Vulnerability index

Browse CVEs

2,810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Unclassified MEDIUM 6.3
CVE-2026-74842

A vulnerability was found in Kira-Pgr PromptShopMCP up to 5bc0cd17358e19a5415d11a531088170d7b81452. Affected is the function download_image of the fi…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified MEDIUM 5.9
CVE-2026-13700

The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side request and attaches stored third-part…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.3
CVE-2026-19984

A flaw has been found in jkawamoto mcp-florence2 up to 0.3.13. Affected by this issue is the function get_images of the file src/mcp_florence2/__init…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.3
CVE-2026-19957

A vulnerability was identified in graphlit graphlit-mcp-server 1.0.1. This affects the function fetch of the file src/tools.ts of the component ssrf-…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.3
CVE-2026-19956

A vulnerability has been found in gomarble-ai facebook-ads-mcp-server 0.1.0. The impacted element is the function fetch_pagination_url of the file se…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 5.8
CVE-2026-73058

stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blocklist, allowing unauthenticated attackers to bypass …

No fix yet
Fix from $4,000 2026-08-16
Unclassified HIGH 8.8
CVE-2026-17123

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form …

No fix yet
Fix from $4,900 2026-08-16
Unclassified MEDIUM 6.3
CVE-2026-19927

A vulnerability was found in OpenBoxes up to 0.9.7. The impacted element is the function Upload of the file grails-app/controllers/org/pih/warehouse/…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 5.3
CVE-2026-73845

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in s…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 6.7
CVE-2026-46380

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSFetcher._do_fetch() method pas…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 5.3
CVE-2026-19770

A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is the function downloadReport of the file src/smadex-…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 6.3
CVE-2026-19765

A security flaw has been discovered in eyaushev swagger-testcase-mcp 5babb27c951fb404bc2b25ec80593616e49054e5. This vulnerability affects the functio…

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 7.3
CVE-2026-19753

A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of the file src/mcp-rdf-explorer/…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.5
CVE-2026-72855

Budibase before 3.40.0 contains server-side request forgery vulnerabilities in OpenAPI query import and REST query execution that allow authenticated…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.3
CVE-2026-19751

A flaw has been found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82. The affected element is the function axios.g…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.3
CVE-2026-19752

A vulnerability was found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82. This affects the function parse-pdf of t…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 7.7
CVE-2026-73530

Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that allows attackers to reach internal services by suppl…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.6
CVE-2026-72777

Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation th…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.5
CVE-2026-59765

SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.3
CVE-2026-58441

SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-58442

Repository migration SSRF via multi-answer DNS allow-list bypass

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 7.7
CVE-2026-58314

Two SSRF findings in Gitea 1.26.2

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.5
CVE-2026-57894

Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.4
CVE-2026-49857

auth-fetch-mcp is an MCP server that lets AI assistants fetch content from authenticated web pages. Version 3.0.1 implements SSRF protection in `asse…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.2
CVE-2026-66704

Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions.

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.0
CVE-2026-66654

Subscriber Server Side Request Forgery (SSRF) in Vehica Core <= 1.0.104 versions.

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 8.7
CVE-2026-49478

Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly foll…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.5
CVE-2026-73629

Serendipity before 2.6.0 contains a server-side request forgery vulnerability in the serendipity_url_allowed() filter that fails to block hex-encoded…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.7
CVE-2026-46382

The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, a user-supplied private/local U…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.1
CVE-2026-18952

Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user …

No fix yet
Fix from $4,900 2026-08-12