Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Websphere Application Server CRITICAL 9.1
CVE-2026-9006

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an a…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-06-22
Watson Speech Services Cartridge MEDIUM 6.0
CVE-2026-7253

IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send specially crafted SQL stateme…

Fix: 5.3.1+
Fix from $1,600 2026-06-22
Unclassified MEDIUM 6.3
CVE-2026-12813

A vulnerability was detected in activepieces up to 0.83.0. This vulnerability affects the function handleUrlFile in the library packages/server/engin…

Mitigation only
Fix from $1,600 2026-06-21
Litellm MEDIUM 6.3
CVE-2026-12798

A weakness has been identified in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function load_openapi_spec_async of the file li…

Fix: after 1.82.2
Fix from $1,600 2026-06-21
Litellm MEDIUM 6.3
CVE-2026-12774

A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function _execute_with_mcp_client o…

Fix: after 1.82.2
Fix from $1,600 2026-06-21
Unclassified MEDIUM 6.8
CVE-2026-56342

AVideo through version 27.0 contains a server-side request forgery vulnerability in plugin/Live/test.php that allows authenticated administrators to …

Mitigation only
Fix from $1,600 2026-06-20
Unclassified MEDIUM 5.4
CVE-2026-56227

Capgo before 12.128.2 contains a server-side request forgery vulnerability in webhook URL validation that allows loopback and internal addresses. Org…

Mitigation only
Fix from $1,600 2026-06-20
Unclassified MEDIUM 5.3
CVE-2026-49345

Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, a Server-Side Request Forgery…

Mitigation only
Fix from $1,600 2026-06-19
Unclassified MEDIUM 6.3
CVE-2026-12726

A flaw was found in the AWX GitHub webhook integration. When processing GitHub pull_request webhooks, the controller stores the pull_request.statuses…

Mitigation only
Fix from $1,600 2026-06-19
Unclassified MEDIUM 6.5
CVE-2026-49359

PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/php-weasyprint` fetches the c…

Patch available
Fix from $1,600 2026-06-19
Unclassified MEDIUM 6.4
CVE-2026-4328

The Advanced Import plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.6. This is due to the…

Mitigation only
Fix from $1,600 2026-06-19
Unclassified MEDIUM 6.5
CVE-2026-11989

The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Server-Side Request…

Mitigation only
Fix from $1,600 2026-06-19
Open Webui HIGH 7.7
CVE-2026-54017

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the terminal-server reverse proxy …

Fix: 0.9.6+
Fix from $1,950 2026-06-18
Geoserver HIGH 8.2
CVE-2025-58175

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.27.3, a GeoServer that uses `E…

Fix: 2.26.4 / 2.27.3+
Fix from $1,950 2026-06-18
Unclassified HIGH 7.2
CVE-2026-11395

The CF7 to Webhook plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.0 via the pull_the_tri…

Mitigation only
Fix from $1,950 2026-06-18
Unclassified HIGH 8.2
CVE-2026-48764

TypeBot is a chatbot builder tool. In versions prior to 3.17.2, SSRF validation is implemented by resolving a hostname once and checking whether the …

Patch available
Fix from $1,950 2026-06-18
Starlette HIGH 7.5
CVE-2026-48818

Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \…

Fix: 1.1.0+
Fix from $1,950 2026-06-17
Pydantic Ai MEDIUM 6.8
CVE-2026-48782

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.56.0 through 1.101.0, 2.0.0b1, and …

Fix: 1.102.0+
Fix from $1,600 2026-06-17
Openclaw MEDIUM 6.5
CVE-2026-53859

OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparisons using trailing-dot notation…

Fix: 2026.5.26+
Fix from $1,600 2026-06-16
Unclassified HIGH 7.7
CVE-2026-47684

Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.3.0, the private IP blockl…

Mitigation only
Fix from $1,950 2026-06-16
Unclassified CRITICAL 9.1
CVE-2026-50887

A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internal resourc…

Mitigation only
Fix from $2,300 2026-06-15
Unclassified HIGH 8.1
CVE-2026-50888

An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Benjamin Jonard Koillection v1.8.0 allows attackers …

Mitigation only
Fix from $1,950 2026-06-15
Unclassified MEDIUM 6.3
CVE-2026-12210

A vulnerability was detected in universal-tool-calling-protocol python-utcp 1.1.0. This affects an unknown function of the component utcp-gql/utcp-we…

Mitigation only
Fix from $1,600 2026-06-15
Openclaw MEDIUM 6.5
CVE-2026-53827

OpenClaw before 2026.5.2 contains a credential exposure vulnerability in message.action forwarding that allows model-controlled metadata to forward a…

Fix: 2026.5.2+
Fix from $1,600 2026-06-12
Unclassified MEDIUM 6.4
CVE-2026-47268

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 0.20.0 to before version 2.0.10, an auth…

Mitigation only
Fix from $1,600 2026-06-12
Unclassified HIGH 7.7
CVE-2026-46717

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, nezha's d…

Mitigation only
Fix from $1,950 2026-06-12
Unclassified HIGH 7.6
CVE-2026-45012

ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 contain an authenticated server-side request f…

Mitigation only
Fix from $1,950 2026-06-12
Unclassified MEDIUM 6.3
CVE-2026-50552

Koel is a free, open-source music streaming solution. Prior to version 9.7.1, Koel contains a Server-Side Request Forgery (SSRF) vulnerability in the…

Patch available
Fix from $1,600 2026-06-12
Unclassified HIGH 7.7
CVE-2026-47260

Koel is a free, open-source music streaming solution. Prior to version 9.3.5, Koel validates the podcast feed URL via the SafeUrl rule (DNS resolutio…

Patch available
Fix from $1,950 2026-06-12
Openclaw HIGH 7.7
CVE-2026-53812

OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows authenticated users to bypass private-n…

Fix: 2026.5.18+
Fix from $1,950 2026-06-11