CVE-2026-105048Medium· 4.0▾ SunlitThe Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses).
▾ Sunlit zone — Low / medium · no exploitation signal
impact 22 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses).
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105049Medium· 5.8Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the public internet.
CVE-2026-100255High· 8.1In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset
CVE-2026-97196Critical· 9.1Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass. This issue affects GiveWP: from n/a through 4.16.9.
CVE-2026-101015High· 7.3A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2
CVE-2026-100837Low· 3.7Contrast (Edgeless Systems) through 1.20.0 performs unanchored suffix matching when selecting per-registry configuration in the imagepuller
CVE-2026-93601Low· 2.2rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS name constraints for certificates asserting a wildcard name