Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Frappe MEDIUM 5.0
CVE-2026-31878

Frappe is a full-stack web application framework. Prior to 14.100.1, 15.100.0, and 16.6.0, a malicious user could send a crafted request to an endpoi…

Fix: 14.100.1 / 15.100.0+
Fix from $1,600 2026-03-11
Sunbirded Portal HIGH 7.5
CVE-2025-70027

An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. This allows attackers to obtain se…

Mitigation only
Fix from $1,950 2026-03-11
Commerce MEDIUM 5.5
CVE-2026-21293

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a Server-Side Request Forgery (…

Fix: 1.3.3 / 2.4.4+
Fix from $1,600 2026-03-11
Commerce MEDIUM 5.5
CVE-2026-21294

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a Server-Side Request Forgery (…

Fix: 1.3.3 / 2.4.4+
Fix from $1,600 2026-03-11
Flowise HIGH 8.8
CVE-2026-31829

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.0.13, Flowise exposes an HTTP Node in AgentFlow a…

Fix: 3.0.13+
Fix from $1,950 2026-03-10
Linkace MEDIUM 6.5
CVE-2026-30953

LinkAce is a self-hosted archive to collect website links. When a user creates a link via POST /links, the server fetches HTML metadata from the prov…

Fix: after 2.0.0
Fix from $1,600 2026-03-10
Mcp Atlassian HIGH 8.2
CVE-2026-27826EPSS 14%

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.17.0, an unauthenticated atta…

Fix: 0.17.0+
Fix from $1,950 2026-03-10
Pdfmake HIGH 7.5
CVE-2026-26801

Server-Side Request Forgery (SSRF) vulnerability in pdfmake versions 0.3.0-beta.2 through 0.3.5 allows a remote attacker to obtain sensitive informat…

Fix: after 0.3.5
Fix from $1,950 2026-03-10
Azure Mcp Server HIGH 8.8
CVE-2026-26118

Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network.

Fix: 2.0.0+
Fix from $1,950 2026-03-10
Azure Iot Explorer HIGH 7.5
CVE-2026-26121

Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a network.

Fix: 0.15.14+
Fix from $1,950 2026-03-10
Netweaver Application Server Abap MEDIUM 6.4
CVE-2026-24316

SAP NetWeaver Application Server for ABAP provides an ABAP Report for testing purposes, which allows to send HTTP requests to arbitrary internal or e…

Mitigation only
Fix from $1,600 2026-03-10
Budibase CRITICAL 9.0
CVE-2026-25737

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.24.0 and earlier, an arbitrary file upload vulnerabili…

Fix: after 3.24.0
Fix from $2,300 2026-03-09
Vllm CRITICAL 9.8
CVE-2026-25960

vLLM is an inference and serving engine for large language models (LLMs). The SSRF protection fix for CVE-2026-24779 add in 0.15.1 can be bypassed in…

Fix: 0.17.0+
Fix from $2,300 2026-03-09
Dirigera Firmware MEDIUM 5.5
CVE-2026-3588

A server-side request forgery (SSRF) vulnerability in IKEA Dirigera v2.866.4 allows an attacker to exfiltrate private keys by sending a crafted reque…

Mitigation only
Fix from $1,600 2026-03-09
Thermakube CRITICAL 9.8
CVE-2025-70042

An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in oslabs-beta ThermaKube master.

Mitigation only
Fix from $2,300 2026-03-09
Bytedesk HIGH 8.8
CVE-2026-3788

A security vulnerability has been detected in Bytedesk up to 1.3.9. This impacts the function getModels of the file source-code/src/main/java/com/byt…

Fix: 1.4.5.4+
Fix from $1,950 2026-03-09
Bytedesk HIGH 8.8
CVE-2026-3789

A vulnerability was detected in Bytedesk up to 1.3.9. Affected is the function getModels of the file source-code/src/main/java/com/bytedesk/ai/spring…

Fix: 1.4.5.4+
Fix from $1,950 2026-03-09
Continew Admin HIGH 7.2
CVE-2026-3750

A security vulnerability has been detected in ContiNew Admin up to 4.2.0. This issue affects the function URI.create of the file continew-system/src/…

Fix: after 4.1.0
Fix from $1,950 2026-03-08
Unclassified MEDIUM 6.3
CVE-2026-3733

A vulnerability was detected in xuxueli xxl-job up to 3.3.2. This impacts an unknown function of the file source-code/src/main/java/com/xxl/job/admin…

Mitigation only
Fix from $1,600 2026-03-08
Unclassified MEDIUM 6.3
CVE-2026-3683

A vulnerability was detected in bufanyun HotGo up to 2.0. This issue affects the function ImageTransferStorage of the file /server/internal/logic/com…

Mitigation only
Fix from $1,600 2026-03-08
Unclassified MEDIUM 6.3
CVE-2026-3681

A weakness has been identified in welovemedia FFmate up to 2.0.15. This affects the function fireWebhook of the file /internal/service/webhook/webhoo…

Mitigation only
Fix from $1,600 2026-03-07
Weknora HIGH 7.5
CVE-2026-30858

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.0, a DNS rebinding vulnerab…

Fix: 0.3.0+
Fix from $1,950 2026-03-07
Pinchtab HIGH 7.5
CVE-2026-30834

PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. Prior to version 0.7.7, a Server-Side Request Forgery…

Fix: 0.7.7+
Fix from $1,950 2026-03-07
Soft Serve CRITICAL 9.1
CVE-2026-30832

Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.4, an authenticated SSH user can force the s…

Fix: 0.11.4+
Fix from $2,300 2026-03-07
Wallos HIGH 8.8
CVE-2026-30840

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, there is a server-side request forgery vulnerability i…

Fix: 4.6.2+
Fix from $1,950 2026-03-07
Wallos HIGH 7.5
CVE-2026-30828

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, the url parameter can be used to retrieve local system…

Fix: 4.6.2+
Fix from $1,950 2026-03-07
Homarr MEDIUM 5.3
CVE-2026-27797

Homarr is an open-source dashboard. Prior to version 1.54.0, an unauthenticated Server-Side Request Forgery (SSRF) vulnerability allows a remote atta…

Fix: 1.54.0+
Fix from $1,600 2026-03-07
Weknora HIGH 7.5
CVE-2026-30247

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, the application's "Impo…

Fix: 0.2.12+
Fix from $1,950 2026-03-07
Plane HIGH 8.5
CVE-2026-30242

Plane is an an open-source project management tool. Prior to version 1.2.3, the webhook URL validation in plane/app/serializers/webhook.py only check…

Fix: 1.2.3+
Fix from $1,950 2026-03-06
Wekan HIGH 8.1
CVE-2026-30844

Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 are vulnerable to Server-Side Request Forgery (SSRF) via attachment URL…

Patch available
Fix from $1,950 2026-03-06