Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Trusttunnel HIGH 7.1
CVE-2026-24902

TrustTunnel is an open-source VPN protocol with a server-side request forgery and and private network restriction bypass in versions prior to 0.9.114…

Fix: 0.9.114+
Fix from $1,950 2026-01-29
Nocodb MEDIUM 6.4
CVE-2026-24767

NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a blind Server-Side Request Forgery (SSRF) vulnerability exists …

Fix: 0.301.0+
Fix from $1,600 2026-01-28
Discourse CRITICAL 9.9
CVE-2025-68662

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, a hostname validation issue in Final…

Fix: 3.5.4 / 2025.11.2+
Fix from $2,300 2026-01-28
Unclassified HIGH 7.2
CVE-2025-14610

The TableMaster for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3.6. This is …

Mitigation only
Fix from $1,950 2026-01-28
Vllm HIGH 7.1
CVE-2026-24779

vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.14.1, a Server-Side Request Forgery (SSRF) vulnerability…

Fix: 0.14.1+
Fix from $1,950 2026-01-27
Squidex HIGH 8.8
CVE-2026-24736

Squidex is an open source headless content management system and content management hub. Versions of the application up to and including 7.21.0 allow…

Fix: after 7.21.0
Fix from $1,950 2026-01-27
Unclassified MEDIUM 6.4
CVE-2026-0746

The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.3.2 via the 'get_audio' funct…

Mitigation only
Fix from $1,600 2026-01-27
Kyverno CRITICAL 9.9
CVE-2026-22039

Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have a critical authorization bo…

Fix: 1.15.3 / 1.16.3+
Fix from $2,300 2026-01-27
Skipper HIGH 8.1
CVE-2026-24470

Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.24.0, when running Skipper as an Ingress controller, users wi…

Fix: 0.24.0+
Fix from $1,950 2026-01-26
Omada Controller MEDIUM 5.3
CVE-2025-9522

Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests to internal services, which ma…

Fix: 6.0+
Fix from $1,600 2026-01-26
Unclassified HIGH 7.2
CVE-2026-0807

The Frontis Blocks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.1.6. This is due to insu…

Mitigation only
Fix from $1,950 2026-01-24
Unclassified MEDIUM 5.4
CVE-2026-24548

Server-Side Request Forgery (SSRF) vulnerability in princeahmed Radio Player radio-player allows Server Side Request Forgery.This issue affects Radio…

Mitigation only
Fix from $1,600 2026-01-23
Unclassified HIGH 7.5
CVE-2026-24138

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1754 and below contain an unauthenticated SSRF vu…

Mitigation only
Fix from $1,950 2026-01-23
Rekor MEDIUM 5.3
CVE-2026-24117

Rekor is a software supply chain transparency log. In versions 1.4.3 and below, attackers can trigger SSRF to arbitrary internal services because /ap…

Fix: 1.5.0+
Fix from $1,600 2026-01-22
Unclassified MEDIUM 5.4
CVE-2026-24381

Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods PhotoMe photome allows Server Side Request Forgery.This issue affects PhotoMe: from n/…

Mitigation only
Fix from $1,600 2026-01-22
Unclassified MEDIUM 5.4
CVE-2026-22358

Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Electrician - Electrical Service WordPress electrician allows Server Side Request F…

Mitigation only
Fix from $1,600 2026-01-22
Unclassified HIGH 7.2
CVE-2025-68030

Server-Side Request Forgery (SSRF) vulnerability in WP Messiah Frontis Blocks frontis-blocks allows Server Side Request Forgery.This issue affects Fr…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified MEDIUM 6.4
CVE-2025-67961

Server-Side Request Forgery (SSRF) vulnerability in Marco van Wieren WPO365 wpo365-login allows Server Side Request Forgery.This issue affects WPO365…

Mitigation only
Fix from $1,600 2026-01-22
Unclassified MEDIUM 5.4
CVE-2025-62741

Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Pool Services pool-services allows Server Side Request Forgery.This issue affects P…

Mitigation only
Fix from $1,600 2026-01-22
Html2pdf HIGH 7.5
CVE-2025-56589

A Local File Inclusion (LFI) and a Server-Side Request Forgery (SSRF) vulnerability was found in the InsertFromHtmlString() function of the Apryse HT…

Fix: after 11.7.0
Fix from $1,950 2026-01-22
Unclassified MEDIUM 5.8
CVE-2026-1180

A flaw was identified in Keycloak’s OpenID Connect Dynamic Client Registration feature when clients authenticate using private_key_jwt. The issue all…

No fix yet
Fix from $1,600 2026-01-20
Chainlit HIGH 7.7
CVE-2026-22219

Chainlit versions prior to 2.9.4 contain a server-side request forgery (SSRF) vulnerability in the /project/element update flow when configured with …

Fix: 2.9.4+
Fix from $1,950 2026-01-20
Mailpit HIGH 7.5
CVE-2026-23845

Mailpit is an email testing tool and API for developers. Versions prior to 1.28.3 are vulnerable to Server-Side Request Forgery (SSRF) via HTML Check…

Fix: 1.28.3+
Fix from $1,950 2026-01-19
Weasyprint HIGH 7.5
CVE-2025-68616

WeasyPrint helps web developers to create PDF documents. Prior to version 68.0, a server-side request forgery (SSRF) protection bypass exists in Weas…

Fix: 68.0+
Fix from $1,950 2026-01-19
Teamwork Management System CRITICAL 9.8
CVE-2026-1062

A flaw has been found in xiweicheng TMS up to 2.28.0. This affects the function Summary of the file src/main/java/com/lhjz/portal/util/HtmlUtil.java.…

Fix: after 2.28.0
Fix from $2,300 2026-01-17
Unclassified HIGH 7.7
CVE-2026-23529

Kafka Connect BigQuery Connector is an implementation of a sink connector from Apache Kafka to Google BigQuery. Prior to 2.11.0, there is an arbitrar…

Patch available
Fix from $1,950 2026-01-16
Validator MEDIUM 5.3
CVE-2025-15104

Nu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arbitrary HTTP/HTTPS requests to…

Fix: 2026-01-11+
Fix from $1,600 2026-01-16
The Librarian HIGH 7.5
CVE-2026-0613

The Librarian contains an internal port scanning vulnerability, facilitated by the `web_fetch` tool, which can be used with SSRF-style behavior to pe…

Mitigation only
Fix from $1,950 2026-01-16
Unclassified MEDIUM 5.0
CVE-2025-14793

The DK PDF – WordPress PDF Generator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.3.0 vi…

Mitigation only
Fix from $1,600 2026-01-16
Lucy Xss Filter MEDIUM 6.1
CVE-2026-23768

lucy-xss-filter before commit 7c1de6d allows an attacker to induce server-side HEAD requests to arbitrary URLs when the ObjectSecurityListener or Emb…

Fix: 2025-06-08+
Fix from $1,600 2026-01-16