Miggo Predictive Vulnerability Database
Comprehensive vulnerability intelligence for security teams to gain clarity into CVEs to prioritize and respond with precision.
Concerned about an active attack path? Talk to our security experts and see Miggo in action
Contact UsTop 10 CVEs
New vulnerabilities last 30 days
CVE-2026-42353: i18next-http-middleware has path traversal / SSRF via user-controlled language and namespace parameters
i18next-http-middleware path traversal via unsanitized lng/ns params in getResourcesHandler grants arbitrary file read with fs-backend or SSRF with http-
Analysis:
Available
8.2
high
4/29/2026
CVE-2026-42352: pygeoapi 0.23.x: Unauthenticated SSRF via OGC API - Processes Subscriber
pygeoapi unauthenticated SSRF in the OGC API - Processes Subscriber forces arbitrary HTTP requests to internal services via a malicious subscriber object.
Analysis:
Available
8.6
high
4/29/2026
CVE-2026-42351: pygeoapi 0.23.x: Path Traversal in STAC FileSystemProvider
pygeoapi STAC FileSystemProvider path traversal grants unauthenticated directory exposure via crafted URLs with .. exploiting raw string path concatenation.
Analysis:
Available
7.5
high
4/29/2026
CVE-2026-41671: Admidio: OIDC Token Introspection Endpoint Returns Active for All Tokens Without Validation
Admidio OIDC introspection auth bypass returns active for fabricated tokens, granting attackers full authentication bypass on connected resource servers.
Analysis:
Available
6.8
medium
4/29/2026