Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Flink Kubernetes Operator MEDIUM 6.5
CVE-2026-40564

Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator. The Flink…

Fix: 1.15.0+
Fix from $1,600 2026-05-26
Unclassified HIGH 7.6
CVE-2026-45082

Karakeep is a elf-hostable bookmark-everything app. A Server-Side Request Forgery (SSRF) protection bypass vulnerability was identified in versions p…

Mitigation only
Fix from $1,950 2026-05-26
Shiro MEDIUM 5.4
CVE-2026-44598

With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vulnerability in Apache Shiro. …

Fix: 2.1.1+
Fix from $1,600 2026-05-25
Unclassified HIGH 7.2
CVE-2026-48843

Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail me…

Patch available
Fix from $1,950 2026-05-25
Hackney MEDIUM 6.5
CVE-2026-47076

Interpretation Conflict vulnerability in benoitc hackney allows Server Side Request Forgery. hackney_url:normalize/2 URL-decodes the host component a…

Fix: 4.0.1+
Fix from $1,600 2026-05-25
Unclassified HIGH 7.3
CVE-2026-9372

A flaw has been found in ItzCrazyKns Vane up to 1.12.1. This vulnerability affects unknown code of the file src/app/api/providers/route.ts of the com…

Mitigation only
Fix from $1,950 2026-05-24
Unclassified MEDIUM 5.0
CVE-2026-9304

A security flaw has been discovered in calcom cal.diy up to 4.9.4. The affected element is the function validateUrlForSSRF of the file apps/web/app/a…

Mitigation only
Fix from $1,600 2026-05-23
Unclassified HIGH 7.7
CVE-2026-39965

TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain an SSRF via Open Redirect Bypass as the HTTP Request block and Code block valida…

Mitigation only
Fix from $1,950 2026-05-22
Unclassified CRITICAL 10.0
CVE-2026-33712

Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typebotId}/preview/startChat) allo…

Mitigation only
Fix from $2,300 2026-05-22
Unclassified HIGH 7.6
CVE-2026-34207

TypeBot is a chatbot builder tool. In versions prior to 3.16.0, SSRF protection for Webhook / HTTP Request blocks validates only the URL string, bloc…

Patch available
Fix from $1,950 2026-05-22
Devolutions Server HIGH 7.1
CVE-2026-7325

Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authenticated user to obtain authentica…

Fix: 2025.3.22.0 / 2026.1.19.0+
Fix from $1,950 2026-05-22
Unclassified MEDIUM 5.4
CVE-2026-7798

The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin for WordPress is vulnerable to…

No fix yet
Fix from $1,600 2026-05-22
Concrete Cms MEDIUM 6.4
CVE-2026-7890

In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation enabli…

Fix: 9.5.1+
Fix from $1,600 2026-05-21
Unclassified MEDIUM 5.4
CVE-2026-6394

The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) …

Mitigation only
Fix from $1,600 2026-05-20
Faraday MEDIUM 6.5
CVE-2026-33637

Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Versions 2.0.0 through 2.14.1 still allow pr…

Fix: 2.14.2+
Fix from $1,600 2026-05-19
Terrascan HIGH 8.6
CVE-2026-47358

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running i…

Fix: after 1.18.3
Fix from $1,950 2026-05-19
Terrascan HIGH 8.6
CVE-2026-47356

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file scan endpoint (POST /v1/{i…

Fix: after 1.18.3
Fix from $1,950 2026-05-19
Terrascan HIGH 8.6
CVE-2026-47357

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (…

Fix: after 1.18.3
Fix from $1,950 2026-05-19
Unclassified CRITICAL 9.8
CVE-2026-30118

scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SSRF) in the scalar_url query parameter of the Scalar Proxy endpoint. T…

Mitigation only
Fix from $2,300 2026-05-19
Ofbiz HIGH 7.5
CVE-2026-31910

Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrad…

Fix: 24.09.06+
Fix from $1,950 2026-05-19
Ofbiz HIGH 7.3
CVE-2026-29226

Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations. This issue affects Apache OFBiz: before 24.09.06.…

Fix: 24.09.06+
Fix from $1,950 2026-05-19
Unclassified MEDIUM 5.0
CVE-2026-33234

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions 0.1.0 through …

Mitigation only
Fix from $1,600 2026-05-19
Summarize HIGH 7.4
CVE-2026-45245

Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch synthetic mouseover events ov…

Fix: 0.15.1+
Fix from $1,950 2026-05-18
Mattermost Server MEDIUM 5.0
CVE-2026-6333

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate the Host header when constructing response URLs for custom slash commands …

Fix: 10.11.14 / 11.5.2+
Fix from $1,600 2026-05-18
Ai HIGH 7.3
CVE-2026-8768

A vulnerability was found in vercel ai up to 3.0.97. The affected element is the function validateDownloadUrl of the file packages/provider-utils/src…

Fix: after 3.0.97
Fix from $1,950 2026-05-17
Unclassified HIGH 7.3
CVE-2026-8725

A weakness has been identified in CoreWorxLab CAAL up to 1.6.0. The affected element is an unknown function of the file src/caal/webhooks.py of the c…

Mitigation only
Fix from $1,950 2026-05-17
Open Webui MEDIUM 5.4
CVE-2026-45347

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.5.11, there is a blind server side requ…

Fix: 0.5.11+
Fix from $1,600 2026-05-15
Open Webui HIGH 7.7
CVE-2026-45338

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, a Server-Side Request Forgery (SSR…

Fix: 0.9.0+
Fix from $1,950 2026-05-15
Open Webui HIGH 8.5
CVE-2026-45400

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, a parsing difference between the u…

Fix: 0.9.5+
Fix from $1,950 2026-05-15
Open Webui HIGH 8.5
CVE-2026-45401

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the validate_url() function in bac…

Fix: 0.9.5+
Fix from $1,950 2026-05-15