Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Koha MEDIUM 6.5
CVE-2026-26379

Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configuration. This allows authenticat…

Fix: after 25.11.00
Fix from $1,600 2026-06-03
Unified Communications Manager HIGH 8.6
CVE-2026-20230 KEVEPSS 83%

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM …

Fix: 14su6+
Fix from $1,950 2026-06-03
Unclassified MEDIUM 6.3
CVE-2026-10690

A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of the file src/tools/filesystem…

Patch available
Fix from $1,600 2026-06-03
Unclassified MEDIUM 6.3
CVE-2026-10662

A vulnerability was found in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. The affected element is the function requests.get o…

Patch available
Fix from $1,600 2026-06-02
Unclassified HIGH 8.5
CVE-2026-49120

Medplum before 5.1.14 contains a server-side request forgery vulnerability in the subscription worker that allows authenticated users to perform unau…

Patch available
Fix from $1,950 2026-06-02
Unclassified MEDIUM 6.3
CVE-2026-10581

A flaw has been found in DedeCMS 5.7.88. Affected by this vulnerability is the function base64_decode of the file /plus/download.php?open=1. This man…

Mitigation only
Fix from $1,600 2026-06-02
Unclassified MEDIUM 5.0
CVE-2026-49138

Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the web_fetch tool that allows remote attackers to reach inter…

Patch available
Fix from $1,600 2026-06-01
Unclassified HIGH 7.0
CVE-2026-49139

Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handler that allows remote attacke…

Patch available
Fix from $1,950 2026-06-01
Unclassified HIGH 7.3
CVE-2026-10287

A vulnerability was determined in SourceCodester SEO Meta Tag Extractor 1.0. This vulnerability affects the function get_headers of the file /index.p…

Mitigation only
Fix from $1,950 2026-06-01
Unclassified MEDIUM 6.3
CVE-2026-10276

A vulnerability has been found in hekmon8 Jenkins-server-mcp 0.1.0. This vulnerability affects the function jobPath of the file src/index.ts of the c…

Mitigation only
Fix from $1,600 2026-06-01
Unclassified HIGH 7.3
CVE-2026-10280

A security flaw has been discovered in horizon921 mcpilot 0.1.0. The impacted element is an unknown function of the file client/src/app/api/mcp/call/…

Mitigation only
Fix from $1,950 2026-06-01
Unclassified MEDIUM 6.3
CVE-2026-10274

A vulnerability was determined in indrasishbanerjee aem-mcp-server up to b5f833aef9b5dfd17a5991b3b18a8a11edbdc583. This impacts the function getAsset…

Mitigation only
Fix from $1,600 2026-06-01
Fesod MEDIUM 5.3
CVE-2026-49328

Server-Side Request Forgery (SSRF) in the UrlImageConverter component of Apache Fesod (Incubating) fesod-sheet before 2.0.2-incubating allows attacke…

Fix: 2.0.2+
Fix from $1,600 2026-06-01
Unclassified MEDIUM 5.8
CVE-2026-10517

A flaw was found in Clair. The fetcher component makes outbound HTTP requests to attacker-supplied URIs from manifest layer descriptors without IP or…

Mitigation only
Fix from $1,600 2026-06-01
Unclassified MEDIUM 6.3
CVE-2026-10239

A vulnerability was determined in JeecgBoot up to 3.9.2. The affected element is the function WordUtil.addImage of the file /airag/word/edit. Executi…

Mitigation only
Fix from $1,600 2026-06-01
Unclassified MEDIUM 6.3
CVE-2026-10240

A vulnerability was identified in JeecgBoot up to 3.9.2. The impacted element is an unknown function of the file /airag/airagModel/test. The manipula…

Mitigation only
Fix from $1,600 2026-06-01
Unclassified MEDIUM 6.3
CVE-2026-10241

A security flaw has been discovered in jeecgboot The server processes these URLs up to 3.9.1. This affects the function FileDownloadUtils.download2Di…

Mitigation only
Fix from $1,600 2026-06-01
Unclassified MEDIUM 6.3
CVE-2026-10177

A security vulnerability has been detected in Aider-AI Aider 0.86.3. This affects the function requests.get of the file api_docs.py of the component …

Patch available
Fix from $1,600 2026-05-31
Unclassified HIGH 7.4
CVE-2026-48555

Spatie Laravel Media Library before version 11.23.0 contains a server-side request forgery vulnerability that allows remote attackers to cause the se…

Patch available
Fix from $1,950 2026-05-29
Unclassified HIGH 7.7
CVE-2026-44285

FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker …

Mitigation only
Fix from $1,950 2026-05-29
Teamcity HIGH 7.5
CVE-2026-49372

In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible

Fix: 2025.11.5+
Fix from $1,950 2026-05-29
Unclassified MEDIUM 6.9
CVE-2026-44652

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines,…

Mitigation only
Fix from $1,600 2026-05-29
Unclassified HIGH 8.5
CVE-2026-46372

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines,…

Mitigation only
Fix from $1,950 2026-05-29
Unclassified MEDIUM 5.4
CVE-2026-45660

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.22 and 6.18.1, the Glide image proxy's URL validation could be b…

Mitigation only
Fix from $1,600 2026-05-29
Unclassified HIGH 7.7
CVE-2026-10107

MoviePilot v2 contains a server-side request forgery vulnerability in the image proxy endpoint that allows authenticated attackers to request arbitra…

Patch available
Fix from $1,950 2026-05-29
Unclassified HIGH 7.3
CVE-2026-10068

A flaw has been found in Shibby Tomato 1.28. The affected element is the function send of the file usr/sbin/miniupnpd of the component SUBSCRIBE Call…

Mitigation only
Fix from $1,950 2026-05-29
Mcp Security MEDIUM 6.5
CVE-2026-45609

mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mcp-security framework fails to…

Fix: 0.1.9+
Fix from $1,600 2026-05-29
Avideo MEDIUM 6.5
CVE-2026-45619

WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveAsync.json.php, and other locations do not use the…

Fix: after 29.0
Fix from $1,600 2026-05-29
Unclassified MEDIUM 6.4
CVE-2026-9557

A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authe…

Mitigation only
Fix from $1,600 2026-05-29
Openshift Container Platform MEDIUM 6.5
CVE-2026-42965

A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQ…

Mitigation only
Fix from $1,600 2026-05-29