Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
10.0 CRITICAL
CVE-2026-40175 — Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.3.1, the Axios library is vulnerable to a specific "Gadget" attack chain that allows Prototype Pollution in any…

axios | Remote | Supply Chain
Apr 10, 2026 May 07, 2026
Apr 10, 2026
May 07, 2026
8.2 HIGH
CVE-2026-40168 — Postiz has Server-Side Request Forgery via Redirect Bypass in /api/public/stream

Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endpoint is vulnerable to SSRF. Although the application validates the initially supplied URL and blocks direct p…

postiz | Remote | Server-Side Request Forgery
Apr 10, 2026 Apr 14, 2026
Apr 10, 2026
Apr 14, 2026
6.3 MEDIUM
CVE-2026-39922 — GeoNode SSRF via Service Registration

GeoNode versions 4.4.5 and 5.0.2 (and prior within their respective releases) contain a server-side request forgery vulnerability in the service registration endpoint that allows authenticated attack…

geonode | Remote | Server-Side Request Forgery
Apr 10, 2026 Apr 16, 2026
Apr 10, 2026
Apr 16, 2026
6.3 MEDIUM
CVE-2026-39921 — GeoNode < 4.4.5, 5.0.2 SSRF via Document Upload

GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery vulnerability that allows authenticated users with document upload permissions to trigger arbitrary outbou…

geonode | Remote | Server-Side Request Forgery
Apr 10, 2026 Apr 16, 2026
Apr 10, 2026
Apr 16, 2026
7.7 HIGH
CVE-2026-32252 — Chartbrew Cross-Tenant Template Export and Secret Disclosure in `GET /team/:team_id/templ…

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 4.9.0, a cross-tenant authorization bypass exists in Chartbrew …

chartbrew | Remote | Authorization
Apr 10, 2026 Apr 14, 2026
Apr 10, 2026
Apr 14, 2026
9.6 CRITICAL
CVE-2026-30232 — Chartbrew has SSRF in API Data Connection - No IP Validation on User-Provided URLs

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 4.8.5, Chartbrew allows authenticated users to create API data …

chartbrew | Remote | Server-Side Request Forgery
Apr 10, 2026 Apr 14, 2026
Apr 10, 2026
Apr 14, 2026
Showing 20 of 5486 Results