Vulnerability index

Browse CVEs

2,810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Unclassified MEDIUM 6.9
CVE-2026-73297

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, _is_blocked_ip in ufo/utils/url_security…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.8
CVE-2026-65941

In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitra…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.1
CVE-2026-73432

Vulnerability-Lookup contains a server-side request forgery (SSRF) vulnerability in the remote-instance synchronization functionality. Remote instanc…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 7.6
CVE-2026-73264

Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration access could supply an unvalidate…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 6.4
CVE-2026-19050

The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the capability or nonce of the requ…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 7.1
CVE-2026-16294

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode URL settings before performi…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 8.6
CVE-2026-73247

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/functions/Ht…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 5.4
CVE-2026-48762

TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI "Create Transcription" action handler fetches a user-supplied audio URL using …

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 5.8
CVE-2026-73243

kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated GET /addTask endpoint in kkFileView i…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 5.8
CVE-2026-73212

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.1, good_peer_addr() in src/server/ns_turn_server.c uses ioa_addr_i…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 5.3
CVE-2026-73082

Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the POST /api/v1/projects/:projectId/mcp-server/validate-agent-mcp-t…

No fix yet
Fix from $4,000 2026-08-11
Sharepoint Server HIGH 8.8
CVE-2026-70324

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

Fix: 16.0.19725.20522+
Fix from $4,900 2026-08-11
Sharepoint Server HIGH 8.8
CVE-2026-70326

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

Fix: 16.0.19725.20522+
Fix from $4,900 2026-08-11
Allura CRITICAL 9.1
CVE-2026-69223

Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommend…

No fix yet
Fix from $5,750 2026-08-11
Exchange Server HIGH 8.8
CVE-2026-65813

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $4,900 2026-08-11
Visual Studio 2022 MEDIUM 6.5
CVE-2026-62902

Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.

Fix: 8.0.30 / 9.0.19+
Fix from $4,000 2026-08-11
Sharepoint Server MEDIUM 6.5
CVE-2026-58639

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Fix: 16.0.19725.20522+
Fix from $4,000 2026-08-11
Powershell HIGH 7.5
CVE-2026-58612

Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 5.4
CVE-2026-48483

TypeBot is a chatbot builder tool. Prior to version 3.17.0, Typebot's WhatsApp status forwarding feature stores a workspace-configured webhook forwar…

No fix yet
Fix from $4,000 2026-08-11
Unclassified CRITICAL 9.3
CVE-2026-73080

SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a caller-supp…

No fix yet
Fix from $5,750 2026-08-11
Unclassified MEDIUM 5.1
CVE-2026-73210

A Server-Side Request Forgery (SSRF) vulnerability existed in Lookyloo's PlaywrightCapture when the only_global_lookup option was enabled. Playwrigh…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 8.5
CVE-2026-51583

An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF) via the Webhook validation …

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 5.4
CVE-2026-72784

Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulnerability in the GraphQL save<…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.4
CVE-2026-72768

n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node that allows authenticated use…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 7.5
CVE-2026-72606

A server-side request forgery vulnerability in Pinry through 2.1.13 allows unauthenticated remote attackers to make the server issue HTTP requests to…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-72597

A server-side request forgery vulnerability in Friendica through the 2026.08-dev branch allows authenticated users with a free self-registered accoun…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-72598

A server-side request forgery vulnerability in Apioo Fusio 8.8.3 allows authenticated consumer-role users to make the server issue HTTP requests to i…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-72560

A server-side request forgery vulnerability in HumanSignal Label Studio through 1.24.0.dev0 exists because SSRF_PROTECTION_ENABLED is set to false by…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 7.5
CVE-2026-72552

A server-side request forgery vulnerability in Dub as of 2026-07-10 allows unauthenticated remote attackers to make the server issue HTTP requests to…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.8
CVE-2026-13739

A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrar…

No fix yet
Fix from $4,900 2026-08-11