Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Smolagents CRITICAL 9.8
CVE-2026-2654

A weakness has been identified in huggingface smolagents 1.24.0. Impacted is the function requests.get/requests.post of the component LocalPythonExec…

Fix: after 1.24.0
Fix from $2,300 2026-02-18
Unclassified HIGH 7.1
CVE-2026-22048

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and configured to use Microsoft Entr…

Mitigation only
Fix from $1,950 2026-02-18
Trufusion Enterprise HIGH 7.3
CVE-2025-32355

Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is misconfigured in a way that a…

Fix: 7.10.5.0+
Fix from $1,950 2026-02-17
Unclassified MEDIUM 6.3
CVE-2026-2558

A flaw has been found in GeekAI up to 4.2.4. The affected element is the function Download of the file api/handler/net_handler.go. This manipulation …

Mitigation only
Fix from $1,600 2026-02-16
Cskefu MEDIUM 6.3
CVE-2026-2556

A security vulnerability has been detected in cskefu up to 8.0.1. This issue affects some unknown processing of the file com/cskefu/cc/controller/res…

Fix: after 8.0.1
Fix from $1,600 2026-02-16
Deepaudit CRITICAL 9.8
CVE-2026-2532

A vulnerability was detected in lintsinghua DeepAudit up to 3.0.3. This issue affects some unknown processing of the file backend/app/api/v1/endpoint…

Fix: after 3.0.3
Fix from $2,300 2026-02-16
Mindsdb HIGH 7.3
CVE-2026-2531

A security vulnerability has been detected in MindsDB up to 25.14.1. This vulnerability affects the function clear_filename of the file mindsdb/utili…

Fix: after 25.14.1
Fix from $1,950 2026-02-16
Unclassified MEDIUM 5.0
CVE-2026-1249

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Server-Side Request Forgery in versions 5…

Mitigation only
Fix from $1,600 2026-02-14
Unclassified MEDIUM 5.5
CVE-2026-0745

The User Language Switch plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.10 due to missin…

Mitigation only
Fix from $1,600 2026-02-14
Recipes HIGH 7.7
CVE-2026-25991

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, there is a Blind Server-Side Req…

Fix: 2.5.1+
Fix from $1,950 2026-02-13
Clipbucket MEDIUM 5.0
CVE-2026-26005

ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #45, in Clip Bucket V5, The Remote Play allows creating video entries that r…

Fix: 5.5.3-45+
Fix from $1,600 2026-02-12
GitLab MEDIUM 5.4
CVE-2025-12575

GitLab has remediated an issue in GitLab EE affecting all versions from 18.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under ce…

Fix: 18.6.6 / 18.7.4+
Fix from $1,600 2026-02-11
Unclassified MEDIUM 5.8
CVE-2026-25870

DoraCMS version 3.1 and prior contains a server-side request forgery (SSRF) vulnerability in its UEditor remote image fetch functionality. The applic…

No fix yet
Fix from $1,600 2026-02-10
Azure Devops Server MEDIUM 6.5
CVE-2026-21512

Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network.

Fix: 2022.2.0+
Fix from $1,600 2026-02-10
Unclassified CRITICAL 9.8
CVE-2025-11242

Server-Side Request Forgery (SSRF) vulnerability in Teknolist Computer Systems Software Publishing Industry and Trade Inc. Okulistik allows Server Si…

No fix yet
Fix from $2,300 2026-02-10
Faraday MEDIUM 5.8
CVE-2026-25765

Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Prior to 2.14.1, Faraday's build_exclusive_u…

Fix: 1.10.5 / 2.14.1+
Fix from $1,600 2026-02-09
Unclassified MEDIUM 5.8
CVE-2026-25528

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. The LangSmith SDK's distributed tracing feature is vulnerable to Ser…

Mitigation only
Fix from $1,600 2026-02-09
Craft Cms MEDIUM 6.5
CVE-2026-25492

Craft CMS is a content management system. In Craft versions 3.5.0 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the save_images_Asset GraphQL mutatio…

Fix: 4.16.18 / 5.8.22+
Fix from $1,600 2026-02-09
Craft Cms MEDIUM 6.5
CVE-2026-25493

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQL…

Fix: 4.16.18 / 5.8.22+
Fix from $1,600 2026-02-09
Craft Cms MEDIUM 6.5
CVE-2026-25494

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQ…

Fix: 4.16.18 / 5.8.22+
Fix from $1,600 2026-02-09
Unclassified MEDIUM 5.4
CVE-2026-0632

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.12 via t…

Mitigation only
Fix from $1,600 2026-02-09
Unclassified MEDIUM 5.8
CVE-2026-25904

The Pydantic-AI MCP Run Python tool configures the Deno sandbox with an overly permissive configuration that allows the underlying Python code to acc…

Mitigation only
Fix from $1,600 2026-02-09
Homarr MEDIUM 5.3
CVE-2026-25123

Homarr is an open-source dashboard. Prior to 1.52.0, a public (unauthenticated) tRPC endpoint widget.app.ping accepts an arbitrary url and performs a…

Fix: 1.52.0+
Fix from $1,600 2026-02-06
Pydantic Ai HIGH 8.6
CVE-2026-25580

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.0.26 to before 1.56.0, aServer-Side Reques…

Fix: 1.56.0+
Fix from $1,950 2026-02-06
Unclassified HIGH 7.2
CVE-2026-1294

The All In One Image Viewer Block plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.2 due t…

Mitigation only
Fix from $1,950 2026-02-05
Autogpt Platform CRITICAL 9.8
CVE-2025-62615

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prio…

Fix: 0.6.34+
Fix from $2,300 2026-02-04
Autogpt Platform CRITICAL 9.8
CVE-2025-62616

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prio…

Fix: 0.6.34+
Fix from $2,300 2026-02-04
Glpi CRITICAL 9.1
CVE-2026-22247

GLPI is a free asset and IT management software package. From version 11.0.0 to before 11.0.5, a GLPI administrator can perform SSRF request through …

Fix: 11.0.5+
Fix from $2,300 2026-02-04
Unclassified MEDIUM 5.4
CVE-2026-24961

Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods Grand Blog grandblog allows Server Side Request Forgery.This issue affects Grand Blog:…

Mitigation only
Fix from $1,600 2026-02-03
Business Automation Workflow HIGH 7.1
CVE-2025-13096

IBM Business Automation Workflow containers V25.0.0 through V25.0.0-IF007, V24.0.1 - V24.0.1-IF007, V24.0.0 - V24.0.0-IF007 and IBM Business Automati…

Fix: after 24.0.0
Fix from $1,950 2026-02-02