Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Postiz MEDIUM 5.4
CVE-2026-34590

Postiz is an AI social media scheduling tool. Prior to version 2.21.4, the POST /webhooks/ endpoint for creating webhooks uses WebhooksDto which vali…

Fix: 2.21.4+
Fix from $1,600 2026-04-02
Sillytavern MEDIUM 5.0
CVE-2026-34526

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines,…

Fix: 1.17.0+
Fix from $1,600 2026-04-02
Unclassified HIGH 7.3
CVE-2026-5346

A vulnerability was determined in huimeicloud hm_editor up to 2.2.3. Impacted is the function client.get of the file src/mcp-server.js of the compone…

Mitigation only
Fix from $1,950 2026-04-02
Fastmcp CRITICAL 10.0
CVE-2026-32871

FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clien…

Fix: 3.2.0+
Fix from $2,300 2026-04-02
Unclassified MEDIUM 6.4
CVE-2026-0688

The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.6.2 via the 'Tools::read' fu…

Mitigation only
Fix from $1,600 2026-04-02
Unclassified HIGH 7.2
CVE-2026-0686

The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.6.2 in the 'MF2::parse_autho…

Mitigation only
Fix from $1,950 2026-04-02
Unclassified MEDIUM 5.3
CVE-2026-5323

A vulnerability was found in priyankark a11y-mcp up to 1.0.5. This vulnerability affects the function A11yServer of the file src/index.js. The manipu…

Patch available
Fix from $1,600 2026-04-02
Aiohttp HIGH 7.5
CVE-2026-34515

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the static resource handler may e…

Fix: 3.13.4+
Fix from $1,950 2026-04-01
Payload HIGH 7.7
CVE-2026-34746

Payload is a free and open source headless content management system. Prior to version 3.79.1, an authenticated Server-Side Request Forgery (SSRF) vu…

Fix: 3.79.1+
Fix from $1,950 2026-04-01
Unclassified HIGH 7.4
CVE-2026-34076

Clerk JavaScript is the official JavaScript repository for Clerk authentication. In @clerk/hono from versions 0.1.0 to before 0.1.5, @clerk/express f…

Mitigation only
Fix from $1,950 2026-04-01
Model Runner CRITICAL 9.1
CVE-2026-33990

Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Prior to version 1.1.25, Docker Model Runner contains a…

Fix: 1.1.25+
Fix from $2,300 2026-04-01
Unclassified MEDIUM 6.1
CVE-2026-20041

A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights could allow an unauthenticated, remote attacker to conduct a server-side …

No fix yet
Fix from $1,600 2026-04-01
M Files Server HIGH 7.3
CVE-2026-0932

Blind server-side request forgery (SSRF) vulnerability in legacy connection methods of document co-authoring features in M-Files Server before 26.3 a…

Fix: 26.3.15818.5+
Fix from $1,950 2026-04-01
Unclassified MEDIUM 6.3
CVE-2026-5259

A vulnerability was determined in AutohomeCorp frostmourne up to 1.0. The affected element is an unknown function of the file frostmourne-monitor/src…

Mitigation only
Fix from $1,600 2026-04-01
Freescout MEDIUM 5.3
CVE-2026-34443

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, checkIpByMask() in app/Misc/Helper.php c…

Fix: 1.8.211+
Fix from $1,600 2026-03-31
Avideo MEDIUM 6.5
CVE-2026-34740

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the EPG (Electronic Program Guide) link feature in AVideo allows authentica…

Fix: after 26.0
Fix from $1,600 2026-03-31
Invoiceshelf HIGH 8.1
CVE-2026-34366

InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version …

Fix: 2.2.0+
Fix from $1,950 2026-03-31
Invoiceshelf HIGH 8.7
CVE-2026-34367

InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version …

Fix: 2.2.0+
Fix from $1,950 2026-03-31
Invoiceshelf HIGH 8.1
CVE-2026-34365

InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version …

Fix: 2.2.0+
Fix from $1,950 2026-03-31
Discourse MEDIUM 5.0
CVE-2026-33185

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l…

Fix: 2026.1.3 / 2026.2.2+
Fix from $1,600 2026-03-31
Unclassified MEDIUM 6.3
CVE-2026-5205

A vulnerability was identified in chatwoot up to 4.11.2. Affected by this vulnerability is the function Webhooks::Trigger in the library lib/webhooks…

Mitigation only
Fix from $1,600 2026-03-31
Hl7 Fhir Core MEDIUM 5.8
CVE-2026-34360

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the /loadIG HTTP end…

Fix: 6.9.4+
Fix from $1,600 2026-03-31
Openclaw HIGH 8.3
CVE-2026-34504

OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows…

Fix: 2026.3.28+
Fix from $1,950 2026-03-31
Fastgpt HIGH 7.7
CVE-2026-34163

FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, FastGPT's MCP (Model Context Protocol) tools endpoints (/api/core/app/mcpTools/g…

Fix: 4.14.9.5+
Fix from $1,950 2026-03-31
Fastgpt CRITICAL 10.0
CVE-2026-34162

FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exp…

Fix: 4.14.9.5+
Fix from $2,300 2026-03-31
Unclassified MEDIUM 5.8
CVE-2026-3881

The Performance Monitor WordPress plugin through 1.0.6 does not validate a parameter before making a request to it, which could allow unauthenticated…

Mitigation only
Fix from $1,600 2026-03-31
Glance MEDIUM 5.0
CVE-2026-34881

OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authen…

Fix: 29.1.1 / 30.1.1+
Fix from $1,600 2026-03-31
Kyverno CRITICAL 9.8
CVE-2026-4789

Kyverno, versions 1.16.0 and later, are vulnerable to SSRF due to unrestricted CEL HTTP functions.

Fix: after 1.17.1
Fix from $2,300 2026-03-30
Gotenberg HIGH 7.5
CVE-2026-27018

Gotenberg is an API for converting document formats. Prior to version 8.29.0, the fix introduced for CVE-2024-21527 can be bypassed using mixed-case …

Fix: 8.29.0+
Fix from $1,950 2026-03-30
Tautulli MEDIUM 5.3
CVE-2026-31804

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /pms_image_proxy endpoint accepts a user-…

Fix: 2.17.0+
Fix from $1,600 2026-03-30