Server-Side Request Forgery Vulnerabilities

15 advisories classified as Server-Side Request Forgery

15

Total CVEs

7

Critical

8

High

CVE-2026-15409

Jul 14, 2026

Critical 10.0

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make re...

Read Advisory

CVE-2026-20230

Jun 3, 2026

High 8.6

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacke...

Read Advisory

CVE-2026-44335

May 8, 2026

Critical 9.8

PraisonAI is a multi-agent teams system. Prior to version 1.6.32, the URL checking logic in PraisonAI has a logical flaw that could be bypassed by attackers, leading to SSRF attacks. This issue has be...

Read Advisory

CVE-2026-32210

Apr 23, 2026

Critical 9.3

Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network....

Read Advisory

CVE-2026-35431

Apr 23, 2026

Critical 10.0

Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network....

Read Advisory

CVE-2026-26150

Apr 23, 2026

High 8.6

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network....

Read Advisory

CVE-2026-40089

Apr 9, 2026

Critical 9.9

Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audio Streaming Stack dashboard contains a Server-Side Request Forgery (SSRF) vulnerability in its API c...

Read Advisory

CVE-2026-33107

Apr 3, 2026

Critical 10.0

Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network....

Read Advisory

CVE-2026-34163

Mar 31, 2026

High 7.7

FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, FastGPT's MCP (Model Context Protocol) tools endpoints (/api/core/app/mcpTools/getTools and /api/core/app/mcpTools/runTool) accept ...

Read Advisory

CVE-2026-34504

Mar 31, 2026

High 8.3

OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows attackers to fetch internal URLs. A malicious or c...

Read Advisory

CVE-2026-5016

Mar 28, 2026

High 7.3

A vulnerability was identified in elecV2 elecV2P up to 3.8.3. This affects the function eAxios of the file /mock of the component URL Handler. Such manipulation of the argument req leads to server-sid...

Read Advisory

CVE-2026-22742

Mar 27, 2026

High 8.6

Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal messages that include user-supplied media URLs. I...

Read Advisory

CVE-2026-32169

Mar 19, 2026

Critical 10.0

Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network....

Read Advisory

CVE-2026-30834

Mar 7, 2026

High 7.5

PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. Prior to version 0.7.7, a Server-Side Request Forgery (SSRF) vulnerability in the /download endpoint all...

Read Advisory

CVE-2026-0745

Feb 14, 2026

High 7.2

The User Language Switch plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.10 due to missing URL validation on the 'download_language()' funct...

Read Advisory

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.