Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Unclassified HIGH 7.7
CVE-2026-29178

Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on activitypub_federation, a fram…

Patch available
Fix from $1,950 2026-03-06
Ghostfolio CRITICAL 9.3
CVE-2026-28680

Ghostfolio is an open source wealth management software. Prior to version 2.245.0, an attacker can exploit the manual asset import feature to perform…

Fix: 2.245.0+
Fix from $2,300 2026-03-06
Opensift HIGH 8.2
CVE-2026-28677

OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version 1.6.3-alpha, the URL ingest …

Fix: 1.6.3+
Fix from $1,950 2026-03-06
Known HIGH 8.6
CVE-2026-28508

Idno is a social publishing platform. Prior to version 1.6.4, a logic error in the API authentication flow causes the CSRF protection on the URL unfu…

Fix: 1.6.4+
Fix from $1,950 2026-03-06
Openclaw MEDIUM 5.8
CVE-2026-28476

OpenClaw versions prior to 2026.2.14 contain a server-side request forgery vulnerability in the optional Tlon Urbit extension that accepts user-provi…

Fix: 2026.2.14+
Fix from $1,600 2026-03-05
Openclaw HIGH 8.6
CVE-2026-28467

OpenClaw versions prior to 2026.2.2 contain a server-side request forgery vulnerability in attachment and media URL hydration that allows remote atta…

Fix: 2026.2.2+
Fix from $1,950 2026-03-05
Openclaw CRITICAL 9.3
CVE-2026-28451

OpenClaw versions prior to 2026.2.14 contain server-side request forgery vulnerabilities in the Feishu extension that allow attackers to fetch attack…

Fix: 2026.2.14+
Fix from $2,300 2026-03-05
Twenty MEDIUM 5.0
CVE-2026-27023

Twenty is an open source CRM. Prior to version 1.18, the SSRF protection in SecureHttpClientService validated request URLs at the request level but d…

Fix: 1.18.0+
Fix from $1,600 2026-03-05
Ragas HIGH 7.5
CVE-2025-45691

An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in Exploding Gradients RAGAS v0.2.3 to v0.2.14. The vulnerability stems…

Fix: after 0.2.14
Fix from $1,950 2026-03-05
Unclassified MEDIUM 6.4
CVE-2026-28036

Server-Side Request Forgery (SSRF) vulnerability in SkatDesign Ratatouille ratatouille allows Server Side Request Forgery.This issue affects Ratatoui…

No fix yet
Fix from $1,600 2026-03-05
Opennext For Cloudflare MEDIUM 6.5
CVE-2026-3125

A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package, resulting from a path normalization bypass i…

Fix: 1.17.1+
Fix from $1,600 2026-03-04
Unclassified HIGH 7.2
CVE-2026-1273

The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Server-Side Request Forgery in all ve…

Mitigation only
Fix from $1,950 2026-03-04
Zimaos MEDIUM 6.5
CVE-2025-64427

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.0 and prior, due to insufficient valida…

Fix: after 1.5.0
Fix from $1,600 2026-03-02
Chamilo Lms CRITICAL 9.1
CVE-2025-50199

Chamilo is a learning management system. Prior to version 1.11.30, there is a blind SSRF vulnerability in /index.php via the POST openid_url paramete…

Fix: 1.11.30+
Fix from $2,300 2026-03-02
Chamilo Lms MEDIUM 5.3
CVE-2024-50337

Chamilo is a learning management system. Prior to version 1.11.28, the OpenId function allows anyone to send requests to any URL on server's behalf, …

Fix: 1.11.28+
Fix from $1,600 2026-03-02
Statamic HIGH 8.6
CVE-2026-28423

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, when Glide image manipulation is used in…

Fix: 5.73.11 / 6.4.0+
Fix from $1,950 2026-02-27
Unclassified MEDIUM 5.3
CVE-2026-27759

Featured Image from Content (featured-image-from-content) WordPress plugin versions prior to 1.7 contain an authenticated server-side request forgery…

Mitigation only
Fix from $1,600 2026-02-27
Gradio HIGH 8.6
CVE-2026-28416EPSS 7%

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Forgery (SSRF) vulnerability in…

Fix: 6.6.0+
Fix from $1,950 2026-02-27
Kiteworks MEDIUM 6.5
CVE-2026-28271

Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration functionality allows bypassing of SSRF …

Fix: 9.2.0+
Fix from $1,600 2026-02-27
Freeflow Core HIGH 7.5
CVE-2026-2252

An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via crafted XML input containing malic…

Fix: 8.1.0+
Fix from $1,950 2026-02-27
Psi Probe HIGH 8.8
CVE-2026-3270

A vulnerability has been found in psi-probe PSI Probe up to 5.3.0. This affects the function lookup of the file psi-probe-core/src/main/java/psiprobe…

Fix: after 5.3.0
Fix from $1,950 2026-02-27
Zitadel MEDIUM 6.5
CVE-2026-27945

ZITADEL is an open source identity management platform. Zitadel Action V2 (introduced as early preview in 2.59.0, beta in 3.0.0 and GA in 4.0.0) is a…

Fix: 4.11.1+
Fix from $1,600 2026-02-26
\@astrojs\/node HIGH 7.2
CVE-2026-27829

Astro is a web framework. In versions 9.0.0 through 9.5.3, a bug in Astro's image pipeline allows bypassing `image.domains` / `image.remotePatterns` …

Fix: 9.5.4+
Fix from $1,950 2026-02-26
Mailpit HIGH 8.6
CVE-2026-27808

Mailpit is an email testing tool and API for developers. Prior to version 1.29.2, the Link Check API (/api/v1/message/{ID}/link-check) is vulnerable …

Fix: 1.29.2+
Fix from $1,950 2026-02-26
Terriajs Server HIGH 7.5
CVE-2026-27818

TerriaJS-Server is a NodeJS Express server for TerriaJS, a library for building web-based geospatial data explorers. A validation bug in versions pri…

Fix: 4.0.3+
Fix from $1,950 2026-02-26
Kruise HIGH 7.6
CVE-2026-24005

Kruise provides automated management of large-scale applications on Kubernetes. Prior to versions 1.8.3 and 1.7.5, PodProbeMarker allows defining cus…

Fix: 1.7.5 / 1.8.3+
Fix from $1,950 2026-02-25
Langchain Community HIGH 7.4
CVE-2026-27795

LangChain is a framework for building LLM-powered applications. Prior to version 1.1.8, a redirect-based Server-Side Request Forgery (SSRF) bypass ex…

Fix: 1.1.18+
Fix from $1,950 2026-02-25
Unclassified CRITICAL 9.2
CVE-2026-27739

The Angular SSR is a server-rise rendering tool for Angular applications. Versions prior to 21.2.0-rc.1, 21.1.5, 20.3.17, and 19.2.21 have a Server-S…

Patch available
Fix from $2,300 2026-02-25
Plane HIGH 7.7
CVE-2026-27706

Plane is an an open-source project management tool. Prior to version 1.2.2, a Full Read Server-Side Request Forgery (SSRF) vulnerability has been ide…

Fix: 1.2.2+
Fix from $1,950 2026-02-25
Esm.sh HIGH 7.5
CVE-2026-27730

esm.sh is a no-build content delivery network (CDN) for web development. Versions up to and including 137 have an SSRF vulnerability (CWE-918) in esm…

Fix: after 137
Fix from $1,950 2026-02-25