Vulnerability index

Browse CVEs

2,810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Unclassified HIGH 8.5
CVE-2026-61430

PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostnames at check time but re-reso…

Mitigation only
Fix from $1,950 2026-07-15
C2pa HIGH 8.2
CVE-2026-48290

CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the contex…

Fix: after 0.84.0
Fix from $1,950 2026-07-14
Unclassified MEDIUM 6.3
CVE-2026-15750

A weakness has been identified in mastergo-design mastergo-magic-mcp up to 0.2.0. Impacted is the function z.string of the file src/tools/get-compone…

Mitigation only
Fix from $1,600 2026-07-14
Unclassified HIGH 7.7
CVE-2026-61520

Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery vulnerability in the image p…

Mitigation only
Fix from $1,950 2026-07-14
Coldfusion HIGH 7.7
CVE-2026-48332EPSS 11%

ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacke…

Mitigation only
Fix from $1,950 2026-07-14
Unclassified MEDIUM 6.8
CVE-2026-24234

NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal media fetching functions, where a network-accessible attacker could cause se…

Mitigation only
Fix from $1,600 2026-07-14
Unclassified HIGH 7.3
CVE-2026-15643

AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with AWS HealthLa…

Mitigation only
Fix from $1,950 2026-07-14
Symfony HIGH 8.6
CVE-2026-48736

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, N…

Fix: 5.4.43 / 6.4.41+
Fix from $1,950 2026-07-14
Experience Manager CRITICAL 9.6
CVE-2026-48259

Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the conte…

Fix: after 2020.5.0
Fix from $2,300 2026-07-14
Sma6210 Firmware CRITICAL 10.0
CVE-2026-15409 KEVEPSS 74%

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attack…

Mitigation only
Fix from $2,300 2026-07-14
Sharepoint Server MEDIUM 6.5
CVE-2026-55051

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

Fix: 16.0.19725.20434+
Fix from $1,600 2026-07-14
Unclassified MEDIUM 5.1
CVE-2026-14645

Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, all…

Mitigation only
Fix from $1,600 2026-07-14
Webmail CRITICAL 10.0
CVE-2026-62643

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to…

Fix: 1.6.17 / 1.7.2+
Fix from $2,300 2026-07-14
Unclassified MEDIUM 5.3
CVE-2026-7494

Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-trust…

Mitigation only
Fix from $1,600 2026-07-14
Sustainable Irrigation Platform MEDIUM 6.5
CVE-2026-58478

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated …

Fix: after 5.2.16
Fix from $1,600 2026-07-14
Unclassified CRITICAL 9.2
CVE-2026-15183

Multiple input validation vulnerabilities in the Snowflake Spark Connector (spark-snowflake) versions prior to 3.2.1 can allow attackers to exfiltrat…

Mitigation only
Fix from $2,300 2026-07-14
Unclassified MEDIUM 6.3
CVE-2026-15668

A vulnerability has been found in louisho5 picobot up to 0.2.0. This vulnerability affects the function WebTool.Execute of the file internal/agent/to…

Mitigation only
Fix from $1,600 2026-07-14
Unclassified MEDIUM 6.3
CVE-2026-15628

A security flaw has been discovered in zhayujie chatgpt-on-wechat CowAgent up to 2.1.1. This issue affects the function Vision._download_to_data_url …

Patch available
Fix from $1,600 2026-07-14
Unclassified MEDIUM 6.3
CVE-2026-15624

A vulnerability has been found in nextlevelbuilder GoClaw 3.13.3-beta.3. Affected by this vulnerability is the function bytePlusDownloadVideo of the …

Mitigation only
Fix from $1,600 2026-07-14
Unclassified MEDIUM 6.3
CVE-2026-15620

A security vulnerability has been detected in mosaxiv clawlet up to 0.2.10. This affects the function tools.webFetch of the file tools/tool_web_fetch…

Mitigation only
Fix from $1,600 2026-07-14
Unclassified MEDIUM 6.3
CVE-2026-15619

A weakness has been identified in mosaxiv clawlet up to 0.2.10. The impacted element is the function web_fetch of the file tools/tool_web_fetch.go of…

Mitigation only
Fix from $1,600 2026-07-14
Crewai HIGH 7.4
CVE-2026-62240

CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and bloc…

Fix: 1.15.1+
Fix from $1,950 2026-07-13
Unclassified HIGH 8.6
CVE-2026-62242

Spring Boot Admin Server before 4.1.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers to register instance…

Patch available
Fix from $1,950 2026-07-13
Openclaw HIGH 8.5
CVE-2026-62197

OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebSocket URLs. Attackers with lower-tr…

Fix: 2026.6.6+
Fix from $1,950 2026-07-13
Unclassified HIGH 7.4
CVE-2026-49969

Laravel-Mediable before 7.0.0 contains a server-side request forgery vulnerability that allows remote attackers to issue arbitrary HTTP requests from…

Patch available
Fix from $1,950 2026-07-13
Unclassified HIGH 7.3
CVE-2025-45869

LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server-Side Request Forgery (SSRF). An unauthenticated attacker can exploit th…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified MEDIUM 6.4
CVE-2026-57413

Server-Side Request Forgery (SSRF) vulnerability in bdthemes Instant Image Generator ai-image allows Server Side Request Forgery.This issue affects I…

Mitigation only
Fix from $1,600 2026-07-13
Unclassified HIGH 7.2
CVE-2026-57407

Server-Side Request Forgery (SSRF) vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp allows Server Side Request Forgery.Thi…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified HIGH 7.2
CVE-2026-57372

Server-Side Request Forgery (SSRF) vulnerability in denishua WPJAM Basic wpjam-basic allows Server Side Request Forgery.This issue affects WPJAM Basi…

No fix yet
Fix from $1,950 2026-07-13
Gravitino MEDIUM 6.5
CVE-2026-49876

Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job temp…

Fix: 1.3.0+
Fix from $1,600 2026-07-13