Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Unclassified HIGH 7.4
CVE-2026-53782

Summarize before 0.17.0 contains a server-side request forgery vulnerability that allows attackers who control a podcast RSS feed to direct the host …

Patch available
Fix from $1,950 2026-06-11
Unclassified HIGH 7.7
CVE-2026-47170

Garlic-Hub manages digital signage network — devices, content, and playlists — from a single self-hosted interface. Prior to version 1.1, authenticat…

Patch available
Fix from $1,950 2026-06-11
Unclassified MEDIUM 5.3
CVE-2026-46698

Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.9, Fediverse Embeds registered the unauthenticated AJAX action wp_aj…

Patch available
Fix from $1,600 2026-06-11
Unclassified MEDIUM 6.5
CVE-2026-47157

aiograpi is an asynchronous Instagram API for Python. aiograpi versions before 0.9.10 accepted server-supplied signup challenge paths and used them t…

Patch available
Fix from $1,600 2026-06-11
Unclassified HIGH 7.5
CVE-2026-46697

Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.8, Fediverse Embeds registered an unauthenticated REST route ftf/med…

Patch available
Fix from $1,950 2026-06-11
Axios HIGH 8.6
CVE-2026-44492

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. Wh…

Fix: 0.32.0 / 1.16.0+
Fix from $1,950 2026-06-11
Langflow Desktop MEDIUM 5.4
CVE-2026-3341

IBM Langflow Desktop 1.0.0 through 1.9.2 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker t…

Fix: 1.9.3+
Fix from $1,600 2026-06-11
Psr 7 MEDIUM 5.3
CVE-2026-48998

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host header validation when parsing …

Fix: 2.10.2+
Fix from $1,600 2026-06-11
GitLab MEDIUM 6.5
CVE-2026-9204

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that un…

Fix: 18.10.8 / 18.11.5+
Fix from $1,600 2026-06-11
Unclassified HIGH 8.6
CVE-2026-40999

When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebService…

Mitigation only
Fix from $1,950 2026-06-11
Unclassified HIGH 8.6
CVE-2026-50131

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Fedify previously addressed SSRF/internal network access in…

No fix yet
Fix from $1,950 2026-06-10
Unclassified MEDIUM 6.9
CVE-2026-46683

Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.0, there is a SSRF and local f…

Mitigation only
Fix from $1,600 2026-06-10
Unclassified MEDIUM 5.9
CVE-2026-50127

Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_RESTRICT_PRIVATE did not properly account for som…

Patch available
Fix from $1,600 2026-06-10
Splunk HIGH 7.6
CVE-2026-20252

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.4.2604.3, 10.3.2512.12, 10.2.2510…

Fix: 9.3.13 / 9.3.2411.132+
Fix from $1,950 2026-06-10
Erlang\/inets MEDIUM 6.5
CVE-2026-48858

Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ftp_internal module) allows FTP bounce attacks and SSRF via an unvalidated PASV r…

Fix: 1.2.3.1 / 1.2.4.1+
Fix from $1,600 2026-06-10
Unclassified MEDIUM 6.5
CVE-2026-45561

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the /smon/agent/{version,uptime…

Mitigation only
Fix from $1,600 2026-06-10
Campaign CRITICAL 10.0
CVE-2026-47938

Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could resu…

Fix: after 7.4.2
Fix from $2,300 2026-06-09
Exchange Server MEDIUM 5.0
CVE-2026-45502EPSS 20%

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

Fix: 15.02.2562.043+
Fix from $1,600 2026-06-09
Exchange Server MEDIUM 6.5
CVE-2026-45503

Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

Fix: 15.02.2562.043+
Fix from $1,600 2026-06-09
Exchange Server HIGH 8.8
CVE-2026-45504

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Fix: 15.02.2562.043+
Fix from $1,950 2026-06-09
Exchange Server MEDIUM 6.1
CVE-2026-45501

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

Fix: 15.02.2562.043+
Fix from $1,600 2026-06-09
Spring Framework MEDIUM 6.5
CVE-2026-41854

Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed …

Fix: 6.2.18.1 / 7.0.7.1+
Fix from $1,600 2026-06-09
Unclassified HIGH 7.3
CVE-2026-11437

A flaw has been found in perfree go-fastdfs-web up to 1.3.7. Affected is the function checkServer of the file /install/checkServer of the component I…

Mitigation only
Fix from $1,950 2026-06-06
Unclassified HIGH 8.3
CVE-2026-11424

A server-side request forgery (SSRF) vulnerability exists in a GraphQL service component shared by Altium Enterprise Server and Altium 365. An authen…

Mitigation only
Fix from $1,950 2026-06-05
Unclassified HIGH 8.7
CVE-2026-46391

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 9.0.1 and prior to version 26.0.0 of @haxtheweb/open-apis, m…

Mitigation only
Fix from $1,950 2026-06-05
Unclassified HIGH 7.1
CVE-2026-46393

HAX CMS helps manage microsite universe with PHP or NodeJs backends. An authenticated Server-Side Request Forgery (SSRF) vulnerability in versions pr…

Mitigation only
Fix from $1,950 2026-06-05
Unclassified MEDIUM 5.3
CVE-2026-11346

A Server-Side Request Forgery (SSRF) vulnerability in the custom process creation feature of linqi allows an authenticated attacker to probe internal…

Mitigation only
Fix from $1,600 2026-06-05
Unclassified HIGH 7.2
CVE-2026-10586

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in al…

Mitigation only
Fix from $1,950 2026-06-05
Unclassified CRITICAL 9.9
CVE-2026-43986

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose a public `/image/<hash>` route that re…

Mitigation only
Fix from $2,300 2026-06-04
Unclassified HIGH 7.3
CVE-2026-10771

A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-common/src/main/java/com/zbkj…

Mitigation only
Fix from $1,950 2026-06-03