Vulnerability index

Browse CVEs

2,810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Unclassified HIGH 8.3
CVE-2026-62143

A Server-Side Request Forgery (SSRF) protection bypass existed in the html_to_markdown expansion module of misp-modules. The module attempts to prev…

Patch available
Fix from $1,950 2026-07-13
Unclassified MEDIUM 6.3
CVE-2026-15525

A vulnerability was detected in kLOsk adloop up to 0.9.0. This vulnerability affects the function _validate_urls of the file src/adloop/ads/write.py.…

Patch available
Fix from $1,600 2026-07-13
Unclassified MEDIUM 6.3
CVE-2026-15508

A flaw has been found in Helicone ai-gateway up to 0.2.0-beta.30. This affects the function build_target_url of the file ai-gateway/src/dispatcher/se…

Mitigation only
Fix from $1,600 2026-07-12
Unclassified MEDIUM 6.3
CVE-2026-15501

A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.25.2. Affected by this issue is the function ToolsRoute.test_mcp_connection…

Mitigation only
Fix from $1,600 2026-07-12
Unclassified MEDIUM 6.3
CVE-2026-15500

A weakness has been identified in AstrBotDevs AstrBot up to 4.25.2. Affected by this vulnerability is the function get_online_plugins of the file ast…

Mitigation only
Fix from $1,600 2026-07-12
Unclassified HIGH 8.5
CVE-2026-61429

PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend that allows attackers to bypass…

Mitigation only
Fix from $1,950 2026-07-11
Unclassified MEDIUM 5.8
CVE-2026-55187

Mailpit is an email testing tool and API for developers. Prior to 1.30.2, the remediation shipped for CVE-2026-27808 is incomplete because the tools.…

Patch available
Fix from $1,600 2026-07-10
Unclassified HIGH 8.1
CVE-2026-49213

TypeBot is a chatbot builder tool. Prior to 3.17.2, Typebot's shared SSRF validator in packages/lib/src/ssrf/validateHttpReqUrl.ts can be bypassed wi…

Patch available
Fix from $1,950 2026-07-10
Unclassified MEDIUM 6.9
CVE-2026-57575

Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a Server-Side Request Forgery (SSRF) vulnerability in…

Patch available
Fix from $1,600 2026-07-10
Rabbitmq Server CRITICAL 10.0
CVE-2026-57211

RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm…

Fix: 4.2.6+
Fix from $2,300 2026-07-10
Unclassified HIGH 7.5
CVE-2026-55229

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.34.0, Gotenberg's /forms/libreoffice/convert endpoint allows a specially crafte…

Patch available
Fix from $1,950 2026-07-10
Coturn HIGH 7.4
CVE-2026-53450

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, coturn rejects loopback peers by default unless allow-loopback-…

Fix: 4.13.0+
Fix from $1,950 2026-07-10
Unclassified HIGH 8.2
CVE-2026-55641

9Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by reading the client-controlled H…

Patch available
Fix from $1,950 2026-07-10
Unclassified HIGH 7.4
CVE-2026-56676

9Router is an AI router & token saver. Prior to 0.5.2, 9router validates image URLs by resolving the host before fetching, but open-sse/translator/co…

Patch available
Fix from $1,950 2026-07-10
Unclassified CRITICAL 9.3
CVE-2026-15143

A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Sc…

Mitigation only
Fix from $2,300 2026-07-10
Unclassified HIGH 7.2
CVE-2026-60091

PraisonAI before 4.6.78 contains an unauthenticated server-side request forgery vulnerability in the Jobs API /api/v1/runs endpoint. The webhook_url …

Mitigation only
Fix from $1,950 2026-07-10
Crawl4ai HIGH 7.5
CVE-2026-56261

Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, which…

Fix: 0.8.7+
Fix from $1,950 2026-07-10
Unclassified CRITICAL 9.3
CVE-2026-15378

A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery …

Mitigation only
Fix from $2,300 2026-07-10
Unclassified MEDIUM 6.4
CVE-2026-12123

The All-in-One Video Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.8.5 via the 'v…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified HIGH 7.3
CVE-2026-15330

A vulnerability was determined in zhayujie CowAgent up to 2.1.1. Impacted is the function _build_image_content/_download_to_data_url of the file agen…

Patch available
Fix from $1,950 2026-07-10
Unclassified MEDIUM 6.3
CVE-2026-15317

A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. Affected by this vulnerability is the function WebFetchTool.Execute of the file p…

Mitigation only
Fix from $1,600 2026-07-10
New Api HIGH 7.7
CVE-2026-33655

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the default SSRF pr…

Fix: 0.12.0+
Fix from $1,950 2026-07-09
Open Webui HIGH 7.7
CVE-2026-59221

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 before 0.10.0, _sanitize_proxy_path in backend/open_…

Patch available
Fix from $1,950 2026-07-09
Unclassified MEDIUM 6.3
CVE-2026-15189

A security vulnerability has been detected in aerostackdev aerostack-mcp up to 6315dfde7df0a15aaf743f88d91347115e09ba23. Affected by this issue is th…

Mitigation only
Fix from $1,600 2026-07-09
Fluentd HIGH 7.2
CVE-2026-44161

Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, the Fluentd …

Fix: 1.19.3+
Fix from $1,950 2026-07-08
Unclassified HIGH 8.6
CVE-2026-60105

Monsta FTP before 2.14.5 contains a server-side request forgery vulnerability in the fetchRemoteFile action caused by an incomplete IP blocklist chec…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified HIGH 7.4
CVE-2026-59806

Gradio before 6.20.0 contains an open redirect and server-side request forgery vulnerability that allows attackers to redirect users to arbitrary URL…

Patch available
Fix from $1,950 2026-07-08
Zeep MEDIUM 5.9
CVE-2026-58501

Zeep is a Python SOAP client. From 4.0.0 before 4.3.3, Settings.forbid_external is defined but not enforced when parsing WSDL or XSD documents, allow…

Fix: 4.3.3+
Fix from $1,600 2026-07-08
Unclassified CRITICAL 9.3
CVE-2026-59702

repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that allows unauthenticated attackers to make arbitrary o…

Patch available
Fix from $2,300 2026-07-08
Unclassified HIGH 7.7
CVE-2026-54607

FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta4, the HTTP-tool OpenAPI schema importer validates only the top-level URL b…

Patch available
Fix from $1,950 2026-07-07