Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Flowise HIGH 7.1
CVE-2026-41272

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the core security wrappers (secureAxiosReque…

Fix: 3.1.0+
Fix from $1,950 2026-04-23
Socialengine HIGH 8.5
CVE-2026-41461

SocialEngine versions 7.8.0 and prior contain a blind server-side request forgery vulnerability in the /core/link/preview endpoint where user-supplie…

Fix: after 7.8.0
Fix from $1,950 2026-04-23
Unclassified HIGH 8.5
CVE-2026-41455

WeKan before 8.35 contains a server-side request forgery vulnerability in webhook integration URL handling where the URL scheme field accepts any str…

Patch available
Fix from $1,950 2026-04-22
Unclassified HIGH 7.2
CVE-2026-41170

Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the `RestoreController.PostRestoreJ…

Patch available
Fix from $1,950 2026-04-22
Unclassified HIGH 7.3
CVE-2026-41171

Squidex is an open source headless content management system and content management hub. Versions prior to 7.23.0 have a Server-Side Request Forgery …

Patch available
Fix from $1,950 2026-04-22
Unclassified HIGH 7.3
CVE-2026-41172

Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, an SSRF vulnerability allows a user…

Patch available
Fix from $1,950 2026-04-22
Unclassified MEDIUM 5.5
CVE-2026-41177

Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the Squidex Restore API is vulnerab…

Patch available
Fix from $1,600 2026-04-22
Logpoint HIGH 8.5
CVE-2026-35548

An issue was discovered in guardsix (formerly Logpoint) ODBC Enrichment Plugins before 5.2.1 (5.2.1 is used in guardsix 7.9.0.0). A logic flaw allowe…

Fix: 5.2.1 / 7.9.0+
Fix from $1,950 2026-04-22
Unclassified MEDIUM 5.5
CVE-2026-41129

Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14 are vulnerable to Server-…

Patch available
Fix from $1,600 2026-04-22
Unclassified MEDIUM 5.5
CVE-2026-41130

Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14, the `resource-js` end…

Patch available
Fix from $1,600 2026-04-22
Enterprise Server HIGH 8.9
CVE-2026-5921

A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to extract sensitive environme…

Fix: 3.14.26 / 3.15.21+
Fix from $1,950 2026-04-21
Avideo MEDIUM 6.5
CVE-2026-41060

WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isSSRFSafeURL()` function in `objects/functions.php` contains a same-d…

Fix: after 29.0
Fix from $1,600 2026-04-21
Avideo MEDIUM 5.3
CVE-2026-41055

WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete SSRF fix in AVideo's LiveLinks proxy adds `isSSRFSafeURL()` v…

Fix: after 29.0
Fix from $1,600 2026-04-21
Unclassified MEDIUM 6.3
CVE-2026-6744

A vulnerability was found in Bagisto up to 2.3.15. Affected is the function copy of the component Downloadable Link Handler. The manipulation results…

Mitigation only
Fix from $1,600 2026-04-21
Openclaw MEDIUM 6.3
CVE-2026-41302

OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functionality that allows remote at…

Fix: 2026.3.31+
Fix from $1,600 2026-04-21
Openclaw HIGH 7.6
CVE-2026-41297

OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functionality that allows attackers…

Fix: 2026.3.31+
Fix from $1,950 2026-04-21
Glances HIGH 8.8
CVE-2026-35587

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, a Server-Side Request Forgery (SSRF) vulnerability exists in…

Fix: 4.5.4+
Fix from $1,950 2026-04-21
Lmdeploy HIGH 7.5
CVE-2026-33626EPSS 45%

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions prior to 0.12.3 have a Server-Side Request Forgery (SSR…

Fix: 0.12.3+
Fix from $1,950 2026-04-20
Unclassified HIGH 7.7
CVE-2026-34428

Vvveb prior to 1.0.8.1 contains a server-side request forgery vulnerability in the oEmbedProxy action of the editor/editor module where the url param…

Patch available
Fix from $1,950 2026-04-20
Vexa MEDIUM 5.8
CVE-2026-25883

Vexa is an open-source, self-hostable meeting bot API and meeting transcription API. Prior to 0.10.0-260419-1910, the Vexa webhook feature allows aut…

Fix: after 0.10
Fix from $1,600 2026-04-20
Unclassified MEDIUM 6.3
CVE-2026-6649

A vulnerability was determined in Qibo CMS 1.0. Affected by this issue is some unknown functionality of the file /index/image/headers. Executing a ma…

Mitigation only
Fix from $1,600 2026-04-20
Unclassified HIGH 7.3
CVE-2026-6625

A security vulnerability has been detected in moxi624 Mogu Blog v2 up to 5.2. Affected by this vulnerability is the function LocalFileServiceImpl.upl…

Mitigation only
Fix from $1,950 2026-04-20
Unclassified MEDIUM 6.3
CVE-2026-6618

A flaw has been found in langgenius dify up to 1.13.3. This issue affects the function parse_openai_plugin_json_to_tool_bundle of the file api/core/t…

Mitigation only
Fix from $1,600 2026-04-20
Unclassified MEDIUM 6.3
CVE-2026-6616

A security vulnerability has been detected in TransformerOptimus SuperAGI up to 0.0.14. This affects the function extract_with_bs4/extract_with_3k/ex…

Mitigation only
Fix from $1,600 2026-04-20
Unclassified MEDIUM 6.3
CVE-2026-6617

A vulnerability was detected in langgenius dify up to 0.6.9. This vulnerability affects the function get_api_tool_provider_remote_schema of the file …

Mitigation only
Fix from $1,600 2026-04-20
Unclassified HIGH 7.3
CVE-2026-6604

A vulnerability was identified in modelscope agentscope up to 1.0.18. Affected by this issue is the function _parse_url/prepare_image/openai_audio_to…

Mitigation only
Fix from $1,950 2026-04-20
Unclassified HIGH 7.3
CVE-2026-6605

A security flaw has been discovered in modelscope agentscope up to 1.0.18. This affects the function _get_bytes_from_web_url of the file src/agentsco…

Mitigation only
Fix from $1,950 2026-04-20
Unclassified HIGH 7.3
CVE-2026-6606

A weakness has been identified in modelscope agentscope up to 1.0.18. This vulnerability affects the function _process_audio_block of the file src/ag…

Mitigation only
Fix from $1,950 2026-04-20
Unclassified MEDIUM 6.3
CVE-2026-6587

A security flaw has been discovered in vibrantlabsai RAGAS up to 0.4.3. The affected element is the function _try_process_local_file/_try_process_url…

Mitigation only
Fix from $1,600 2026-04-20
Unclassified MEDIUM 6.3
CVE-2026-6573

A vulnerability was detected in PHPEMS 11.0. This affects the function temppage of the file /app/exam/controller/exams.master.php of the component In…

Mitigation only
Fix from $1,600 2026-04-19