74 CVEs — updated 2026-08-04 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-54735 | Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0 | CRITICAL | 10.0 | 28%ile | NVD | 2026-07-29 |
| CVE-2026-48331 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in priv | CRITICAL | 10.0 | 38%ile | NVD | 2026-08-03 |
| CVE-2026-54725 | vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1 | CRITICAL | 9.6 | 24%ile | NVD | 2026-07-31 |
| CVE-2026-14529 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 t | CRITICAL | 9.4 | 26%ile | NVD | 2026-07-29 |
| CVE-2026-67426 | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verifica | CRITICAL | 9.3 | 21%ile | NVD | 2026-07-29 |
| CVE-2026-18353 | PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and checks its **unverified** `iss` claim against an issuer a | HIGH | 8.8 | 15%ile | NVD | 2026-07-30 |
| CVE-2026-69078 | CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report PDF-generation functio | HIGH | 8.8 | 22%ile | NVD | 2026-08-03 |
| CVE-2026-54722 | DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_ | HIGH | 8.7 | 25%ile | NVD | 2026-07-30 |
| CVE-2026-54729 | DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_ | HIGH | 8.7 | 22%ile | NVD | 2026-07-31 |
| CVE-2026-15307 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse | HIGH | 8.7 | — | NVD | 2026-08-04 |
| CVE-2026-14869 | The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTT | HIGH | 8.6 | 22%ile | NVD | 2026-07-28 |
| CVE-2026-16328 | In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing | HIGH | 8.6 | 14%ile | NVD | 2026-07-29 |
| CVE-2026-67425 | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys | HIGH | 8.6 | 24%ile | NVD | 2026-07-29 |
| CVE-2026-12075 | Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.loa | HIGH | 8.6 | — | GitHub | 2026-07-31 |
| CVE-2026-67424 | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the HTTP modules http.get, ht | HIGH | 8.5 | 15%ile | NVD | 2026-07-29 |
| CVE-2026-67428 | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules includi | HIGH | 8.5 | 26%ile | NVD | 2026-07-29 |
| CVE-2026-69250 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 toke | HIGH | 8.5 | — | NVD | 2026-08-04 |
| CVE-2026-57862 | Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass | HIGH | 8.4 | 22%ile | NVD | 2026-07-30 |
| CVE-2026-66415 | Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated a | HIGH | 8.4 | 21%ile | NVD | 2026-07-30 |
| CVE-2026-67436 | Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In | HIGH | 8.3 | 16%ile | NVD | 2026-07-29 |
| CVE-2026-14980 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which c | HIGH | 8.3 | 13%ile | NVD | 2026-07-30 |
| CVE-2026-54690 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch | HIGH | 8.2 | 11%ile | NVD | 2026-07-28 |
| CVE-2026-54691 | datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61.0, src/datamodel_co | HIGH | 8.2 | 11%ile | NVD | 2026-07-28 |
| CVE-2026-58189 | Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. T | HIGH | 8.2 | 39%ile | NVD | 2026-07-29 |
| CVE-2026-53500 | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes | HIGH | 8.2 | 21%ile | NVD | 2026-07-31 |
| CVE-2026-67311 | Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fail | HIGH | 8.2 | 17%ile | NVD | 2026-08-01 |
| CVE-2026-14540 | A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-t | HIGH | 8.0 | 10%ile | NVD | 2026-07-31 |
| CVE-2026-59931 | PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 t | HIGH | 7.7 | 42%ile | NVD | 2026-07-28 |
| CVE-2026-67201 | V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows | HIGH | 7.7 | 32%ile | NVD | 2026-07-29 |
| CVE-2026-67346 | Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery vulnerability in the _is_safe_url | HIGH | 7.7 | 21%ile | NVD | 2026-07-30 |
| CVE-2026-69192 | ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 ac | HIGH | 7.7 | 22%ile | NVD | 2026-08-03 |
| CVE-2026-18378 | A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able t | HIGH | 7.6 | 15%ile | NVD | 2026-07-30 |
| CVE-2026-18381 | A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom r | HIGH | 7.6 | 10%ile | NVD | 2026-07-30 |
| CVE-2026-69257 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP | HIGH | 7.6 | — | NVD | 2026-08-04 |
| CVE-2026-55391 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch | HIGH | 7.5 | 10%ile | NVD | 2026-07-28 |
| CVE-2026-18446 | fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a refer | HIGH | 7.5 | 13%ile | NVD | 2026-07-31 |
| CVE-2024-43204 | Apache HTTP Server: SSRF with mod_headers setting Content-Type header | HIGH | 7.5 | 52%ile | Microsoft | 2025-07-08 |
| CVE-2026-54660 | swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resol | HIGH | 7.4 | 16%ile | NVD | 2026-07-29 |
| CVE-2026-23904 | Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A re | HIGH | 7.3 | 23%ile | NVD | 2026-07-29 |
| CVE-2026-69246 | Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and | HIGH | 7.2 | 12%ile | NVD | 2026-08-03 |
| CVE-2026-54885 | Server-Side Request Forgery vulnerability in malach-it Boruta allows an unauthenticated remote attacker to cause the OAu | MEDIUM | 6.9 | 30%ile | NVD | 2026-07-30 |
| CVE-2026-69198 | ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, ev | MEDIUM | 6.9 | 20%ile | NVD | 2026-08-03 |
| CVE-2026-46678 | Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.56.0 through 1.98.0, when | MEDIUM | 6.8 | 36%ile | NVD | 2026-07-29 |
| CVE-2026-54249 | Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and | MEDIUM | 6.8 | 10%ile | NVD | 2026-07-29 |
| CVE-2026-18382 | A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able | MEDIUM | 6.8 | 20%ile | NVD | 2026-07-30 |
| GHSA-vg6v-j97m-h5xq | @novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request | MEDIUM | 6.8 | — | GitHub | 2026-07-28 |
| CVE-2026-15974 | SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitize | MEDIUM | 6.5 | 11%ile | NVD | 2026-07-30 |
| CVE-2026-52371 | A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger component of xxl-job v3.4.0 allows authenticat | MEDIUM | 6.5 | 13%ile | NVD | 2026-07-31 |
| CVE-2026-57211 | RabbitMQ: UNC SSRF affecting the management UI on Windows | MEDIUM | 6.5 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-48858 | ftp client PASV response IP not validated against control peer, enabling SSRF and FTP bounce attacks | MEDIUM | 6.5 | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-67530 | WACRM is a self-hostable CRM template for WhatsApp. In 0.7.0 and earlier, the automation send_webhook action in src/lib/ | MEDIUM | 6.4 | 5%ile | NVD | 2026-07-30 |
| CVE-2026-54663 | swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resol | MEDIUM | 6.1 | 8%ile | NVD | 2026-07-29 |
| CVE-2026-66325 | Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofin | MEDIUM | 6.1 | 33%ile | NVD | 2026-08-04 |
| CVE-2026-67435 | linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to ve | MEDIUM | 6.0 | 21%ile | NVD | 2026-07-29 |
| CVE-2026-18369 | A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns | MEDIUM | 5.8 | 9%ile | NVD | 2026-07-30 |
| CVE-2026-10526 | The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests th | MEDIUM | 5.8 | 4%ile | NVD | 2026-08-04 |
| CVE-2026-18647 | A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue | MEDIUM | 5.5 | 28%ile | NVD | 2026-08-03 |
| CVE-2026-70367 | A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS pr | MEDIUM | 5.4 | — | NVD | 2026-08-04 |
| CVE-2026-64870 | MaxKB is an open-source AI assistant for enterprise. In versions 2.0.0 through 2.10.4-lts, UpdateStoreTool.update_tool p | MEDIUM | 5.3 | 12%ile | NVD | 2026-07-30 |
| CVE-2026-59231 | Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to | MEDIUM | 5.3 | 18%ile | NVD | 2026-07-31 |
| CVE-2026-18736 | Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the serve | MEDIUM | 5.3 | 16%ile | NVD | 2026-08-03 |
| CVE-2026-16536 | The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL bef | MEDIUM | 5.3 | 4%ile | NVD | 2026-08-04 |
| CVE-2026-6089 | The WP CTA plugin for WordPress is vulnerable to Server-Side Request Forgery via the 'sticky_s_media' parameter in impor | MEDIUM | 4.9 | 20%ile | NVD | 2026-07-29 |
| CVE-2026-48522 | PyJWKClient: missing scheme allowlist enables SSRF + token forgery via file://, ftp://, data: schemes | MEDIUM | 4.2 | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-4912 | The Media Cleaner: Clean your WordPress! plugin for WordPress is vulnerable to Server-Side Request Forgery in all versio | MEDIUM | 4.1 | 15%ile | NVD | 2026-07-28 |
| CVE-2026-54272 | ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks | MEDIUM | — | 17%ile | GitHub | 2026-08-03 |
| CVE-2026-53607 | @apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header | LOW | 3.7 | 13%ile | GitHub | 2026-07-31 |
| CVE-2026-57232 | Contao is an Open Source CMS. From 5.3.35 through 5.3.47 and from 5.7.0-RC1 through 5.7.8, the Feed Reader front-end mod | LOW | 3.1 | 8%ile | NVD | 2026-07-31 |
| CVE-2026-18774 | A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file ag | LOW | 2.1 | — | NVD | 2026-08-04 |
| CVE-2026-18775 | A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browse | LOW | 2.1 | — | NVD | 2026-08-04 |
| CVE-2025-62718 | Axios has a NO_PROXY Hostname Normalization Bypass Leads to SSRF | UNKNOWN | — | 64%ile | Microsoft | 2026-04-14 |
| CVE-2026-8328 | FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address | UNKNOWN | — | 37%ile | Microsoft | 2026-05-12 |
| CVE-2026-46683 | Snappy: SSRF and local file read via the xsl-style-sheet option | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-50221 | OSSA-2026-024: Swift proxy-server SSRF via header injection | UNKNOWN | — | 4%ile | OpenStack | 2026-06-23 |