026-68536 | Server-Side Request Forgery / Local File Inclusion in Apache MyFace Core. Older unsupported versions may also be affect | CRITICAL | 9.8 | 40%ile | NVD | 2026-09-16 |
| CVE-2025-56563 | A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0. The script accepts | CRITICAL | 9.8 | 34%ile | NVD | 2026-09-16 |
| CVE-2026-12944 | IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) | CRITICAL | 9.6 | 16%ile | NVD | 2026-09-14 |
| CVE-2026-61559 | `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1 | CRITICAL | 9.6 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-67101 | HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functional | CRITICAL | 9.3 | 19%ile | NVD | 2026-09-18 |
| CVE-2026-92576 | HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the | CRITICAL | 9.2 | 34%ile | NVD | 2026-09-16 |
| CVE-2026-88592 | kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF). The cross-origin file proxy endpoint /getCorsFi | CRITICAL | 9.1 | 8%ile | NVD | 2026-09-16 |
| CVE-2026-77866 | Server-Side Request Forgery (SSRF) vulnerability in Slab safeurl allows an attacker who controls a validated URL to reac | CRITICAL | 9.0 | 39%ile | NVD | 2026-09-15 |
| CVE-2026-92566 | DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that a | HIGH | 8.8 | 41%ile | NVD | 2026-09-16 |
| CVE-2026-91935 | Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect | HIGH | 8.7 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-58201 | Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services. Prior to 2.1.2 | HIGH | 8.7 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-92719 | Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, allowing at | HIGH | 8.7 | 36%ile | NVD | 2026-09-16 |
| CVE-2026-92815 | changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attac | HIGH | 8.7 | 35%ile | NVD | 2026-09-16 |
| CVE-2026-54628 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes URL-capable SQLite virtu | HIGH | 8.6 | 28%ile | NVD | 2026-09-14 |
| CVE-2026-73247 | Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata | HIGH | 8.6 | 31%ile | GitHub | 2026-09-17 |
| CVE-2026-57126 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _host_is_block | HIGH | 8.5 | 32%ile | NVD | 2026-09-14 |
| CVE-2026-59973 | FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). From mcp-from-openapi 2.3.0 until 2.5.0 a | HIGH | 8.5 | 32%ile | NVD | 2026-09-15 |
| CVE-2026-76680 | Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low privi | HIGH | 8.5 | 21%ile | NVD | 2026-09-15 |
| CVE-2026-54507 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5 | HIGH | 8.4 | 25%ile | NVD | 2026-09-17 |
| CVE-2026-90769 | Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated us | HIGH | 8.3 | 18%ile | NVD | 2026-09-13 |
| CVE-2026-91923 | KubeSphere through 4.1.3 contains a server-side request forgery vulnerability in the git credential verification endpoin | HIGH | 8.3 | 19%ile | NVD | 2026-09-15 |
| CVE-2026-91943 | Crawl4AI before 0.9.3 contains a server-side request forgery vulnerability in PDFContentScrapingStrategy where _get_pdf_ | HIGH | 8.3 | 24%ile | NVD | 2026-09-15 |
| CVE-2026-63443 | Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10 | HIGH | 8.3 | 36%ile | NVD | 2026-09-15 |
| CVE-2026-54549 | Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, th | HIGH | 8.3 | 14%ile | NVD | 2026-09-15 |
| CVE-2025-69299 | WordPress Oxygen theme <= 6.0.8 - Server Side Request Forgery (SSRF) vulnerability | HIGH | 8.3 | 9%ile | Microsoft | 2026-02-10 |
| CVE-2026-79425 | An authenticated Server-Side Request Forgery (SSRF) in the /adminapi/file/online_upload component of CRMEB v6.0.0 allows | HIGH | 8.1 | 26%ile | NVD | 2026-09-15 |
| CVE-2026-55864 | GeoNetwork is a catalog application to manage spatially referenced resources. Prior to 4.2.17 and 4.4.12, POST /api/tool | HIGH | 7.8 | 47%ile | NVD | 2026-09-15 |
| CVE-2026-53957 | Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to @contentful/mcp-ser | HIGH | 7.7 | 17%ile | NVD | 2026-09-15 |
| CVE-2026-76820 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260701.0 | HIGH | 7.7 | 23%ile | NVD | 2026-09-15 |
| CVE-2026-54339 | Glean is a self-hosted RSS reader and personal knowledge management tool. Prior to 0.2.6, POST /api/feeds/discover passe | HIGH | 7.7 | 27%ile | NVD | 2026-09-17 |
| CVE-2026-91938 | Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer | HIGH | 7.6 | 28%ile | NVD | 2026-09-15 |
| CVE-2026-76425 | A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks | HIGH | 7.6 | 22%ile | NVD | 2026-09-16 |
| CVE-2026-85917 | Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a netw | HIGH | 7.5 | 45%ile | NVD | 2026-09-17 |
| GHSA-39wr-7q6h-cf68 | LMDeploy has an SSRF bypass | HIGH | 7.5 | — | GitHub | 2026-09-18 |
| CVE-2026-81446 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerab | HIGH | 7.4 | 30%ile | NVD | 2026-09-17 |
| CVE-2026-54544 | Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.16, two API endpoints that trigger outbou | HIGH | 7.2 | 25%ile | NVD | 2026-09-15 |
| CVE-2026-54166 | Shelf is a platform for tracking physical assets. Prior to version 1.20.3, authenticated users with the `asset:import` p | HIGH | 7.1 | 17%ile | NVD | 2026-09-11 |
| CVE-2026-91750 | WeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url en | HIGH | 7.1 | 19%ile | NVD | 2026-09-15 |
| CVE-2026-54077 | ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/java/com/arcadedb/quer | HIGH | 7.1 | 31%ile | NVD | 2026-09-15 |
| CVE-2026-58485 | mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through | HIGH | 7.1 | 3%ile | NVD | 2026-09-15 |
| CVE-2026-92602 | TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigContro | HIGH | 7.1 | 23%ile | NVD | 2026-09-16 |
| CVE-2026-92775 | Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches | HIGH | 7.1 | 23%ile | NVD | 2026-09-16 |
| CVE-2026-92789 | Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after | HIGH | 7.1 | 23%ile | NVD | 2026-09-16 |
| CVE-2026-92795 | Coze Studio through 0.5.1 fails to restrict the server URL supplied when registering plugin tools, allowing authenticate | HIGH | 7.1 | 15%ile | NVD | 2026-09-16 |
| CVE-2026-92804 | Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token | HIGH | 7.1 | 20%ile | NVD | 2026-09-16 |
| CVE-2026-86862 | pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbn | HIGH | 7.1 | 10%ile | NVD | 2026-09-17 |
| CVE-2026-71198 | In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to | HIGH | 7.0 | 38%ile | NVD | 2026-09-14 |
| CVE-2026-71196 | OSSA-2026-038: Multiple SSRF vulnerabilities in Glance web-download and HTTP image APIs | HIGH | 7.0 | — | OpenStack | 2026-09-03 |
| CVE-2026-91081 | Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous | MEDIUM | 6.9 | 16%ile | NVD | 2026-09-14 |
| CVE-2026-91966 | AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability | MEDIUM | 6.9 | 32%ile | NVD | 2026-09-15 |
| CVE-2026-92215 | A vulnerability has been found in a2ui-project a2ui up to 0.10.7. Affected by this vulnerability is the function httpx.g | MEDIUM | 6.9 | 32%ile | NVD | 2026-09-16 |
| CVE-2026-92813 | Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing una | MEDIUM | 6.9 | 22%ile | NVD | 2026-09-16 |
| CVE-2026-61793 | Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthen | MEDIUM | 6.9 | 39%ile | NVD | 2026-09-17 |
| CVE-2026-53708 | ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for M | MEDIUM | 6.6 | 15%ile | NVD | 2026-09-14 |
| CVE-2026-57115 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, SpiderTools.scrape_page validates only the ini | MEDIUM | 6.5 | 18%ile | NVD | 2026-09-14 |
| CVE-2026-73497 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). From 0.17.0 until 0 | MEDIUM | 6.5 | 14%ile | NVD | 2026-09-14 |
| CVE-2026-12765 | IBM Langflow OSS 1.0.0 through 1.10.2 is vulnerable to server-side request forgery (SSRF). This may allow an unauthentic | MEDIUM | 6.5 | 12%ile | NVD | 2026-09-14 |
| CVE-2026-12767 | IBM Langflow OSS 1.0.0 through 1.11.5 is vulnerable to server-side request forgery (SSRF). This may allow an unauthentic | MEDIUM | 6.5 | 12%ile | NVD | 2026-09-14 |
| CVE-2026-54688 | mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through | MEDIUM | 6.5 | 30%ile | NVD | 2026-09-15 |
| CVE-2026-92139 | Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, includin | MEDIUM | 6.5 | 22%ile | NVD | 2026-09-16 |
| CVE-2026-87116 | Tanium addressed a server-side request forgery vulnerability in Threat Response. | MEDIUM | 6.5 | 16%ile | NVD | 2026-09-16 |
| CVE-2026-62282 | OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, OpenCVE notification testing for Webhook and Slack int | MEDIUM | 6.5 | — | NVD | 2026-09-18 |
| CVE-2026-57211 | RabbitMQ: UNC SSRF affecting the management UI on Windows | MEDIUM | 6.5 | 49%ile | Microsoft | 2026-07-14 |
| CVE-2026-48858 | ftp client PASV response IP not validated against control peer, enabling SSRF and FTP bounce attacks | MEDIUM | 6.5 | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-66608 | Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= | MEDIUM | 6.4 | 6%ile | NVD | 2026-09-17 |
| CVE-2026-81443 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerab | MEDIUM | 6.4 | 14%ile | NVD | 2026-09-17 |
| CVE-2026-12106 | The Auto Upload Images plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, | MEDIUM | 6.4 | 16%ile | NVD | 2026-09-18 |
| CVE-2026-13318 | Virt-api-rhel9: kubevirt: kubevirt: ssrf in virt-api port-forward via unvalidated guest-agent-reported ip | MEDIUM | 6.4 | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-54452 | safeurl is a server-side request forgery protection library. Prior to 0.2.4, the privateNetworks list in ip.go omits the | MEDIUM | 6.3 | 33%ile | NVD | 2026-09-14 |
| CVE-2026-91079 | Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing h | MEDIUM | 6.3 | 29%ile | NVD | 2026-09-14 |
| CVE-2026-54689 | mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through | MEDIUM | 6.3 | 3%ile | NVD | 2026-09-15 |
| CVE-2026-55073 | WeasyPrint helps web developers to create PDF documents. Prior to 70.0, server-side applications that configure a restri | MEDIUM | 6.2 | 9%ile | NVD | 2026-09-14 |
| CVE-2026-77164 | Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote insta | MEDIUM | 6.2 | 3%ile | NVD | 2026-09-18 |
| CVE-2026-55591 | Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.28.0, makeRemoteRequest() in sr | MEDIUM | 5.8 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-90984 | The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetch | MEDIUM | 5.8 | 3%ile | NVD | 2026-09-18 |
| CVE-2026-86144 | In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This ha | MEDIUM | 5.6 | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-90710 | A vulnerability was determined in taisan tarzan-cms 1.0.0. This issue affects the function openConnection of the file co | MEDIUM | 5.5 | 40%ile | NVD | 2026-09-14 |
| CVE-2026-54637 | Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4-rc.3, the schedule | MEDIUM | 5.5 | 41%ile | NVD | 2026-09-15 |
| CVE-2026-92380 | A flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is the function ckditor::saveRemote of the file core | MEDIUM | 5.5 | 40%ile | NVD | 2026-09-16 |
| CVE-2026-15887 | IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requ | MEDIUM | 5.4 | 8%ile | NVD | 2026-09-14 |
| CVE-2026-12766 | IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticat | MEDIUM | 5.4 | 8%ile | NVD | 2026-09-14 |
| CVE-2026-70367 | Stunnel: ssrf bypass in stunnel socks proxy via ipv4-mapped ipv6 loopback and unspecified addresses allows access to loo | MEDIUM | 5.4 | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-49865 | Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain a server-side request forgery vulner | MEDIUM | 5.3 | 26%ile | NVD | 2026-09-11 |
| CVE-2026-90446 | An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path o | MEDIUM | 5.3 | 11%ile | NVD | 2026-09-11 |
| CVE-2026-90486 | A vulnerability has been found in openstatusHQ openstatus up to f04c827112f30a11d571ebdad3892826034d6265. Affected by th | MEDIUM | 5.3 | 15%ile | NVD | 2026-09-12 |
| CVE-2026-90790 | A security vulnerability has been detected in a2aproject a2a-python up to 1.1.3. This affects the function _dispatch_not | MEDIUM | 5.3 | 12%ile | NVD | 2026-09-14 |
| CVE-2026-91199 | Refly through 1.1.0 contains a server-side request forgery vulnerability in the POST /v1/misc/scrape endpoint that fetch | MEDIUM | 5.3 | 10%ile | NVD | 2026-09-14 |
| CVE-2026-44202 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListene | MEDIUM | 5.3 | 25%ile | NVD | 2026-09-15 |
| CVE-2026-91967 | AVideo through 29.0 contains a blind server-side request forgery vulnerability in the getHeaderContentTypeFromURL functi | MEDIUM | 5.3 | 26%ile | NVD | 2026-09-15 |
| CVE-2026-92184 | A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. Affected is the function urllib.request.urlopen of th | MEDIUM | 5.3 | 20%ile | NVD | 2026-09-16 |
| CVE-2026-92568 | MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows | MEDIUM | 5.3 | 22%ile | NVD | 2026-09-16 |
| CVE-2026-92569 | Hippo4j through 1.5.0 contains a server-side request forgery vulnerability in four ThreadPoolController endpoints that f | MEDIUM | 5.3 | 20%ile | NVD | 2026-09-16 |
| CVE-2026-59823 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.9, an authenticated | MEDIUM | 5.3 | 38%ile | NVD | 2026-09-16 |
| CVE-2026-54918 | NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. In the a | MEDIUM | 5.3 | 23%ile | NVD | 2026-09-17 |
| CVE-2026-93597 | ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and | MEDIUM | 5.3 | — | NVD | 2026-09-18 |
| CVE-2026-93506 | A vulnerability was determined in SveltyCMS 0.0.6. This issue affects some unknown processing of the file /mediagallery/ | MEDIUM | 5.3 | — | NVD | 2026-09-18 |
| CVE-2026-92932 | In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in | MEDIUM | 5.1 | 14%ile | NVD | 2026-09-17 |
| CVE-2026-54546 | CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to 13.22. | MEDIUM | 5.0 | 20%ile | NVD | 2026-09-17 |
| CVE-2026-48737 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, is_global_address in src/p | MEDIUM | 4.9 | 8%ile | NVD | 2026-09-15 |
| CVE-2026-55374 | canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, Request::buildRequestUr | MEDIUM | 4.8 | 14%ile | NVD | 2026-09-15 |
| CVE-2026-58196 | ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior | MEDIUM | 4.7 | 31%ile | NVD | 2026-09-15 |
| CVE-2026-85732 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/utils.go a | MEDIUM | 4.7 | 32%ile | NVD | 2026-09-16 |
| CVE-2026-54565 | rhwp is an HWP viewer and editor implemented in Rust and WebAssembly. Prior to rhwp 0.7.15 and rhwp Chrome and Firefox e | MEDIUM | 4.7 | 3%ile | NVD | 2026-09-17 |
| CVE-2026-40537 | A server-side request forgery (SSRF) vulnerability in PersonMail API in Synology DiskStation Manager (DSM) before 7.2.1- | MEDIUM | 4.3 | 17%ile | NVD | 2026-09-18 |
| CVE-2026-48522 | PyJWKClient: missing scheme allowlist enables SSRF + token forgery via file://, ftp://, data: schemes | MEDIUM | 4.2 | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-76559 | The WP Import Export Lite WordPress plugin before 3.9.33 does not properly validate URLs before requesting them during t | MEDIUM | 4.1 | 21%ile | NVD | 2026-09-16 |
| CVE-2026-19504 | Fabric.js loadFromJSON Server-Side Request Forgery Vulnerability. This vulnerability allows remote attackers to disclose | MEDIUM | 4.0 | 2%ile | NVD | 2026-09-15 |
| CVE-2026-93384 | Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker l | LOW | 3.7 | 12%ile | NVD | 2026-09-17 |
| CVE-2026-54450 | ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior | LOW | 2.9 | 25%ile | NVD | 2026-09-15 |
| CVE-2026-90580 | A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the fi | LOW | 2.1 | 14%ile | NVD | 2026-09-13 |
| CVE-2026-90814 | A flaw has been found in cosmicstack-labs mercury-agent up to 1.1.13. Affected by this vulnerability is the function git | LOW | 2.1 | 12%ile | NVD | 2026-09-14 |
| CVE-2026-90818 | A security flaw has been discovered in netease-youdao LobsterAI 2026.6.15/2026.8.28/2026.9.3/2026.9.4. Impacted is the f | LOW | 2.1 | 42%ile | NVD | 2026-09-14 |
| CVE-2026-18424 | Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Server-Side Request Forgery iremote file import via cross-port reuse of a h | LOW | 2.1 | 22%ile | NVD | 2026-09-15 |
| CVE-2026-92527 | A vulnerability has been found in chatwoot up to 4.17.1. This impacts an unknown function of the file callbacks_controll | LOW | 2.1 | 29%ile | NVD | 2026-09-16 |
| CVE-2026-90971 | Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier all | UNKNOWN | — | 4%ile | NVD | 2026-09-15 |
| CVE-2026-8328 | FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address | UNKNOWN | — | 39%ile | Microsoft | 2026-05-12 |
| CVE-2026-46683 | Snappy: SSRF and local file read via the xsl-style-sheet option | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-50221 | OSSA-2026-024: Swift proxy-server SSRF via header injection | UNKNOWN | — | 4%ile | OpenStack | 2026-06-23 |
| FG-IR-26-159 | Server-Side Request Forgery (SSRF) | UNKNOWN | — | — | Fortinet | 2026-08-12 |