ssrf
76 articles with this tag
HIGH
CRITICAL
CRITICAL
HIGH
MEDIUM
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
HIGH
CRITICAL
MEDIUM
CRITICAL
MEDIUM
MEDIUM
MEDIUM
MEDIUM
HIGH
HIGH
MEDIUM
CRITICAL
CRITICAL
HIGH
MEDIUM
MEDIUM
CRITICAL
HIGH
CRITICAL
CRITICAL
HIGH
HIGH
CRITICAL
CRITICAL
LOW
CRITICAL
CRITICAL
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
CRITICAL
HIGH
MEDIUM
HIGH
LOW
INFO
MEDIUM
MEDIUM
MEDIUM
MEDIUM
[NEU] [hoch] IBM MQ Appliance (Axios Node.js): Mehrere Schwachstellen
🕵️‍♂️ SonicWall SMA1000 (CVE-2026-15409): SSRF to Erlang RCE chained into automated DCSync from the appliance
[NEU] [hoch] Kyverno: Mehrere Schwachstellen
CVE-2026-81357 Visual Studio Code Security Feature Bypass Vulnerability
VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability
[NEU] [hoch] OpenCTI: Mehrere Schwachstellen
SonicWall reports two major security holes under active exploit
Multiples vulnérabilités dans les produits SonicWall (02 septembre 2026)
Multiples vulnérabilités dans SonicWall Secure Mobile Access (02 septembre 2026)
NCSC-2026-0337 [1.00] [H/H] Zero-Day kwetsbaarheden verholpen in SMA1000 Appliance van SonicWall
Hackers Chain Two New SonicWall Zero-Day Vulnerabilities
SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
Multiples vulnérabilités dans JFrog Artifactory (01 septembre 2026)
MLflow Vulnerability Exploited for Cloud Credential Theft
Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Server-Side Request Forgery Vulnerability
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
[webapps] Nodemailer 9.0.0 - File Read/ SSRF
[webapps] Linuxfabrik monitoring_plugins_6.0.0 - SSRF
[webapps] flyto_core 2.26.7 - Server-Side Request Forgery
Server-Side Request Forgery (SSRF)
VU#305509: OPeNDAP Hyrax is vulnerable to SSRF and Credential Disclosure
NCSC-2026-0251 [1.00] [M/H] Kwetsbaarheden verholpen in IBM Langflow OSS
USN-8572-1: Wget vulnerability
Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)
NCSC-2026-0239 [1.00] [H/H] Zero-Day kwetsbaarheden verholpen in SonicWall SMA1000
CVE-2026-57211 RabbitMQ: UNC SSRF affecting the management UI on Windows
VU#564823: GNU Wget enables SSRF via unvalidated FTP PASV IPs
Multiples vulnérabilités dans Roundcube (06 juillet 2026)
Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability
NCSC-2026-0217 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe ColdFusion
In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw
OHIF Viewers DICOM
OHIF Viewers DICOM
Multiples vulnérabilités dans GitLab (25 juin 2026)
Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230)
PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM
Microsoft AntiSSRF open-source library helps block server-side request forgery
NCSC-2026-0198 [1.00] [M/H] Kwetsbaarheden verholpen in Splunk Enterprise en Splunk Cloud Platform
PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data
CVE-2026-46683 Snappy: SSRF and local file read via the xsl-style-sheet option
Pre-auth XXE → HTTP SSRF on ArubaOS 8.13.2 closed as "theoretical / no valid PoC" despite TCP pcap, sshd localhost log, and internal port scan — documenting for community review
ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories
Vulnérabilité dans les produits Cisco (04 juin 2026)
Multiples vulnérabilités dans Synology Chat Server pour DSM (04 juin 2026)
Cisco Warns of Available PoC for Critical Unified CM Vulnerability
Blind POST SSRF in phpBB 4.0.0-alhpa1 Web Push (CVD with phpBB)
[webapps] EspoCRM 9.3.3 - SSRF
CVE-2026-8328 FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address
NCSC-2026-0136 [1.00] [M/H] Kwetsbaarheden verholpen in Cisco Unity Connection
Exploit su LMDeploy CVE-2026-33626: attacco SSRF immediato dopo disclosure
App UE verifica etĂ hackerata in 2 minuti: il gap tra promesse e realtĂ
LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure
SSRF via Report template and scheduling
Vulnérabilité dans Foxit PDF Services API (13 avril 2026)
[local] is-localhost-ip 2.0.0 - SSRF
NCSC-2026-0105 [1.00] [M/H] Kwetsbaarheden verholpen in Cisco Nexus Dashboard en Nexus Dashboard Insights
Cisco Nexus Dashboard and Nexus Dashboard Insights Server-Side Request Forgery Vulnerability
[NEU] [mittel] Docker Desktop Model Runner: Schwachstelle ermöglicht Offenlegung von Informationen
VU#655822: Kyverno is vulnerable to server-side request forgery (SSRF)
Vulnérabilité dans Docker Desktop (30 mars 2026)
Multiples vulnérabilités dans les produits Adobe (11 mars 2026)
Multiples vulnérabilités dans WordPress (11 mars 2026)
Six flaws found hiding in OpenClaw’s plumbing
Researchers Reveal Six New OpenClaw Vulnerabilities
Multiples vulnérabilités dans SPIP (18 février 2026)
When Audits Fail Part 2: From Pre-Auth SSRF to RCE in TRUfusion Enterprise
When Audits Fail Part 2: From Pre-Auth SSRF to RCE in TRUfusion Enterprise
PHP Server-Side Request Forgery (SSRF) | Security Vulnerability Database | Sourcery
Snyk Vulnerability Database | Snyk
PHP Server-Side Request Forgery (SSRF) Vulnerability (CVE-2025-1220) - Web Application Vulnerabilities | Invicti
[NEU] [niedrig] LangChain: Mehrere Schwachstellen
TURN Security Threats: A Hacker's View
[UPDATE] [hoch] PHP: Mehrere Schwachstellen
Multiples vulnérabilités dans GLPI (04 février 2026)
[NEU] [UNGEPATCHT] [niedrig] Keycloakb (CIBA): Schwachstelle ermöglicht Manipulation von Dateien
Tenable Discovers SSRF Vulnerability in Java TLS Handshakes That Creates DoS Risk