Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Langflow MEDIUM 6.5
CVE-2026-10546

IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the URL component ( src/lfx/src/lfx/components/da…

Fix: after 1.9.3
Fix from $1,600 2026-06-30
Langflow HIGH 8.2
CVE-2026-10564

IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). The legacy RSSReaderComponent in rss.py and SearXNG component in …

Fix: after 1.9.6
Fix from $1,950 2026-06-30
Websphere Application Server CRITICAL 9.8
CVE-2026-11546

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-…

Fix: 26.0.0.8+
Fix from $2,300 2026-06-30
Langflow HIGH 8.5
CVE-2026-10129

IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) protection bypass vulnerability in the API Request component. An a…

Fix: after 1.9.3
Fix from $1,950 2026-06-30
Coldfusion HIGH 8.6
CVE-2026-48285

ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security fe…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified HIGH 8.5
CVE-2026-57947

Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint that allows authenticated users to r…

Mitigation only
Fix from $1,950 2026-06-29
Unclassified HIGH 8.6
CVE-2026-56285

Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded default HMAC key, allowing unauthen…

Patch available
Fix from $1,950 2026-06-29
Snowflake Cli CRITICAL 9.6
CVE-2026-13751

Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request forgery. The SQL statement reade…

Fix: 3.19.0+
Fix from $2,300 2026-06-29
Unclassified MEDIUM 6.3
CVE-2026-13540

A security flaw has been discovered in GitBucket up to 4.46.1. This affects the function Git.cloneRepository.setURI of the file src/main/scala/gitbuc…

Patch available
Fix from $1,600 2026-06-29
Kestra CRITICAL 10.0
CVE-2026-49869

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().…

Fix: 1.0.45 / 1.3.21+
Fix from $2,300 2026-06-26
Budibase HIGH 7.1
CVE-2026-54353

Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypass Budibase's SSRF blacklist t…

Fix: 3.39.9+
Fix from $1,950 2026-06-26
Unclassified HIGH 8.5
CVE-2026-56663

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.52, an authen…

Mitigation only
Fix from $1,950 2026-06-26
Lxd MEDIUM 5.0
CVE-2026-28385

In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import functionality allows authenticated…

Fix: after 6.9
Fix from $1,600 2026-06-26
Unclassified MEDIUM 6.4
CVE-2026-56026

Subscriber Server Side Request Forgery (SSRF) in utm.codes <= 1.9.0 versions.

Mitigation only
Fix from $1,600 2026-06-26
Mattermost Server MEDIUM 6.5
CVE-2026-4339

Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in…

Fix: 10.11.19 / 11.5.7+
Fix from $1,600 2026-06-26
Api Manager CRITICAL 10.0
CVE-2026-2053

The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled inpu…

Fix: 3.1.0.360 / 3.2.0.465+
Fix from $2,300 2026-06-26
Kubevirt MEDIUM 6.4
CVE-2026-13318

A server-side request forgery (SSRF) flaw was found in KubeVirt's virt-api port-forward handler. When processing a port-forward request to a VirtualM…

Fix: after 4.22.0
Fix from $1,600 2026-06-26
Build Of Apicurio Registry HIGH 7.4
CVE-2026-12992

A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.wsdl.importDocuments feature. W…

Fix: after 3.2
Fix from $1,950 2026-06-25
Unclassified HIGH 8.2
CVE-2026-12473

Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter without validation. A global aut…

Mitigation only
Fix from $1,950 2026-06-25
Unclassified HIGH 8.5
CVE-2026-56771

NewsBlur before version 14.5.0 contains a server-side request forgery vulnerability in the add_url endpoint that allows authenticated users to make a…

Patch available
Fix from $1,950 2026-06-25
Unclassified MEDIUM 6.4
CVE-2026-56779

MaxKB before 2.10.0 contains a server-side request forgery vulnerability in tool creation and update endpoints that allows authenticated users to mak…

Patch available
Fix from $1,600 2026-06-25
Unclassified HIGH 8.5
CVE-2026-56769

Huly Platform through 0.7.423, fixed in commit 68cbf8a contains an authenticated server-side request forgery vulnerability in the /import endpoint of…

Patch available
Fix from $1,950 2026-06-25
Unclassified HIGH 8.3
CVE-2026-55412

ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts…

Mitigation only
Fix from $1,950 2026-06-25
Librechat MEDIUM 6.5
CVE-2026-54033

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, LibreChat allows users to configure custom OpenAI-com…

Fix: after 0.8.3
Fix from $1,600 2026-06-25
Appsmith CRITICAL 9.1
CVE-2026-55455

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the outbound HTTP host filter applied by WebClientUtils (…

Fix: 2.1+
Fix from $2,300 2026-06-24
Appsmith HIGH 7.2
CVE-2026-50189

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, Appsmith's bundled supervisord exposes an XML-RPC interfa…

Fix: 2.1+
Fix from $1,950 2026-06-24
Unclassified HIGH 8.7
CVE-2026-52805

Gogs is an open source self-hosted Git service. Prior to 0.14.3, a Server-Side Request Forgery (SSRF) vulnerability exists in the repository migratio…

Patch available
Fix from $1,950 2026-06-24
Unclassified HIGH 8.3
CVE-2026-47267

Gogs is an open source self-hosted Git service. Prior to 0.14.3, the fix for CVE-2022-1285 prevents adding webooks or running webhooks with URLs with…

Patch available
Fix from $1,950 2026-06-24
Unclassified HIGH 8.7
CVE-2026-46348

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, the list of disallowed IP address ra…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 8.6
CVE-2026-47389

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, when using Ruby versions older than …

Mitigation only
Fix from $1,950 2026-06-24