Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Kibana HIGH 7.7
CVE-2026-49093

Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configure…

Fix: 9.3.3+
Fix from $1,950 2026-05-28
Kibana HIGH 7.7
CVE-2026-42398

Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured con…

Fix: 9.2.8 / 9.3.2+
Fix from $1,950 2026-05-28
Unclassified MEDIUM 5.8
CVE-2026-49129

Music Player Daemon (MPD) before version 0.24.11 contains a server-side request forgery vulnerability in CurlInputPlugin where CURLOPT_FOLLOWLOCATION…

Patch available
Fix from $1,600 2026-05-28
Unclassified MEDIUM 5.0
CVE-2026-46526

Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.10, the URL checking logic in local-deep-research …

Patch available
Fix from $1,600 2026-05-28
Unclassified MEDIUM 5.0
CVE-2026-43979

Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.0, PDFService._markdown_to_html() constructs an HT…

Patch available
Fix from $1,600 2026-05-28
Unclassified MEDIUM 5.0
CVE-2026-46561

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the PREREQFUNCTION-based private IP check was not appli…

Mitigation only
Fix from $1,600 2026-05-28
Unclassified HIGH 7.4
CVE-2026-45310

CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.22, the fetch_url tool validates the initial URL's resolved IP address against …

Mitigation only
Fix from $1,950 2026-05-28
Unclassified HIGH 7.4
CVE-2026-45373

CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, although SSRF is validated against hostnames that resolve to private IPv6 a…

Mitigation only
Fix from $1,950 2026-05-28
Nautobot HIGH 8.5
CVE-2026-44797

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot's Webhook data model and associated featur…

Fix: 2.4.33 / 3.1.2+
Fix from $1,950 2026-05-28
Flowintel CRITICAL 9.9
CVE-2026-9813

FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL probe functionality in app/ca…

Fix: 3.3.0+
Fix from $2,300 2026-05-28
Unclassified MEDIUM 6.5
CVE-2026-5737

The Independent Analytics plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.14.9. This is due…

Mitigation only
Fix from $1,600 2026-05-28
Unclassified MEDIUM 5.3
CVE-2026-48148

Budibase is an open-source low-code platform. Prior to 3.35.3, the VectorDB configuration endpoint in Budibase accepts a host parameter that undergo…

No fix yet
Fix from $1,600 2026-05-27
Unclassified HIGH 8.5
CVE-2026-48153

Budibase is an open-source low-code platform. Prior to 3.39.0, fetchToken in the OAuth2 SDK makes a POST to a builder-supplied URL with plain node-fe…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified MEDIUM 5.1
CVE-2026-48128

Budibase is an open-source low-code platform. Prior to 3.39.0, the executeQuery automation step in Budibase accepts a queryId from automation step in…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified HIGH 7.7
CVE-2026-48146

Budibase is an open-source low-code platform. Prior to 3.39.0, the OAuth2 token fetch function in packages/server/src/sdk/workspace/oauth2/utils.ts u…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.7
CVE-2026-45548

Budibase is an open-source low-code platform. Prior to 3.34.8, the processUrlFile function in packages/server/src/automations/steps/ai/extract.ts use…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.7
CVE-2026-45715

Budibase is an open-source low-code platform. Prior to 3.38.1, the REST datasource integration (packages/server/src/integrations/rest.ts) follows HTT…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.7
CVE-2026-45061

Budibase is an open-source low-code platform. Prior to 3.35.10, the Plugin URL upload endpoint (POST /api/plugin) validates the submitted URL with a …

Mitigation only
Fix from $1,950 2026-05-27
Ldap MEDIUM 6.6
CVE-2026-48916

Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals.

Fix: after 793.v754d6b_41b_ea_4
Fix from $1,600 2026-05-27
Active Directory MEDIUM 6.6
CVE-2026-48918

Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default.

Fix: after 2.41
Fix from $1,600 2026-05-27
Unclassified HIGH 8.2
CVE-2026-44971

GuardDog is a CLI tool to identify malicious PyPI packages. From 1.0.0 to 2.9.0, the programmatic remote project scanning path rewrites attacker-cont…

Mitigation only
Fix from $1,950 2026-05-27
Tauri HIGH 8.8
CVE-2026-42184

Tauri is a framework for building binaries for all major desktop platforms. From 2.0 to 2.11.0, a flaw in Tauri's is_local_url() function causes it t…

Fix: 2.10.3+
Fix from $1,950 2026-05-27
Enterprise Server HIGH 8.2
CVE-2026-9312EPSS 7%

A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafte…

Fix: 3.16.19 / 3.17.16+
Fix from $1,950 2026-05-27
Enterprise Server MEDIUM 5.9
CVE-2026-8606

A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause the server to issue H…

Fix: 3.16.19 / 3.17.16+
Fix from $1,600 2026-05-27
Dozzle HIGH 8.6
CVE-2026-45298

Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (the documented quickstart, no DOZZLE_AUTH_PROVIDE…

Fix: 10.5.2+
Fix from $1,950 2026-05-26
Unclassified MEDIUM 6.3
CVE-2026-45412

MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, SSRF via work_flow_template Import. Authenticated users can supply arbitrary URL…

Mitigation only
Fix from $1,600 2026-05-26
Unclassified MEDIUM 6.3
CVE-2026-42335

MaxKB is an open-source AI assistant for enterprise. Prior to 2.8.1, MaxKB v2.8.0 and prior are vulnerable to a server-side request forgery (SSRF) by…

Mitigation only
Fix from $1,600 2026-05-26
Unclassified MEDIUM 5.1
CVE-2026-42336

MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a server-side request forgery (SSRF) bypass in the OSS f…

Mitigation only
Fix from $1,600 2026-05-26
Unclassified CRITICAL 9.2
CVE-2026-2264

A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and ex…

Mitigation only
Fix from $2,300 2026-05-26
Webmethods Integration Server MEDIUM 5.4
CVE-2025-14290

IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM webMethods Integration is vu…

Mitigation only
Fix from $1,600 2026-05-26