Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Nocobase MEDIUM 6.5
CVE-2026-40346

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.37, NocoBase's …

Fix: 2.0.37+
Fix from $1,600 2026-04-18
Movary HIGH 7.7
CVE-2026-40348

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can trigger server…

Fix: 0.71.1+
Fix from $1,950 2026-04-18
Openharness MEDIUM 6.3
CVE-2026-40516

OpenHarness before commit bd4df81 contains a server-side request forgery vulnerability in the web_fetch and web_search tools that allows attackers to…

Fix: 2026-04-11+
Fix from $1,600 2026-04-17
Unclassified MEDIUM 6.3
CVE-2026-6497

A vulnerability was determined in prasathmani TinyFileManager up to 2.6. Affected by this vulnerability is an unknown functionality of the file /file…

Mitigation only
Fix from $1,600 2026-04-17
Unclassified HIGH 7.5
CVE-2026-31317

Craftql v1.3.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the vendor/markh…

Mitigation only
Fix from $1,950 2026-04-17
Unclassified MEDIUM 6.9
CVE-2026-5131

GREENmod uses named pipes for communication between plugins, the web portal, and the system service, but the access control lists for these pipes are…

Mitigation only
Fix from $1,600 2026-04-17
Vault HIGH 8.6
CVE-2026-5052

Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This may lead to these requests be…

Fix: 1.19.16 / 1.20.10+
Fix from $1,950 2026-04-17
Weblate MEDIUM 5.0
CVE-2026-33440

Weblate is a web based localization tool. In versions prior to 5.17, the ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and …

Fix: 5.17+
Fix from $1,600 2026-04-15
Weblate MEDIUM 5.0
CVE-2026-34244

Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by the per-project "Administrat…

Fix: 5.17+
Fix from $1,600 2026-04-15
Jellyfin HIGH 8.1
CVE-2026-35032

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the LiveTV M3U tuner endpoint (POST /…

Fix: 10.11.7+
Fix from $1,950 2026-04-14
Chamilo Lms HIGH 7.2
CVE-2026-33715

Chamilo LMS is an open-source learning management system. In version 2.0-RC.2, the file public/main/inc/ajax/install.ajax.php is accessible without a…

Mitigation only
Fix from $1,950 2026-04-14
Chamilo Lms HIGH 8.6
CVE-2026-34160

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the PENS (Package Exchange Notification Services) plugin e…

Fix: after 1.11.38
Fix from $1,950 2026-04-14
Unclassified HIGH 8.5
CVE-2026-38527

A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resourc…

Mitigation only
Fix from $1,950 2026-04-14
Maxkb HIGH 7.4
CVE-2026-39418

MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, sandbox network protection can be bypassed by using socket.sendto()…

Fix: 2.8.0+
Fix from $1,950 2026-04-14
Unclassified MEDIUM 6.3
CVE-2026-6215

A weakness has been identified in DbGate up to 7.1.4. The impacted element is the function apiServerUrl1 of the file packages/rest/src/openApiDriver.…

Mitigation only
Fix from $1,600 2026-04-13
Skywalking Mcp HIGH 7.1
CVE-2026-34476

Server-Side Request Forgery via SW-URL Header vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are re…

Fix: 0.2.0+
Fix from $1,950 2026-04-13
Pdf Services Api CRITICAL 9.8
CVE-2026-5936

An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. Thi…

Fix: 2026-04-07+
Fix from $2,300 2026-04-13
Unclassified MEDIUM 6.3
CVE-2026-6119

A vulnerability was identified in AstrBotDevs AstrBot up to 4.22.1. The affected element is the function post_data.get of the component API Endpoint.…

Mitigation only
Fix from $1,600 2026-04-12
Metagpt MEDIUM 6.5
CVE-2026-6111

A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.1. This impacts the function decode_image of the file metagpt/utils/common.…

Patch available
Fix from $1,600 2026-04-12
Unclassified MEDIUM 5.0
CVE-2026-4979

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to blind Ser…

Patch available
Fix from $1,600 2026-04-11
Arcane MEDIUM 6.5
CVE-2026-40242

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.17.3, the /api/templates/fetch endpoint accepts a ca…

Fix: 1.17.3+
Fix from $1,600 2026-04-10
Geonode MEDIUM 6.3
CVE-2026-39921

GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery vulnerability that allows authenticated users with docum…

Fix: 4.4.5 / 5.0.2+
Fix from $1,600 2026-04-10
Geonode MEDIUM 6.3
CVE-2026-39922

GeoNode versions 4.4.5 and 5.0.2 (and prior within their respective releases) contain a server-side request forgery vulnerability in the service regi…

Fix: 4.4.5 / 5.0.2+
Fix from $1,600 2026-04-10
Postiz HIGH 8.2
CVE-2026-40168

Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endpoint is vulnerable to SSRF. Although the application valida…

Fix: 2.21.5+
Fix from $1,950 2026-04-10
Chartbrew CRITICAL 9.6
CVE-2026-30232

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 4.8.5, Chartb…

Fix: 4.8.5+
Fix from $2,300 2026-04-10
Chamilo Lms MEDIUM 6.5
CVE-2026-31941

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains a Server-Side Request Forgery (SSRF) vulnerability…

Fix: 1.11.38+
Fix from $1,600 2026-04-10
Praisonaiagents MEDIUM 6.5
CVE-2026-40160

PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, web_crawl's httpx fallback path passes user-supplied URLs directly to httpx.AsyncCli…

Fix: 1.5.128+
Fix from $1,600 2026-04-10
Fastgpt MEDIUM 5.3
CVE-2026-40100

FastGPT is an AI Agent building platform. Prior to 4.14.10.3, the /api/core/app/mcpTools/runTool endpoint accepts arbitrary URLs without authenticati…

Fix: 4.14.10.3+
Fix from $1,600 2026-04-10
Openclaw HIGH 8.1
CVE-2026-6011

A weakness has been identified in OpenClaw up to 2026.1.26. Affected by this issue is some unknown functionality of the file src/agents/tools/web-fet…

Fix: 2026.1.29+
Fix from $1,950 2026-04-10
Praisonai CRITICAL 10.0
CVE-2026-40114

PraisonAI is a multi-agent teams system. Prior to 4.5.128, the /api/v1/runs endpoint accepts an arbitrary webhook_url in the request body with no URL…

Fix: 4.5.128+
Fix from $2,300 2026-04-09