Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Camel HIGH 7.5
CVE-2026-55994

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…

Fix: 4.18.3 / 4.21.0+
Fix from $1,950 2026-07-06
Camel HIGH 7.5
CVE-2026-55993

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Camel HIGH 7.5
CVE-2026-46726

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Camel CRITICAL 9.1
CVE-2026-48203

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Validation, Server-Side Request Fo…

Fix: 4.14.8 / 4.18.3+
Fix from $2,300 2026-07-06
Camel CRITICAL 9.1
CVE-2026-48205

Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component. The camel-dns producers read DNS operatio…

Fix: 4.14.8 / 4.18.3+
Fix from $2,300 2026-07-06
Unclassified MEDIUM 6.3
CVE-2026-14748

A flaw has been found in AIAnytime Awesome-MCP-Server up to a884bb51bcd99e08e14fd712c749d55d9d9a13ab. Affected by this issue is some unknown function…

Mitigation only
Fix from $1,600 2026-07-05
Unclassified MEDIUM 6.5
CVE-2026-58418

SSRF via HTTP Redirect in Repository Migration

Patch available
Fix from $1,600 2026-07-03
Edge Chromium HIGH 7.4
CVE-2026-57993

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Fix: 150.0.4078.48+
Fix from $1,950 2026-07-03
Edge Chromium MEDIUM 5.4
CVE-2026-58278

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Fix: 150.0.4078.48+
Fix from $1,600 2026-07-03
Edge Chromium MEDIUM 6.5
CVE-2026-57987

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Fix: 150.0.4078.48+
Fix from $1,600 2026-07-03
Unclassified CRITICAL 9.6
CVE-2026-22874

Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.

Patch available
Fix from $2,300 2026-07-03
Unclassified HIGH 8.5
CVE-2026-10055

In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the …

Mitigation only
Fix from $1,950 2026-07-03
Unclassified MEDIUM 5.5
CVE-2026-11397

The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and including 3.9.30 via the wpie_i…

No fix yet
Fix from $1,600 2026-07-03
Azure Openai HIGH 8.8
CVE-2026-45499

Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2026-07-02
Entra Provisioning Service HIGH 8.8
CVE-2026-57100

Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a ne…

Mitigation only
Fix from $1,950 2026-07-02
Unclassified MEDIUM 5.8
CVE-2026-59101

AutoBangumi before 3.2.8 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated remote attackers to probe internal n…

Patch available
Fix from $1,600 2026-07-02
Unclassified HIGH 7.7
CVE-2026-59095

LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attackers to direct internal HTTP req…

Patch available
Fix from $1,950 2026-07-02
Unifi Talk Application HIGH 7.5
CVE-2026-55113

A malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF) vulnerability found in UniFi Talk Application to exec…

Fix: 5.2.2+
Fix from $1,950 2026-07-02
Unifi Protect CRITICAL 9.9
CVE-2026-55115

A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to es…

Fix: 7.1.83+
Fix from $2,300 2026-07-02
Unifi Os Server HIGH 8.8
CVE-2026-54401

A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such…

Fix: after 5.1.15
Fix from $1,950 2026-07-02
Unclassified MEDIUM 6.4
CVE-2026-57681

Subscriber Server Side Request Forgery (SSRF) in GeoDirectory <= 2.8.161 versions.

Mitigation only
Fix from $1,600 2026-07-02
Unclassified HIGH 7.2
CVE-2026-57348

Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified MEDIUM 5.1
CVE-2026-54430

liboauth2 is vulnerable to Server-Side Request Forgery in oauth2_jose_jwks_aws_alb_resolve() function. The AWS ALB verifier reads both signer and kid…

Patch available
Fix from $1,600 2026-07-02
Unclassified HIGH 8.2
CVE-2026-14336

PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith(' https://ci.eclipse.org ') in is_issuer_known, pia…

Mitigation only
Fix from $1,950 2026-07-02
Unclassified MEDIUM 6.9
CVE-2026-55791

Craft CMS is a content management system (CMS). Versions 4.0.0-RC1 and above, prior to 4.18.0 and 5.0.0-RC1, and above, prior to 5.10.0, are vulnerab…

Patch available
Fix from $1,600 2026-07-02
Nemo Megatron Bridge HIGH 7.8
CVE-2026-24242

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause server-side request forgery. A successful exploit of this vul…

Fix: 0.4.1+
Fix from $1,950 2026-07-01
Unclassified CRITICAL 9.0
CVE-2026-13603

The payment integration pretix-oppwa provides support for the payment providers VR Payment, Hobex, and potentially others based on Oppwa's technolo…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified MEDIUM 5.0
CVE-2026-56399

Open WebUI before 0.6.27 contains a server-side request forgery vulnerability in the /api/v1/retrieval/process/web endpoint that allows authenticated…

Patch available
Fix from $1,600 2026-06-30
Websphere Extreme Scale CRITICAL 10.0
CVE-2026-13773

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.…

Fix: after 8.6.1.6
Fix from $2,300 2026-06-30
Websphere Application Server CRITICAL 9.8
CVE-2026-11714

IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.

Fix: 26.0.0.8+
Fix from $2,300 2026-06-30