Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Praisonaiagents MEDIUM 6.5
CVE-2026-40150

PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praisonaiagents/tools/web_crawl_tools.py accepts arbitra…

Fix: 1.5.128+
Fix from $1,600 2026-04-09
Openclaw HIGH 7.4
CVE-2026-35629

OpenClaw before 2026.3.25 contains a server-side request forgery vulnerability in multiple channel extensions that fail to properly guard configured …

Fix: 2026.3.25+
Fix from $1,950 2026-04-09
Siyuan MEDIUM 6.5
CVE-2026-40107

SiYuan is a personal knowledge management system. Prior to 3.6.4, SiYuan configures Mermaid.js with securityLevel: "loose" and htmlLabels: true. In t…

Fix: 3.6.4+
Fix from $1,600 2026-04-09
Radio Audio Streaming Stack CRITICAL 9.9
CVE-2026-40089

Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audio Streaming Stack dashboard contains a Server-Sid…

Fix: 1.7.2+
Fix from $2,300 2026-04-09
Web3.py HIGH 7.2
CVE-2026-40072

web3.py allows you to interact with the Ethereum blockchain using Python. From 6.0.0b3 to before 7.15.0 and 8.0.0b2, web3.py implements CCIP Read / O…

Fix: 7.15.0+
Fix from $1,950 2026-04-09
N8n Mcp HIGH 8.5
CVE-2026-39974

n8n-MCP is a Model Context Protocol (MCP) server that provides AI assistants with comprehensive access to n8n node documentation, properties, and ope…

Fix: 2.47.4+
Fix from $1,950 2026-04-09
Plane HIGH 7.7
CVE-2026-39843

Plane is an an open-source project management tool. From 0.28.0 to before 1.3.0, the remediation of GHSA-jcc6-f9v6-f7jw is incomplete which could lea…

Fix: 1.3.0+
Fix from $1,950 2026-04-09
Axios CRITICAL 9.9
CVE-2025-62718

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization …

Fix: 0.31.0 / 1.15.0+
Fix from $2,300 2026-04-09
Jizhicms CRITICAL 9.1
CVE-2025-50228

Jizhicms v2.5.4 is vulnerable to Server-Side Request Forgery (SSRF) in User Evaluation, Message, and Comment modules.

Mitigation only
Fix from $2,300 2026-04-09
Unclassified HIGH 7.3
CVE-2026-5832

A weakness has been identified in atototo api-lab-mcp up to 0.2.1. This affects the function analyze_api_spec/generate_test_scenarios/test_http_endpo…

Mitigation only
Fix from $1,950 2026-04-09
Unclassified MEDIUM 6.3
CVE-2026-5803

A security flaw has been discovered in bigsk1 openai-realtime-ui up to 188ccde27fdf3d8fab8da81f3893468f53b2797c. The affected element is an unknown f…

Patch available
Fix from $1,600 2026-04-08
\@frontmcp\/adapters HIGH 7.5
CVE-2026-39885

FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 2.3.0, the mcp-from-openapi library uses @apidevtools/json-sc…

Fix: 1.0.4 / 2.3.0+
Fix from $1,950 2026-04-08
Inventree HIGH 7.1
CVE-2026-39362

InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, when INVENTREE_DOWNLOAD_FROM_URL is enabled (opt-in), authenticate…

Fix: 1.2.7+
Fix from $1,950 2026-04-08
Mirror Registry For Red Hat Openshift MEDIUM 5.5
CVE-2026-32591

A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy ca…

Mitigation only
Fix from $1,600 2026-04-08
Kibana HIGH 7.7
CVE-2026-33458

Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and exe…

Fix: 9.3.3+
Fix from $1,950 2026-04-08
Erpnext CRITICAL 9.1
CVE-2026-31017

A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where us…

Mitigation only
Fix from $2,300 2026-04-08
Mirror Registry For Red Hat Openshift MEDIUM 6.5
CVE-2026-2377

A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products allows an authenticated user to …

Mitigation only
Fix from $1,600 2026-04-08
Qd CRITICAL 9.1
CVE-2023-46945

QD 20230821 is vulnerable to Server-side request forgery (SSRF) via a crafted request

Fix: after 20230821
Fix from $2,300 2026-04-08
Unclassified MEDIUM 5.4
CVE-2026-39695

Server-Side Request Forgery (SSRF) vulnerability in podigee Podigee podigee allows Server Side Request Forgery.This issue affects Podigee: from n/a t…

No fix yet
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.0
CVE-2026-39670

Server-Side Request Forgery (SSRF) vulnerability in Brecht Visual Link Preview visual-link-preview allows Server Side Request Forgery.This issue affe…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.4
CVE-2026-39645

Server-Side Request Forgery (SSRF) vulnerability in Global Payments GlobalPayments WooCommerce global-payments-woocommerce allows Server Side Request…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.4
CVE-2026-39647

Server-Side Request Forgery (SSRF) vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar allows Se…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.4
CVE-2026-39630

Server-Side Request Forgery (SSRF) vulnerability in Getty Images Getty Images getty-images allows Server Side Request Forgery.This issue affects Gett…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.5
CVE-2026-39464

Server-Side Request Forgery (SSRF) vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd coming-soon allows S…

Mitigation only
Fix from $1,600 2026-04-08
Security Verify Access HIGH 7.2
CVE-2026-1343

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces…

Fix: after 11.0.2.0
Fix from $1,950 2026-04-08
Avideo HIGH 7.1
CVE-2026-39370

WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoder.json.php still allows attacker-controlled downloadURL…

Fix: after 26.0
Fix from $1,950 2026-04-07
Avideo MEDIUM 6.5
CVE-2026-39368

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the Live restream log callback flow accepted an attacker-controlled restrea…

Fix: after 26.0
Fix from $1,600 2026-04-07
Openobserve HIGH 7.7
CVE-2026-39361

OpenObserve is a cloud-native observability platform. In 0.70.3 and earlier, the validate_enrichment_url function in src/handler/http/request/enrichm…

Fix: after 0.70.3
Fix from $1,950 2026-04-07
Churchcrm MEDIUM 6.0
CVE-2026-35572

ChurchCRM is an open-source church management system. Prior to 6.5.3, it is possible to trigger server-side HTTP/HTTPS requests to arbitrary hosts (S…

Fix: 6.5.3+
Fix from $1,600 2026-04-07
Linkace MEDIUM 5.0
CVE-2026-35516

LinkAce is a self-hosted archive to collect website links. Prior to 2.5.4, LinkRepository::update and CheckLinksCommand::checkLink do not check for p…

Fix: 2.5.4+
Fix from $1,600 2026-04-07