Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Open Webui HIGH 8.5
CVE-2026-45331

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, validate_url() in backend/open_web…

Fix: 0.9.0+
Fix from $1,950 2026-05-15
Unclassified MEDIUM 5.7
CVE-2026-44520

Docling-Graph turns documents into validated Pydantic objects, then builds a directed knowledge graph with explicit semantic relationships. Prior to …

Mitigation only
Fix from $1,600 2026-05-14
Gotenberg MEDIUM 5.9
CVE-2026-42597

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the /forms/chromium/convert/url and /forms/chromium/screenshot/url routes…

Fix: 8.32.0+
Fix from $1,600 2026-05-14
Gotenberg HIGH 8.2
CVE-2026-42591

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the LibreOffice conversion endpoint (/forms/libreoffice/convert) passes u…

Fix: 8.32.0+
Fix from $1,950 2026-05-14
Gotenberg MEDIUM 5.3
CVE-2026-42592

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, FilterOutboundURL resolves the hostname, checks the resolved IPs against …

Fix: 8.32.0+
Fix from $1,600 2026-05-14
Gotenberg HIGH 8.6
CVE-2026-42595

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, Gotenberg's Chromium URL-to-PDF endpoint (/forms/chromium/convert/url) ha…

Fix: 8.32.0+
Fix from $1,950 2026-05-14
Gotenberg CRITICAL 9.4
CVE-2026-42596

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, the default deny-lists used by Gotenberg's downloadFrom feature and webho…

Fix: 8.31.0+
Fix from $2,300 2026-05-14
Magicmirror HIGH 8.6
CVE-2026-42281

MagicMirror² is an open source modular smart mirror platform. Prior to 2.36.0, an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in…

Fix: 2.36.0+
Fix from $1,950 2026-05-14
Unclassified HIGH 7.5
CVE-2026-6514

The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.1.2 via the popup_submit. This m…

Mitigation only
Fix from $1,950 2026-05-14
Playwright Capture HIGH 7.5
CVE-2026-44439

PlaywrightCapture is a simple replacement for splash using playwright. Prior to 1.39.6, PlaywrightCapture did not sufficiently restrict navigations a…

Fix: 1.39.6+
Fix from $1,950 2026-05-13
Unclassified MEDIUM 5.9
CVE-2026-8328

The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV ho…

Patch available
Fix from $1,600 2026-05-13
Unclassified MEDIUM 5.8
CVE-2026-44363

MISP modules are autonomous modules that can be used to extend MISP for new services. Prior to 3.0.7, an unsafe remote resource fetching vulnerabilit…

Patch available
Fix from $1,600 2026-05-13
Pan Os CRITICAL 9.1
CVE-2026-0258

A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attac…

Fix: 10.2.7 / 10.2.10+
Fix from $2,300 2026-05-13
Next.js HIGH 8.6
CVE-2026-44578EPSS 39%

Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the …

Fix: 15.5.16 / 16.2.5+
Fix from $1,950 2026-05-13
Curl HIGH 7.5
CVE-2026-5773

libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequen…

Fix: 8.20.0+
Fix from $1,950 2026-05-13
Nginx Ui CRITICAL 9.9
CVE-2026-44015

Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Server-Side Request Forgery (SSRF)…

Fix: after 2.3.4
Fix from $2,300 2026-05-12
Unclassified MEDIUM 5.0
CVE-2026-41195

mosparo is the modern solution to protect your online forms from spam. Prior to 1.4.13, the automatic rule package source URL feature allows a projec…

Mitigation only
Fix from $1,600 2026-05-12
Commerce HIGH 7.4
CVE-2026-34647

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a Server-Side Request Forgery (S…

Fix: 1.3.3 / 2.4.4+
Fix from $1,950 2026-05-12
Unclassified HIGH 8.2
CVE-2026-43929

ssrfcheck is a library that checks if a string contains a potential SSRF attack. In 1.3.0 and earlier, ssrfcheck fails to block Server-Side Request F…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified MEDIUM 6.5
CVE-2026-42175

requests-hardened is a library that overrides the default behaviors of the requests library, and adds new security features. Prior to , the SSRF prot…

Patch available
Fix from $1,600 2026-05-12
Unclassified HIGH 7.7
CVE-2026-42141

Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.1, an authenti…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified HIGH 8.2
CVE-2026-43993

JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the WAVS bridge's computeDataVerify called fetch() on agent-supp…

Patch available
Fix from $1,950 2026-05-12
Pandora Fms HIGH 8.8
CVE-2026-30810

Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pandora FMS: from 777 through 800

Fix: 777.17 / 802+
Fix from $1,950 2026-05-12
Unclassified HIGH 8.2
CVE-2026-42260

Open-WebSearch is a multi-engine MCP server, CLI, and local daemon for agent web search and content retrieval. Prior to 2.1.7, isPublicHttpUrl / asse…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified HIGH 8.7
CVE-2026-43897

Link Preview JS extracts web links information. Prior to 4.0.1, the library did not check for IPv6 loopback attacks. There was also a DNS attack, whe…

Patch available
Fix from $1,950 2026-05-11
Unclassified HIGH 7.7
CVE-2026-43884

WWBN AVideo is an open source video platform. In versions up to and including 29.0, two endpoints (plugin/AI/receiveAsync.json.php and objects/EpgPar…

Patch available
Fix from $1,950 2026-05-11
Unclassified MEDIUM 5.4
CVE-2026-43879

WWBN AVideo is an open source video platform. In versions up to and including 29.0, an authenticated user can configure their own donation-notificati…

Patch available
Fix from $1,600 2026-05-11
Unclassified CRITICAL 9.9
CVE-2026-42864

FireFighter is an incident management application. Prior to 0.0.54, the POST /api/v2/firefighter/raid/jira_bot endpoint (CreateJiraBotView) is reacha…

Mitigation only
Fix from $2,300 2026-05-11
Openclaw MEDIUM 5.0
CVE-2026-45000

OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy che…

Fix: 2026.4.20+
Fix from $1,600 2026-05-11
Flowise CRITICAL 9.8
CVE-2026-43995

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, multiple tool implementations directly impor…

Fix: 3.1.0+
Fix from $2,300 2026-05-11