Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Unclassified MEDIUM 6.3
CVE-2026-7305

A weakness has been identified in Xuxueli xxl-job up to 3.3.2. The affected element is the function triggerJob of the file xxl-job-admin/src/main/jav…

Patch available
Fix from $1,600 2026-04-28
Unclassified MEDIUM 6.3
CVE-2026-7291

A weakness has been identified in o2oa up to 10.0. This affects the function FileAction of the file FileAction.java of the component URL Fetching. Ex…

Mitigation only
Fix from $1,600 2026-04-28
Openclaw MEDIUM 6.5
CVE-2026-42430

OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in Playwright redirect handling that allows attackers to bypass strict …

Fix: 2026.4.8+
Fix from $1,600 2026-04-28
Openclaw HIGH 8.5
CVE-2026-41914

OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in QQ Bot media download paths that bypass SSRF protection. Attackers c…

Fix: 2026.4.8+
Fix from $1,950 2026-04-28
Openclaw HIGH 7.6
CVE-2026-41912

OpenClaw before 2026.4.8 contains a server-side request forgery policy bypass vulnerability allowing attackers to trigger navigations bypassing norma…

Fix: 2026.4.8+
Fix from $1,950 2026-04-28
Nemoclaw MEDIUM 6.3
CVE-2026-24231

NVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could cause a server-side request …

Fix: 0.0.13+
Fix from $1,600 2026-04-28
Unclassified HIGH 7.3
CVE-2026-7223

A vulnerability was identified in BigSweetPotatoStudio HyperChat up to 2.0.0-alpha.63. Affected by this issue is the function fetch of the file packa…

Mitigation only
Fix from $1,950 2026-04-28
Unclassified HIGH 7.3
CVE-2026-7221

A vulnerability was found in TencentCloudBase CloudBase-MCP up to 2.17.0. Affected is the function openUrl of the file mcp/src/interactive-server.ts …

Patch available
Fix from $1,950 2026-04-28
Nextchat HIGH 7.3
CVE-2026-7178

A weakness has been identified in ChatGPTNextWeb NextChat up to 2.16.1. This affects the function storeUrl of the file app/api/artifacts/route.ts of …

No fix yet
Fix from $1,950 2026-04-27
Nextchat HIGH 7.3
CVE-2026-7177

A security flaw has been discovered in ChatGPTNextWeb NextChat up to 2.16.1. Affected by this issue is the function proxyHandler of the file app/api/…

No fix yet
Fix from $1,950 2026-04-27
Unclassified HIGH 7.3
CVE-2026-7158

A vulnerability has been found in dmitryglhf mcp-url-downloader up to 4b8cf2de55f6e8864a77d108e8a94a5b8e4394c6. Affected by this issue is the functio…

Mitigation only
Fix from $1,950 2026-04-27
Unclassified MEDIUM 6.3
CVE-2026-7150

A vulnerability was found in dh1011 auto-favicon up to f189116a9259950c2393f114dbcb94dde0ad864b. This issue affects the function generate_favicon_fro…

Mitigation only
Fix from $1,600 2026-04-27
Unclassified HIGH 7.3
CVE-2026-7147

A vulnerability was detected in JoeCastrom mcp-chat-studio up to 1.5.0. Affected by this issue is some unknown functionality of the file server/route…

Mitigation only
Fix from $1,950 2026-04-27
Unclassified HIGH 7.3
CVE-2026-7146

A security vulnerability has been detected in AlejandroArciniegas mcp-data-vis up to de5a51525a69822290eaee569a1ab447b490746d. Affected by this vulne…

Mitigation only
Fix from $1,950 2026-04-27
Glutamate Mcp Servers HIGH 7.3
CVE-2026-7094

A vulnerability was determined in ShadowCloneLabs GlutamateMCPServers up to e2de73280b01e5d943593dd1aa2c01c5b9112f78. Affected by this issue is some …

Fix: after 2025-06-26
Fix from $1,950 2026-04-27
Unclassified MEDIUM 6.3
CVE-2026-7084

A vulnerability was found in HBAI-Ltd Toonflow-app up to 1.1.1. This affects the function fetch of the file src/routes/setting/vendorConfig/getCodeBy…

Mitigation only
Fix from $1,600 2026-04-27
Unclassified HIGH 7.3
CVE-2026-7065

A vulnerability has been found in BidingCC BuildingAI up to 26.0.1. Impacted is the function uploadRemoteFile of the file packages/core/src/modules/u…

Mitigation only
Fix from $1,950 2026-04-27
Unclassified HIGH 7.3
CVE-2026-7025

A vulnerability was found in Typecho up to 1.3.0. This vulnerability affects the function Service::sendPingHandle of the file var/Widget/Service.php …

Mitigation only
Fix from $1,950 2026-04-26
Unclassified MEDIUM 6.3
CVE-2026-6981

A vulnerability was found in IhateCreatingUserNames2 AiraHub2 up to 3e4b77fd7d48ed811ffe5b8d222068c17c76495e. Affected is the function connect_stream…

Mitigation only
Fix from $1,600 2026-04-25
Unclassified MEDIUM 6.3
CVE-2026-6979

A flaw has been found in devlikeapro WAHA up to 2026.3.4. This affects an unknown function of the file src/api/media.controller.ts of the component A…

Mitigation only
Fix from $1,600 2026-04-25
Langchain Text Splitters MEDIUM 6.5
CVE-2026-41481

LangChain is a framework for building agents and LLM-powered applications. Prior to langchain-text-splitters 1.1.2, HTMLHeaderTextSplitter.split_tex…

Fix: 1.1.2+
Fix from $1,600 2026-04-24
Axios CRITICAL 10.0
CVE-2026-42043

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axio…

Fix: 0.31.1 / 1.15.1+
Fix from $2,300 2026-04-24
Axios HIGH 7.5
CVE-2026-42038

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, he fix for no_proxy hostname normalization bypass is in…

Fix: 0.31.1 / 1.15.1+
Fix from $1,950 2026-04-24
Kyverno CRITICAL 9.1
CVE-2026-41323

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.18.0-rc1, 1.17.2-rc1, and 1.16.4, Kyverno's apiC…

Fix: 1.16.4 / 1.17.2+
Fix from $2,300 2026-04-24
Openclaw HIGH 7.1
CVE-2026-41361

OpenClaw before 2026.3.28 contains an SSRF guard bypass vulnerability that fails to block four IPv6 special-use ranges. Attackers can exploit this by…

Fix: 2026.3.28+
Fix from $1,950 2026-04-23
Entra Id CRITICAL 10.0
CVE-2026-35431

Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.

Mitigation only
Fix from $2,300 2026-04-23
Dynamics 365 HIGH 7.5
CVE-2026-32210

Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.

Mitigation only
Fix from $1,950 2026-04-23
Purview Ediscovery CRITICAL 10.0
CVE-2026-26150

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-23
Flowise HIGH 8.3
CVE-2026-41270

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) protect…

Fix: 3.1.0+
Fix from $1,950 2026-04-23
Flowise HIGH 8.3
CVE-2026-41271

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) vulnera…

Fix: 3.1.0+
Fix from $1,950 2026-04-23