PoC Archive PoC Archive

tag

Ssrf

Oracle E-Business Suite Pre-Authentication RCE Chain (CVE-2025-61882) KEV RW EPSS 100%
CVE-2025-61882 (Oracle Security Alert, out-of-band, October 2025) web Patched
CVE-2025-61882webCRITICAL 9.8Patched2026-08-09Apache Polaris — Cross-Tenant Credential Vending Before Location Validation in Iceberg REST Register (CVE-2026-64640)
CVE-2026-64640 cloud Patched
CVE-2026-64640cloudHIGH 8.1Patched2026-08-09Apache Tika PDF Parser XXE via Crafted XFA Form (CVE-2025-54988) EPSS 15%
CVE-2025-54988 (GHSA-p72g-pv48-7w9x, Apache JIRA TIKA-4459) web Patched
CVE-2025-54988webCRITICAL 9.8Patched2026-07-31Alibaba Fastjson 1.x checkAutoType Bypass to Remote Code Execution via jar:http SSRF and fd-Reread Trick (CVE-2026-16723) EPSS 16%
CVE-2026-16723 web Unpatched
CVE-2026-16723webCRITICAL 9Unpatched2026-07-31Cisco Unified Communications Manager WebDialer SSRF → Arbitrary File Write → Root (CVE-2026-20230) KEV EPSS 88%
CVE-2026-20230 (cisco-sa-cucm-ssrf-cXPnHcW) network Patched
CVE-2026-20230networkCRITICAL 8.6Patched2026-07-19SonicWall SMA1000 WorkPlace SSRF → Internal Erlang RPC Remote Code Execution (CVE-2026-15409) KEV RW EPSS 84%
CVE-2026-15409 (SNWLID-2026-0008) network Patched
CVE-2026-15409networkCRITICAL 10Patched2026-07-15ThingsBoard IoT Platform SSRF via SVG Image Upload (CVE-2025-34282)
CVE-2025-34282 web Patched
CVE-2025-34282webCRITICAL 9.1Patched2026-07-06StoryChief WordPress Plugin Unauthenticated Arbitrary File Upload via Webhook (CVE-2025-7441) EPSS 39%
CVE-2025-7441 web Unpatched
CVE-2025-7441webCRITICAL 9.8Unpatched2026-07-06ASP.NET Core Kestrel HTTP Request Smuggling (CVE-2025-55315) EPSS 66%
CVE-2025-55315 network Patched
CVE-2025-55315networkCRITICAL 9.9Patched2026-07-06Apache Parquet-Avro Schema Deserialization RCE/SSRF — Incomplete-Fix Bypass (CVE-2025-30065) EPSS 43%
CVE-2025-30065 misc Patched
CVE-2025-30065miscCRITICAL 9.8Patched2026-07-06WordPress User Language Switch Plugin SSRF — CVE-2026-0745
CVE-2026-0745 (GHSA-m38c-5p3m-p7gm) web Unverified
CVE-2026-0745webMEDIUMUnverified2026-07-05Unauthenticated SSRF in Ech0 via /api/website/title (CVE-2026-35037)
CVE-2026-35037 web Patched
CVE-2026-35037webHIGHPatched2026-07-05Typebot Unauthenticated Preview-Chat SSRF — CVE-2026-33712
CVE-2026-33712 web Patched
CVE-2026-33712webHIGHPatched2026-07-05SmarterMail ConnectToHub Unauthenticated SSRF Leading to Remote Command Execution — CVE-2026-24423 KEV RW EPSS 88%
CVE-2026-24423 web Unverified
CVE-2026-24423webCRITICALUnverified2026-07-05Plunk SSRF via Unvalidated AWS SNS SubscriptionConfirmation — CVE-2026-32096
CVE-2026-32096 cloud Patched
CVE-2026-32096cloudCRITICAL 9.3Patched2026-07-05pdfmake Server-Side Request Forgery via Unvalidated Document URLs (CVE-2026-26801)
CVE-2026-26801 web Patched
CVE-2026-26801webHIGHPatched2026-07-05Open WebUI SSRF via HTTP Redirect Bypass of validate_url() (CVE-2026-45401)
CVE-2026-45401 web Patched
CVE-2026-45401webHIGHPatched2026-07-05Microsoft Exchange Authenticated Arbitrary File Read via EWS Reference Attachment (CVE-2026-45504)
CVE-2026-45504 web Patched
CVE-2026-45504webHIGHPatched2026-07-05Mercator Configuration SSRF Chained to Internal Redis RCE (CVE-2026-49345)
CVE-2026-49345 web Unverified
CVE-2026-49345webCRITICALUnverified2026-07-05MagicMirror² Unauthenticated SSRF via `/cors` Endpoint (CVE-2026-42281)
CVE-2026-42281 web Patched
CVE-2026-42281webCRITICAL 9.2Patched2026-07-05LiteLLM /config/update Broken Access Control (CVE-2026-35029) EPSS 26%
CVE-2026-35029 web Patched
CVE-2026-35029webHIGH 8.8Patched2026-07-05Kan SSRF via Attachment Download Endpoint — CVE-2026-32255 EPSS 21%
CVE-2026-32255 (GHSA-qrx8-9hc6-jvqg) web Patched
CVE-2026-32255webHIGH 8.6Patched2026-07-05EspoCRM 9.3.3 Authenticated SSRF via Alternative IPv4 Loopback Notation — CVE-2026-33534
CVE-2026-33534 web Patched
CVE-2026-33534webMEDIUMPatched2026-07-05Chamilo LMS Unauthenticated install.ajax.php SSRF + Open Mail Relay — CVE-2026-33715
CVE-2026-33715 / GHSA-mxc9-9335-45mc web Unverified
CVE-2026-33715 / GHSA-mxc9-9335-45mcwebHIGH 7.5Unverified2026-07-05Apache Flink Kubernetes Operator SSRF via jarURI (CVE-2026-40564)
CVE-2026-40564 cloud Patched
CVE-2026-40564cloudHIGHPatched2026-07-05@haxtheweb/open-apis Credential Exposure via SSRF in cacheAddress Endpoint (CVE-2026-46391)
CVE-2026-46391 (GHSA-4fg7-f244-3j49) web Unverified
CVE-2026-46391webHIGHUnverified2026-07-05Cisco Unified CM WebDialer SSRF to Arbitrary File Write / RCE (CVE-2026-20230) KEV EPSS 88%
CVE-2026-20230 network Unverified
CVE-2026-20230networkCRITICAL 8.6Unverified2026-07-01Next.js WebSocket Upgrade SSRF (Self-Hosted) (CVE-2026-44578) EPSS 39%
CVE-2026-44578 web Patched
CVE-2026-44578webHIGH 8.6Patched2026-05-17Apache Parquet Java Unsafe Deserialization RCE (CVE-2025-30065) EPSS 43%
CVE-2025-30065 misc Patched
CVE-2025-30065miscCRITICAL 10Patched2026-05-16