Vulnerabilities

Summary — last 7 days

New vulnerabilities2,761▲ 86 vs. last week
Critical / high1,460▲ 350 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)91▼ 420 vs. last week
–

1 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedHigh (7.8)0.97%—Create-cloudflareOpennextjs Opennext FOR Cloudflare6/16/20256/17/2026
A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package. The vulnerability stems from an unimplemented feature in the Cloudflare adapter for Open Next, which allowed unauthenticated users to proxy arbitrary remote content via the /_next/image endpoint. This issue allowed…