Vulnerability index

Browse CVEs

2,810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Unclassified HIGH 7.4
CVE-2026-70666

Lemur manages TLS certificate creation. Prior to 1.9.3, an authority-role member could update acme_url through PUT /api/1/authorities/ without revali…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.7
CVE-2026-71303

Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_acme_url enforced ACME_DIRECTORY_HOST_ALLOWLIST when an authority was created, but …

Fix unknown
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.0
CVE-2026-65985

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the device-webapi-request Socket.IO handler in server…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 8.2
CVE-2026-47719

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY Socket.IO han…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-70667

Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_revocation_url in lemur/certificates/verify.py checked the original CRL or OCSP URL…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-55162

Lemur manages TLS certificate creation. Prior to 1.9.2, lemur/certificates/verify.py accepted CRL Distribution Point and OCSP responder URLs from upl…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified CRITICAL 9.9
CVE-2026-55166

Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url without an effective server-si…

Fix unknown
Fix from $5,750 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-63642

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, checkArticleUrl in defaultmodules/newsfeed/node_helper.js accepts the …

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-63643

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, the ADD_CALENDAR handler in defaultmodules/calendar/node_helper.js acc…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 8.1
CVE-2026-50143

The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 8.6
CVE-2026-75856

CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.7
CVE-2026-71365

A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When processing GitHub pull request webhooks…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.6
CVE-2026-12564

A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py r…

Fix unknown
Fix from $5,750 2026-08-18
Unclassified HIGH 8.5
CVE-2026-75898

RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The …

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.2
CVE-2026-32553

Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions.

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.2
CVE-2026-32473

Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions.

Fix unknown
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.0
CVE-2026-32467

Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions.

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 7.1
CVE-2026-75844

ArcadeDB versions before 26.8.1 contain a server-side request forgery vulnerability in the IMPORT DATABASE command where the security validator resol…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.1
CVE-2026-74905

SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vulnerability in the isPrivateIP function in kernel/util/net.go, used by SSRFSafeD…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.3
CVE-2026-64849

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated…

Fix unknown
Fix from $5,750 2026-08-17
Unclassified HIGH 8.6
CVE-2026-56677

9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/oidc/test/route.js passes the …

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 8.5
CVE-2026-73410

Budibase is an open-source low-code platform. Prior to 3.40.0, packages/backend-core/src/utils/outboundFetch.ts pinned a validated address through a …

Fix unknown
Fix from $4,900 2026-08-17
Unclassified MEDIUM 6.5
CVE-2026-73560

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the MiMoV2OmniMultiModalProcessor in vllm/transformers_utils/proc…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified HIGH 7.1
CVE-2026-35219

Budibase is an open-source low-code platform. Prior to 3.41.3, automation steps in packages/server/src/automations/steps/outgoingWebhook.ts, packages…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-50775

A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the server retrieving an image from a crafted URL, an…

Fix unknown
Fix from $5,750 2026-08-17
Unclassified MEDIUM 5.8
CVE-2026-48053

Kolibri is an offline-first education platform. Prior to version 0.19.4, several Kolibri API endpoints accept an unvalidated `baseurl` parameter and …

Fix unknown
Fix from $4,000 2026-08-17
Unclassified MEDIUM 5.4
CVE-2026-75053

In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint

Fix unknown
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.3
CVE-2026-75054

In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects

Fix unknown
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.3
CVE-2026-74858

A vulnerability has been found in jae-jae fetcher-mcp up to 0.3.9. Impacted is the function fetch_url/fetch_urls of the file /latest/meta-data/iam/se…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified MEDIUM 5.8
CVE-2026-75006

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to…

Fix unknown
Fix from $4,000 2026-08-17