Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Text Generation Web Ui HIGH 7.5
CVE-2026-35486

text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, he superbooga and superboogav2 RAG extensions …

Fix: 4.3+
Fix from $1,950 2026-04-07
Popup Box MEDIUM 5.4
CVE-2025-15611

The Popup Box WordPress plugin before 5.5.0 does not properly validate nonces in the add_or_edit_popupbox() function before saving popup data, allow…

Fix: 5.5.0+
Fix from $1,600 2026-04-07
Directus HIGH 7.7
CVE-2026-35409

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.0, a Server-Side Request Forgery (SSRF) protection by…

Fix: 11.16.0+
Fix from $1,950 2026-04-06
Pyload Ng CRITICAL 9.1
CVE-2026-35459

pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, pyLoad has a server-side request forgery (SSRF) vu…

Fix: 0.5.0b3.dev97+
Fix from $2,300 2026-04-06
Pyload Ng HIGH 7.7
CVE-2026-35187

pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the parse_urls API function in src/pyload/core/api…

Fix: 0.5.0b3.dev97+
Fix from $1,950 2026-04-06
Ech0 HIGH 7.2
CVE-2026-35037

Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to 4.2.8, the GET /api/website/title endpoint accepts an arb…

Fix: 4.2.8+
Fix from $1,950 2026-04-06
Ech0 HIGH 7.5
CVE-2026-35036

Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to 4.2.8, Ech0 implements link preview (editor fetches a pag…

Fix: 4.2.8+
Fix from $1,950 2026-04-06
Whisperx Rest Api MEDIUM 5.8
CVE-2026-34981

The whisperX API is a tool for enhancing and analyzing audio content. From 0.3.1 to 0.5.0, FileService.download_from_url() in app/services/file_servi…

Fix: 0.6.0+
Fix from $1,600 2026-04-06
Vllm MEDIUM 5.4
CVE-2026-34753

vLLM is an inference and serving engine for large language models (LLMs). From 0.16.0 to before 0.19.0, a server-side request forgery (SSRF) vulnerab…

Fix: 0.19.0+
Fix from $1,600 2026-04-06
Curl Cffi HIGH 8.6
CVE-2026-33752

curl_cffi is the a Python binding for curl. Prior to 0.15.0, curl_cffi does not restrict requests to internal IP ranges, and follows redirects automa…

Fix: 0.15.0+
Fix from $1,950 2026-04-06
Distribution HIGH 7.5
CVE-2026-33540

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, in pull-through cache mode, distribution discovers tok…

Fix: 3.1.0+
Fix from $1,950 2026-04-06
Unclassified HIGH 7.3
CVE-2026-5633

A vulnerability was determined in assafelovic gpt-researcher up to 3.4.3. Affected is an unknown function of the component ws Endpoint. Executing a m…

Mitigation only
Fix from $1,950 2026-04-06
Unclassified MEDIUM 6.3
CVE-2026-5623

A vulnerability was identified in hcengineering Huly Platform 0.7.382. This affects an unknown part of the file server/front/src/index.ts of the comp…

Mitigation only
Fix from $1,600 2026-04-06
Unclassified MEDIUM 5.6
CVE-2026-5618

A vulnerability was detected in kalcaddle kodbox up to 1.64. This affects an unknown function of the component shareMake/shareCheck. Performing a man…

Mitigation only
Fix from $1,600 2026-04-06
Unclassified MEDIUM 6.3
CVE-2026-5607

A security vulnerability has been detected in imprvhub mcp-browser-agent up to 0.8.0. This impacts the function CallToolRequestSchema of the file src…

Mitigation only
Fix from $1,600 2026-04-06
Unclassified MEDIUM 6.3
CVE-2026-5538

A vulnerability was detected in QingdaoU OnlineJudge up to 1.6.1. Affected by this issue is the function service_url of the file JudgeServer.service_…

Mitigation only
Fix from $1,600 2026-04-05
Unclassified MEDIUM 6.3
CVE-2026-5530

A flaw has been found in Ollama up to 0.18.1. This issue affects some unknown processing of the file server/download.go of the component Model Pull A…

Mitigation only
Fix from $1,600 2026-04-05
Praisonaiagents HIGH 8.6
CVE-2026-34954

PraisonAI is a multi-agent teams system. Prior to version 1.5.95, FileTools.download_file() in praisonaiagents validates the destination path but per…

Fix: 1.5.95+
Fix from $1,950 2026-04-03
Praisonai HIGH 7.7
CVE-2026-34936

PraisonAI is a multi-agent teams system. Prior to version 4.5.90, passthrough() and apassthrough() in praisonai accept a caller-controlled api_base p…

Fix: 4.5.90+
Fix from $1,950 2026-04-03
Prompts.chat HIGH 7.7
CVE-2026-22664

prompts.chat prior to commit 30a8f04 contains a server-side request forgery vulnerability in the Fal.ai media status polling feature that allows auth…

Fix: 2026-03-25+
Fix from $1,950 2026-04-03
Zimaos CRITICAL 10.0
CVE-2026-28798

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. Prior to version 1.5.3, a proxy endpoint (/v1/sys/prox…

Fix: 1.5.3+
Fix from $2,300 2026-04-03
Bing CRITICAL 9.8
CVE-2026-32186

Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-04-03
Unclassified MEDIUM 6.3
CVE-2026-5470

A security vulnerability has been detected in mixelpixx Google-Research-MCP 1e062d7bd887bfe5f6e582b6cc288bb897b35cf2/ca613b736ab787bc926932f59cddc694…

Mitigation only
Fix from $1,600 2026-04-03
Budibase CRITICAL 9.9
CVE-2026-31818

Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST d…

Fix: 3.33.4+
Fix from $2,300 2026-04-03
Casdoor HIGH 7.2
CVE-2026-5469

A weakness has been identified in Casdoor 2.356.0. This vulnerability affects unknown code of the component Webhook URL Handler. Executing a manipula…

Mitigation only
Fix from $1,950 2026-04-03
Azure Databricks CRITICAL 9.8
CVE-2026-33107

Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-03
Azure Custom Locations Resource Provider HIGH 8.8
CVE-2026-26135

Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a networ…

Mitigation only
Fix from $1,950 2026-04-03
Unclassified HIGH 7.3
CVE-2026-5418

A vulnerability was identified in appsmithorg appsmith up to 1.97. Impacted is the function computeDisallowedHosts of the file app/server/appsmith-in…

Mitigation only
Fix from $1,950 2026-04-02
Postiz HIGH 7.7
CVE-2026-34576

Postiz is an AI social media scheduling tool. Prior to version 2.21.3, the POST /public/v1/upload-from-url endpoint accepts a user-supplied URL and f…

Fix: 2.21.3+
Fix from $1,950 2026-04-02
Postiz HIGH 8.6
CVE-2026-34577

Postiz is an AI social media scheduling tool. Prior to version 2.21.3, the GET /public/stream endpoint in PublicController accepts a user-supplied ur…

Fix: 2.21.3+
Fix from $1,950 2026-04-02