Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Invoice Ninja HIGH 7.7
CVE-2026-29925

Invoice Ninja v5.12.46 and v5.12.48 is vulnerable to Server-Side Request Forgery (SSRF) in CheckDatabaseRequest.php.

No fix yet
Fix from $1,950 2026-03-30
Unclassified MEDIUM 6.3
CVE-2026-5126

A flaw has been found in SourceCodester RSS Feed Parser 1.0. Affected by this issue is the function file_get_contents. This manipulation causes serve…

Mitigation only
Fix from $1,600 2026-03-30
Kubeplus HIGH 7.6
CVE-2026-29954

In KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF vulnerability when processing the chartURL field of ResourceC…

No fix yet
Fix from $1,950 2026-03-30
Crewai CRITICAL 9.8
CVE-2026-2286

CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services, facilitated by the RAG…

Mitigation only
Fix from $2,300 2026-03-30
Lollms HIGH 7.5
CVE-2026-0560

A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/export-content`…

Fix: after 2.1.0
Fix from $1,950 2026-03-29
Unclassified HIGH 7.3
CVE-2026-5016

A vulnerability was identified in elecV2 elecV2P up to 3.8.3. This affects the function eAxios of the file /mock of the component URL Handler. Such m…

Mitigation only
Fix from $1,950 2026-03-28
Unclassified HIGH 7.2
CVE-2025-12886

The Oxygen Theme theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.8 via the laborator_calc_…

Mitigation only
Fix from $1,950 2026-03-28
Pyload MEDIUM 6.5
CVE-2026-33992

pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, PyLoad's download engine accepts arbitrary URLs …

Patch available
Fix from $1,600 2026-03-27
Linkace HIGH 8.5
CVE-2026-33953

LinkAce is a self-hosted archive to collect website links. Versions prior to 2.5.3 block direct requests to private IP literals, but still performs s…

Fix: 2.5.3+
Fix from $1,950 2026-03-27
Librechat HIGH 7.7
CVE-2026-31945

LibreChat is a ChatGPT clone with additional features. Versions 0.8.2-rc2 through 0.8.2 are vulnerable to a server-side request forgery (SSRF) attack…

No fix yet
Fix from $1,950 2026-03-27
Librechat HIGH 8.5
CVE-2026-31943

LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.3, `isPrivateIP()` in `packages/api/src/auth/domain.ts` fails to detect I…

Fix: 0.8.3+
Fix from $1,950 2026-03-27
Letta MEDIUM 6.5
CVE-2026-4964

A security vulnerability has been detected in letta-ai letta 0.16.4. This vulnerability affects the function _convert_message_create_to_message of th…

No fix yet
Fix from $1,600 2026-03-27
Unclassified HIGH 7.3
CVE-2026-4953

A weakness has been identified in mingSoft MCMS up to 5.5.0. This issue affects the function catchImage of the file net/mingsoft/cms/action/BaseActio…

Mitigation only
Fix from $1,950 2026-03-27
Avideo MEDIUM 6.5
CVE-2026-33766

WWBN AVideo is an open source video platform. In versions up to and including 26.0, `isSSRFSafeURL()` validates URLs against private/reserved IP rang…

Fix: after 26.0
Fix from $1,600 2026-03-27
Calibre MEDIUM 5.5
CVE-2026-33205

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a Server-Side Request Fo…

Fix: 9.6.0+
Fix from $1,600 2026-03-27
Otcms HIGH 7.5
CVE-2026-30637

Server-Side Request Forgery (SSRF) vulnerability exists in the AnnounContent of the /admin/read.php in OTCMS V7.66 and before. The vulnerability allo…

Fix: after 7.66
Fix from $1,950 2026-03-27
Spring Ai HIGH 8.6
CVE-2026-22742

Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimoda…

Fix: 1.0.5 / 1.1.4+
Fix from $1,950 2026-03-27
Unclassified MEDIUM 6.3
CVE-2026-4907

A vulnerability was identified in Page-Replica Page Replica up to e4a7f52e75093ee318b4d5a9a9db6751050d2ad0. The impacted element is the function site…

Mitigation only
Fix from $1,600 2026-03-27
Unclassified MEDIUM 6.5
CVE-2026-33693

Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.7.0-beta.9, the `v4_is_invalid()` function in `activitypub-federation-rust…

Patch available
Fix from $1,600 2026-03-27
Pinchtab MEDIUM 5.5
CVE-2026-33619

PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab v0.8.3 contains a server-side request forger…

Fix: 0.8.4+
Fix from $1,600 2026-03-26
Lychee MEDIUM 5.0
CVE-2026-33537

Lychee is a free, open-source photo-management tool. The patch introduced for GHSA-cpgw-wgf3-xc6v (SSRF via `Photo::fromUrl`) contains an incomplete …

Fix: 7.5.1+
Fix from $1,600 2026-03-26
Core Bundle Dev App MEDIUM 6.5
CVE-2026-33486

Roadiz is a polymorphic content management system based on a node system that can handle many types of services. A vulnerability in roadiz/documents …

Fix: 2.3.42 / 2.5.44+
Fix from $1,600 2026-03-26
Unclassified HIGH 8.6
CVE-2026-32857

Firecrawl version 2.8.0 and prior contain a server-side request forgery (SSRF) protection bypass vulnerability in the Playwright scraping service whe…

Mitigation only
Fix from $1,950 2026-03-26
Saloon HIGH 7.5
CVE-2026-33182

Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, when building the request URL, Saloon comb…

Fix: 4.0.0+
Fix from $1,950 2026-03-26
Infosphere Information Server MEDIUM 5.4
CVE-2026-1015

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated atta…

Fix: after 11.7.1.6
Fix from $1,600 2026-03-25
Websphere Application Server MEDIUM 5.4
CVE-2026-1561

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is vulnerable to server-side request fo…

Fix: 26.0.0.4+
Fix from $1,600 2026-03-25
Infosphere Information Server MEDIUM 5.4
CVE-2025-14912

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated atta…

Fix: after 11.7.1.6
Fix from $1,600 2026-03-25
Unclassified MEDIUM 6.4
CVE-2026-24964

Server-Side Request Forgery (SSRF) vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Server Side Re…

Mitigation only
Fix from $1,600 2026-03-25
Drupal Canvas MEDIUM 5.0
CVE-2026-3216

Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal Canvas allows Server Side Request Forgery.This issue affects Drupal Canvas: from 0.…

Fix: 1.1.1+
Fix from $1,600 2026-03-25
Commonmark MEDIUM 6.1
CVE-2026-33347

league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerab…

Fix: 2.8.2+
Fix from $1,600 2026-03-24