Vulnerability index

Browse CVEs

2,810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Coder MEDIUM 6.5
CVE-2026-45796

Coder allows organizations to provision remote development environments via Terraform. Versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, an…

Fix: 2.24.5 / 2.29.13+
Fix from $1,600 2026-07-07
Unclassified HIGH 8.6
CVE-2026-59707

LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint that allows attackers to fetch arbit…

Patch available
Fix from $1,950 2026-07-07
Unclassified MEDIUM 5.5
CVE-2026-58468

NocoBase through 2.1.20 contains a server-side request forgery vulnerability in the serverRequest wrapper that allows authenticated administrators to…

Patch available
Fix from $1,600 2026-07-07
Crawl4ai HIGH 8.6
CVE-2026-57573

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF destination check on the non-…

Fix: 0.9.0+
Fix from $1,950 2026-07-06
Hugo MEDIUM 6.8
CVE-2026-58404

Hugo is a static site generator. From v0.162.0 through v0.163.0, the default security.http.urls policy denies requests to loopback, internal, and clo…

Fix: 0.163.1+
Fix from $1,600 2026-07-06
Hugo MEDIUM 5.8
CVE-2026-50134

Hugo is a static site generator. From 0.91.0 until 0.162.0, resources.GetRemote enforces security.http.urls on the URL it is called with, but it did …

Fix: 0.162.0+
Fix from $1,600 2026-07-06
Unclassified CRITICAL 9.1
CVE-2025-53830

Anti-Virus for ownCloud is an anti-virus application for file storage, synchronization, and sharing application ownCloud. Versions of Anti-Virus for …

Mitigation only
Fix from $2,300 2026-07-06
Unclassified HIGH 8.5
CVE-2025-53828

SharePoint for ownCloud is an application for using SharePoint with the file storage, synchronization, and sharing application ownCloud Classic. In S…

Mitigation only
Fix from $1,950 2026-07-06
Rancher Fleet MEDIUM 5.0
CVE-2026-44936

Missing filtering when the helmRepoURLRegex field isn't set on a GitRepo resource in SUSE Rancher Fleet's bundle reader in 0.15 before 0.15.2, 0.14 b…

Fix: 0.12.15 / 0.13.11+
Fix from $1,600 2026-07-06
Rancher Fleet HIGH 8.2
CVE-2026-44937

Potential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before …

Fix: 0.12.15 / 0.13.11+
Fix from $1,950 2026-07-06
Camel HIGH 7.5
CVE-2026-55994

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…

Fix: 4.18.3 / 4.21.0+
Fix from $1,950 2026-07-06
Camel HIGH 7.5
CVE-2026-55993

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Camel HIGH 7.5
CVE-2026-46726

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Camel CRITICAL 9.1
CVE-2026-48203

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Validation, Server-Side Request Fo…

Fix: 4.14.8 / 4.18.3+
Fix from $2,300 2026-07-06
Camel CRITICAL 9.1
CVE-2026-48205

Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component. The camel-dns producers read DNS operatio…

Fix: 4.14.8 / 4.18.3+
Fix from $2,300 2026-07-06
Unclassified MEDIUM 6.3
CVE-2026-14748

A flaw has been found in AIAnytime Awesome-MCP-Server up to a884bb51bcd99e08e14fd712c749d55d9d9a13ab. Affected by this issue is some unknown function…

Mitigation only
Fix from $1,600 2026-07-05
Unclassified MEDIUM 6.5
CVE-2026-58418

SSRF via HTTP Redirect in Repository Migration

Patch available
Fix from $1,600 2026-07-03
Edge Chromium HIGH 7.4
CVE-2026-57993

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Fix: 150.0.4078.48+
Fix from $1,950 2026-07-03
Edge Chromium MEDIUM 5.4
CVE-2026-58278

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Fix: 150.0.4078.48+
Fix from $1,600 2026-07-03
Edge Chromium MEDIUM 6.5
CVE-2026-57987

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Fix: 150.0.4078.48+
Fix from $1,600 2026-07-03
Unclassified CRITICAL 9.6
CVE-2026-22874

Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.

Patch available
Fix from $2,300 2026-07-03
Unclassified HIGH 8.5
CVE-2026-10055

In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the …

Mitigation only
Fix from $1,950 2026-07-03
Unclassified MEDIUM 5.5
CVE-2026-11397

The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and including 3.9.30 via the wpie_i…

No fix yet
Fix from $1,600 2026-07-03
Azure Openai HIGH 8.8
CVE-2026-45499

Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2026-07-02
Entra Provisioning Service HIGH 8.8
CVE-2026-57100

Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a ne…

Mitigation only
Fix from $1,950 2026-07-02
Unclassified MEDIUM 5.8
CVE-2026-59101

AutoBangumi before 3.2.8 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated remote attackers to probe internal n…

Patch available
Fix from $1,600 2026-07-02
Unclassified HIGH 7.7
CVE-2026-59095

LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attackers to direct internal HTTP req…

Patch available
Fix from $1,950 2026-07-02
Unifi Talk Application HIGH 7.5
CVE-2026-55113

A malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF) vulnerability found in UniFi Talk Application to exec…

Fix: 5.2.2+
Fix from $1,950 2026-07-02
Unifi Protect CRITICAL 9.9
CVE-2026-55115

A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to es…

Fix: 7.1.83+
Fix from $2,300 2026-07-02
Unifi Os Server HIGH 8.8
CVE-2026-54401

A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such…

Fix: after 5.1.15
Fix from $1,950 2026-07-02