Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Wallos HIGH 7.7
CVE-2026-33399

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the SSRF fix applied in version 4.6.2 for CVE-2026-308…

Fix: 4.7.0+
Fix from $1,950 2026-03-24
Wallos MEDIUM 6.5
CVE-2026-33401

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the patch introduced in commit e8a513591 (CVE-2026-308…

Fix: 4.7.0+
Fix from $1,600 2026-03-24
Wallos CRITICAL 9.1
CVE-2026-33407

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, Wallos endpoints/logos/search.php accepts HTTP_PROXY a…

Fix: 4.7.0+
Fix from $2,300 2026-03-24
Lollms Web Ui CRITICAL 9.1
CVE-2026-33340EPSS 22%

LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side Request Forgery (SSRF) vulner…

No fix yet
Fix from $2,300 2026-03-24
Vikunja HIGH 7.4
CVE-2026-33679

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DownloadImage` function in `pkg/utils/avatar.go` uses a …

Fix: 2.2.1+
Fix from $1,950 2026-03-24
Vikunja MEDIUM 5.4
CVE-2026-33675

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the migration helper functions `DownloadFile` and `DownloadFi…

Fix: 2.2.1+
Fix from $1,600 2026-03-24
Unclassified HIGH 7.3
CVE-2026-4623

A security vulnerability has been detected in DefaultFuction Jeson-Customer-Relationship-Management-System up to 1b4679c4d06b90d31dd521c2b000bfdec5a3…

Patch available
Fix from $1,950 2026-03-24
Connect Cms MEDIUM 6.8
CVE-2026-32279

Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and includi…

Fix: 1.41.1 / 2.41.1+
Fix from $1,600 2026-03-23
Avideo HIGH 8.2
CVE-2026-33502

WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated server-side request forgery vulnerability in `…

Fix: after 26.0
Fix from $1,950 2026-03-23
Avideo HIGH 8.6
CVE-2026-33480

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `isSSRFSafeURL()` function in AVideo can be bypassed using IP…

Fix: after 26.0
Fix from $1,950 2026-03-23
Unclassified MEDIUM 6.3
CVE-2026-4589

A vulnerability was identified in kalcaddle kodbox 1.64. The affected element is the function PathDriverUrl of the file /workspace/source-code/app/co…

Mitigation only
Fix from $1,600 2026-03-23
Avideo CRITICAL 9.1
CVE-2026-33351

WWBN AVideo is an open source video platform. Prior to version 26.0, a Server-Side Request Forgery (SSRF) vulnerability exists in `plugin/Live/standA…

Fix: 26.0+
Fix from $2,300 2026-03-23
Unclassified HIGH 7.3
CVE-2026-4528

A vulnerability was determined in trueleaf ApiFlow 0.9.7. The impacted element is the function validateUrlSecurity of the file packages/server/src/se…

Mitigation only
Fix from $1,950 2026-03-21
Unclassified HIGH 7.2
CVE-2026-3478

The Content Syndication Toolkit plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3 via the r…

Mitigation only
Fix from $1,950 2026-03-21
Unclassified HIGH 7.2
CVE-2026-1648

The Performance Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.6. This is due to…

Mitigation only
Fix from $1,950 2026-03-21
Unclassified HIGH 8.3
CVE-2026-1313

The MimeTypes Link Icons plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.2.20. This is due …

Mitigation only
Fix from $1,950 2026-03-21
Unclassified HIGH 7.2
CVE-2026-4302

The WowOptin: Next-Gen Popup Maker plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.29. Th…

Mitigation only
Fix from $1,950 2026-03-21
Avideo MEDIUM 5.5
CVE-2026-33237

WWBN AVideo is an open source video platform. Prior to version 26.0, the Scheduler plugin's `run()` function in `plugin/Scheduler/Scheduler.php` call…

Fix: 26.0+
Fix from $1,600 2026-03-21
Budibase HIGH 8.7
CVE-2026-33226

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions from 3.30.6 and prior, the REST datasource quer…

Fix: after 3.30.6
Fix from $1,950 2026-03-20
Ckan Mcp Server MEDIUM 5.7
CVE-2026-33060

CKAN MCP Server is a tool for querying CKAN open data portals. Versions prior to 0.4.85 provide tools including ckan_package_search and sparql_query …

Fix: 0.4.85+
Fix from $1,600 2026-03-20
Avideo HIGH 8.6
CVE-2026-33039

WWBN AVideo is an open source video platform. In versions 25.0 and below, the plugin/LiveLinks/proxy.php endpoint validates user-supplied URLs agains…

Fix: 26.0+
Fix from $1,950 2026-03-20
Avideo Encoder CRITICAL 9.1
CVE-2026-33024

AVideo is a video-sharing Platform. Versions prior to 8.0 contain a Server-Side Request Forgery vulnerability (CWE-918) in the public thumbnail endpo…

Fix: 8.0+
Fix from $2,300 2026-03-20
Sqlbot HIGH 7.5
CVE-2026-32949

SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a Server-Side Request Forgery (SS…

Fix: 1.7.0+
Fix from $1,950 2026-03-20
Admidio MEDIUM 6.8
CVE-2026-32812

Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, unrestricted URL fetch in the SSO Metadata API can result in SSR…

Fix: 5.0.7+
Fix from $1,600 2026-03-20
Suitecrm MEDIUM 5.3
CVE-2026-29107

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, it is p…

Fix: 7.15.1 / 8.9.3+
Fix from $1,600 2026-03-19
Suitecrm HIGH 7.5
CVE-2026-29097

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions prior to 7.15.1 and 8.9.3 contain …

Fix: 7.15.1 / 8.9.3+
Fix from $1,950 2026-03-19
Openclaw MEDIUM 6.5
CVE-2026-32037

OpenClaw versions prior to 2026.2.22 fail to consistently validate redirect chains against configured mediaAllowHosts allowlists during MSTeams media…

Fix: 2026.2.22+
Fix from $1,600 2026-03-19
Openclaw MEDIUM 5.3
CVE-2026-32019

OpenClaw versions prior to 2026.2.22 contain incomplete IPv4 special-use range validation in the isPrivateIpv4() function, allowing requests to RFC-r…

Fix: 2026.2.22+
Fix from $1,600 2026-03-19
Openemr HIGH 7.6
CVE-2026-33321

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, users with the `Notes - my…

Fix: 8.0.0.2+
Fix from $1,950 2026-03-19
Azure Cloud Shell CRITICAL 9.8
CVE-2026-32169

Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-03-19