Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Esm.sh HIGH 7.5
CVE-2025-50180

esm.sh is a no-build content delivery network (CDN) for web development. In version 136, esm.sh is vulnerable to a full-response SSRF, allowing an at…

Fix: 137+
Fix from $1,950 2026-02-25
Unclassified MEDIUM 5.0
CVE-2026-2479

The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.1. This…

Mitigation only
Fix from $1,600 2026-02-25
Website Link Extractor HIGH 7.5
CVE-2026-3163

A vulnerability has been found in SourceCodester Website Link Extractor 1.0. This vulnerability affects the function file_get_contents of the compone…

No fix yet
Fix from $1,950 2026-02-25
Changedetection HIGH 8.6
CVE-2026-27696

changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, changedetection.io is vulnerable to Server-Side…

Fix: 0.54.1+
Fix from $1,950 2026-02-25
Mastodon MEDIUM 5.9
CVE-2026-27477

Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versio…

Fix: 4.4.14 / 4.5.7+
Fix from $1,600 2026-02-24
Altec Doclink CRITICAL 9.8
CVE-2026-26222

Altec DocLink (now maintained by Beyond Limits Inc.) version 4.0.336.0 exposes insecure .NET Remoting endpoints over TCP and HTTP/SOAP via Altec.RDCH…

Mitigation only
Fix from $2,300 2026-02-24
Avideo HIGH 8.1
CVE-2026-27732

WWBN AVideo is an open source video platform. Prior to version 22.0, the `aVideoEncoder.json.php` API endpoint accepts a `downloadURL` parameter and …

Fix: 22.0+
Fix from $1,950 2026-02-24
Craft Cms MEDIUM 6.5
CVE-2026-27129

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s Gr…

Fix: 4.16.19 / 5.8.23+
Fix from $1,600 2026-02-24
Dinky HIGH 7.7
CVE-2026-3052

A vulnerability was found in DataLinkDC dinky up to 1.2.5. The impacted element is the function proxyUba of the file dinky-admin/src/main/java/org/di…

Fix: after 1.2.5
Fix from $1,950 2026-02-24
\@astrojs\/node HIGH 8.6
CVE-2026-25545

Astro is a web framework. Prior to version 9.5.4, Server-Side Rendered pages that return an error with a prerendered custom error page (eg. `404.astr…

Fix: 9.5.4+
Fix from $1,950 2026-02-24
Jeewms HIGH 7.3
CVE-2026-3026

A vulnerability has been found in erzhongxmu JEEWMS 3.7. Affected by this issue is some unknown functionality of the file /plug-in/ueditor/jsp/getRem…

Fix: after 3.7
Fix from $1,950 2026-02-23
Unclassified MEDIUM 6.3
CVE-2026-2985

A security flaw has been discovered in Tiandy Video Surveillance System 视频监控平台 7.17.0. This impacts the function downloadImage of the file /com…

Mitigation only
Fix from $1,600 2026-02-23
Jeecg Boot MEDIUM 6.5
CVE-2026-2945

A weakness has been identified in JeecgBoot 3.9.0. Affected by this vulnerability is an unknown functionality of the file /sys/common/uploadImgByHttp…

No fix yet
Fix from $1,600 2026-02-22
Openclaw HIGH 7.3
CVE-2026-27488

OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, Cron webhook delivery in src/gateway/server-cron.ts uses fetch() directly, so w…

Fix: after 2026.2.17
Fix from $1,950 2026-02-21
Wallos HIGH 7.7
CVE-2026-27479

Wallos is an open-source, self-hostable personal subscription tracker. Versions 4.6.0 and below contain a Server-Side Request Forgery (SSRF) vulnerab…

Fix: 4.6.1+
Fix from $1,950 2026-02-21
Opensift HIGH 7.1
CVE-2026-27170

OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. In versions 1.1.2-alpha and below, URL ingest…

Fix: 1.1.3+
Fix from $1,950 2026-02-21
Phpmoadmin HIGH 8.8
CVE-2019-25451

phpMoAdmin 1.1.5 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized database operations by crafting ma…

No fix yet
Fix from $1,950 2026-02-20
Unclassified HIGH 7.2
CVE-2025-69299

Server-Side Request Forgery (SSRF) vulnerability in Laborator Oxygen oxygen allows Server Side Request Forgery.This issue affects Oxygen: from n/a th…

No fix yet
Fix from $1,950 2026-02-20
Openclaw HIGH 7.6
CVE-2026-26322

OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Gateway tool accepted a tool-supplied `gatewayUrl` without sufficient r…

Fix: 2026.2.14+
Fix from $1,950 2026-02-19
Openclaw HIGH 7.5
CVE-2026-26324

OpenClaw is a personal AI assistant. Prior to version 2026.2.14, OpenClaw's SSRF protection could be bypassed using full-form IPv4-mapped IPv6 litera…

Fix: 2026.2.14+
Fix from $1,950 2026-02-19
Xm Fax MEDIUM 5.3
CVE-2025-8055

Server-Side Request Forgery (SSRF) vulnerability in OpenText™ XM Fax allows Server Side Request Forgery.  The vulnerability could allow an attacker …

Mitigation only
Fix from $1,600 2026-02-19
Sillytavern HIGH 8.5
CVE-2026-26286

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines,…

Fix: 1.16.0+
Fix from $1,950 2026-02-19
Alfresco Transform Service CRITICAL 9.8
CVE-2026-26339

Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the argument injection vulnerability…

Fix: 4.2.3 / 5.2.4+
Fix from $2,300 2026-02-19
Alfresco Transform Service CRITICAL 9.8
CVE-2026-26338

Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve server-side request forgery (SSRF) through the document processing…

Fix: 4.3 / 5.3.0+
Fix from $2,300 2026-02-19
Unclassified HIGH 8.5
CVE-2026-2274

A SSRF and Arbitrary File Read vulnerability in AppSheet Core in Google AppSheet prior to 2025-11-23 allows an authenticated remote attacker to read …

Mitigation only
Fix from $1,950 2026-02-19
Webpdf CRITICAL 9.1
CVE-2025-55853

SoftVision webPDF before 10.0.2 is vulnerable to Server-Side Request Forgery (SSRF). The PDF converter function does not check if internal or externa…

Fix: 10.0.2+
Fix from $2,300 2026-02-19
Unclassified MEDIUM 5.5
CVE-2026-25385

Server-Side Request Forgery (SSRF) vulnerability in KaizenCoders URL Shortify url-shortify allows Server Side Request Forgery.This issue affects URL …

Mitigation only
Fix from $1,600 2026-02-19
Unclassified MEDIUM 6.4
CVE-2026-23803

Server-Side Request Forgery (SSRF) vulnerability in Burhan Nasir Smart Auto Upload Images smart-auto-upload-images allows Server Side Request Forgery…

Mitigation only
Fix from $1,600 2026-02-19
Unclassified MEDIUM 5.6
CVE-2026-2711

A vulnerability has been found in zhutoutoutousan worldquant-miner up to 1.0.9. The impacted element is an unknown function of the file worldquant-mi…

Mitigation only
Fix from $1,600 2026-02-19
Unclassified MEDIUM 6.4
CVE-2025-12375

The Printful Integration for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.2.…

Mitigation only
Fix from $1,600 2026-02-19