CVE-2026-61953
Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
CVSS
7.2
Alto
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 27 jul 2026 · Última mod.: 27 jul 2026 · CWE-918
Sin historial EPSS suficiente todavía.
Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-654427.2 ALT—
———Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.4hCVE-2026-659256.5 MED—
———A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.6hCVE-2026-659246.5 MED—
———JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifactory to issue outbound HTTP requests to arbitrary destinations and receive the response content.6hCVE-2026-659236.8 MED—
———A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests.
The issue primarily affects confidentiality and integrity and has been addressed in fixed Artifactory versions.6hCVE-2026-656186.5 MED—
———Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cached response data.6hCVE-2026-64649——
———Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the attacker's request to control Host-associated headers. In some configurations, it's also possible to obtain internal values that weaken middleware/proxy authorization. Applications that use Server Actions are affected when the incoming host header is not fixed to a trusted value. This typically occurs on custom servers, or on deployments not behind a proxy that pins the host. Managed hosting pins the host upstream and is not affected; next start and standalone output do the same from version 14.2 onward. This issue has been fixed in versions 15.5.21 and 16.2.11.7h