Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Openedx CRITICAL 9.9
CVE-2026-42858

Open edX Platform enables the authoring and delivery of online learning at any scale. The sync_provider_data endpoint in SAMLProviderDataViewSet allo…

Fix: 2026-04-24+
Fix from $2,300 2026-05-11
Edx Enterprise HIGH 8.5
CVE-2026-42860

The Open edx Enterprise Service app provides enterprise features to the Open edX platform. From 7.0.2 to 7.0.4, the sync_provider_data endpoint in SA…

Fix: 7.0.5+
Fix from $1,950 2026-05-11
Pyload Ng HIGH 8.3
CVE-2026-42313

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SE…

Fix: 0.5.0b3.dev100+
Fix from $1,950 2026-05-11
Unclassified MEDIUM 5.1
CVE-2026-3048

An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be ab…

Mitigation only
Fix from $1,600 2026-05-11
Mlflow HIGH 7.1
CVE-2026-2393

A Server-Side Request Forgery (SSRF) vulnerability exists in MLflow versions prior to 3.9.0. The `_create_webhook()` function in `mlflow/server/handl…

Fix: 3.9.0+
Fix from $1,950 2026-05-11
Unclassified MEDIUM 6.3
CVE-2026-8193

A weakness has been identified in Akaunting 3.1.21. This issue affects some unknown processing of the file config/dompdf.php of the component Invoice…

Mitigation only
Fix from $1,600 2026-05-09
Unclassified CRITICAL 9.1
CVE-2026-44313

Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. Prior to version 2.13.0, a Server-…

Mitigation only
Fix from $2,300 2026-05-09
Unclassified MEDIUM 6.3
CVE-2026-44284

FastGPT is an AI Agent building platform. Prior to version 4.14.17, FastGPT had an inconsistent SSRF protection gap in MCP tool URL handling. The dir…

Patch available
Fix from $1,600 2026-05-08
Unclassified HIGH 8.6
CVE-2026-42352

pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23.3, OGC API process executio…

Patch available
Fix from $1,950 2026-05-08
Unclassified HIGH 7.7
CVE-2026-42345

FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packages/service/common/system/uti…

Mitigation only
Fix from $1,950 2026-05-08
Unclassified MEDIUM 6.5
CVE-2026-42346

Postiz is an AI social media scheduling tool. From version 2.16.6 to before version 2.21.7, all SSRF protections added in v2.21.4–v2.21.6 share a fun…

Patch available
Fix from $1,600 2026-05-08
New Api HIGH 7.1
CVE-2026-42339

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. In versions 0.11.9-alpha.1 and prior, the SS…

Fix: 0.11.9+
Fix from $1,950 2026-05-08
Unclassified MEDIUM 6.9
CVE-2026-41682

pupnp is an SDK for development of UPnP device and control point applications. Prior to version 1.18.5, pupnp is vulnerable to SRRF port confusion du…

Patch available
Fix from $1,600 2026-05-08
Unclassified MEDIUM 5.1
CVE-2026-42213

SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, th…

Patch available
Fix from $1,600 2026-05-08
Unclassified MEDIUM 6.3
CVE-2026-42180

Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy allows an authenticated low-privileged user to create a link …

No fix yet
Fix from $1,600 2026-05-08
Unclassified MEDIUM 6.5
CVE-2026-42181

Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy fetches metadata for user-supplied post URLs and, under the d…

Mitigation only
Fix from $1,600 2026-05-08
N8n Mcp CRITICAL 9.1
CVE-2026-44694

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. From version 2.18.7 to before vers…

Fix: 2.50.2+
Fix from $2,300 2026-05-08
Unclassified HIGH 8.2
CVE-2026-42353

i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Prior to version 3.9.3, i18…

Mitigation only
Fix from $1,950 2026-05-08
Praisonaiagents CRITICAL 9.8
CVE-2026-44335

PraisonAI is a multi-agent teams system. Prior to version 1.6.32, the URL checking logic in PraisonAI has a logical flaw that could be bypassed by at…

Fix: 1.6.32+
Fix from $2,300 2026-05-08
Angular MEDIUM 5.3
CVE-2026-41423

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions…

Fix: 19.2.21 / 20.3.19+
Fix from $1,600 2026-05-08
Prompthub HIGH 7.1
CVE-2026-42261

PromptHub is an all-in-one AI toolbox for prompt, skill, and agent management. From version 0.4.9 to before version 0.5.4, apps/web/src/routes/skills…

Fix: 0.5.4+
Fix from $1,950 2026-05-08
Enterprise Server CRITICAL 9.8
CVE-2026-8034

A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access …

Fix: 3.16.18 / 3.17.15+
Fix from $2,300 2026-05-07
Azure Monitor Action Group Notification System HIGH 8.1
CVE-2026-41105

Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2026-05-07
N8n Mcp HIGH 8.5
CVE-2026-42449

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. In versions 2.47.4 through 2.47.13…

Fix: 2.47.14+
Fix from $1,950 2026-05-07
Unclassified HIGH 7.7
CVE-2026-41905

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, Helper::sanitizeRemoteUrl() in app/Misc/…

Mitigation only
Fix from $1,950 2026-05-07
Cliproxyapi MEDIUM 6.3
CVE-2026-8081

A vulnerability has been found in router-for-me CLIProxyAPI 6.9.29. Affected by this issue is some unknown functionality of the file internal/api/han…

Mitigation only
Fix from $1,600 2026-05-07
Unclassified HIGH 7.7
CVE-2026-41688

Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the incomplete SSRF fix in Wallos validates webho…

Patch available
Fix from $1,950 2026-05-07
Unclassified MEDIUM 6.0
CVE-2026-41689

Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the webhook notification feature reuses an admini…

Mitigation only
Fix from $1,600 2026-05-07
Weblate HIGH 8.1
CVE-2026-41654

Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS …

Fix: 5.17.1+
Fix from $1,950 2026-05-07
Monetr HIGH 7.1
CVE-2026-41644

monetr is a budgeting application for recurring expenses. Prior to version 1.12.5, a server-side request forgery (SSRF) vulnerability in monetr's Lun…

Fix: 1.12.5+
Fix from $1,950 2026-05-07