Vulnerability index

Browse CVEs

2,810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Unclassified HIGH 7.4
CVE-2026-50236

An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without …

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.4
CVE-2026-50237

A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelm…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.7
CVE-2026-73160

Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_search_events endpoints. The URL validation rou…

No fix yet
Fix from $4,900 2026-08-11
Unclassified CRITICAL 9.1
CVE-2026-19516

A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the…

No fix yet
Fix from $5,750 2026-08-11
Unclassified MEDIUM 6.3
CVE-2026-72916

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, PrivateAddressCheck.pri…

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 6.9
CVE-2026-72761

The webhook URL validator in `website/notifications/webhooks.py` uses `ip.is_global` to reject non-public addresses after DNS resolution. IPv6 transi…

No fix yet
Fix from $4,000 2026-08-10
Unclassified HIGH 7.7
CVE-2026-72591

A server-side request forgery (SSRF) vulnerability in gabehf/Koito through v0.3.2 allows an authenticated user to make the server perform HTTP reques…

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 8.6
CVE-2026-72581

A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to make the Xiaomi smart spe…

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 7.7
CVE-2026-72566

A server-side request forgery (SSRF) vulnerability in automatisch through commit 41f3c56 allows a low-privileged authenticated user with 'manage Flow…

No fix yet
Fix from $4,900 2026-08-10
Unclassified MEDIUM 5.0
CVE-2026-19075

All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=<post_id>` on any `aiovg_videos` post (`public/…

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 5.3
CVE-2026-14860

The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side request built from user-supplied input, allowing…

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 6.3
CVE-2026-19375

A vulnerability was detected in dmitriiweb article-scraper-mcp 1.0.0. This vulnerability affects the function fetch_article of the file news_scraper_…

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 5.3
CVE-2026-19373

A weakness has been identified in PhialsBasement KoboldCPP-MCP-Server 1.0.0. Affected by this issue is the function makeRequest of the file src/index…

No fix yet
Fix from $4,000 2026-08-09
Unclassified HIGH 7.3
CVE-2026-19374

A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of…

No fix yet
Fix from $4,900 2026-08-09
Unclassified MEDIUM 5.3
CVE-2026-19369

A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. This affects the function axios.get of the file src/index.ts of the component add_attac…

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 6.3
CVE-2026-19367

A vulnerability has been found in NocteDefensor LudusMCP 1.0.24. Affected by this vulnerability is an unknown functionality of the file src/tools/ran…

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 6.3
CVE-2026-19339

A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is the function ReadResourceReques…

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 6.3
CVE-2026-19340

A weakness has been identified in anubissbe ProjectHub-Mcp up to 5.0.0. This affects an unknown function of the file backend-fix/complete_backend.js …

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 5.3
CVE-2026-19337

A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/index.ts of the component rea…

No fix yet
Fix from $4,000 2026-08-09
Unclassified HIGH 7.7
CVE-2026-67620

Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_L…

No fix yet
Fix from $1,950 2026-08-08
Unclassified HIGH 8.7
CVE-2026-47662

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling …

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 8.6
CVE-2026-47664

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling …

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 6.3
CVE-2026-19246

A vulnerability has been found in HKUDS nanobot up to 0.2.1. This affects the function _download_image_data_url of the file nanobot/providers/image_g…

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 8.7
CVE-2026-47659

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling …

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 8.7
CVE-2026-47660

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling …

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 5.1
CVE-2026-17597

Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification feature. A user holding the ne…

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 6.5
CVE-2026-16637

OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers …

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 7.1
CVE-2026-15570

An improper restriction of URL schemes and destinations in the SmartCenter browserseturl command in the Telefunken TE24553B45V2DZ Smart TV running on…

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 7.7
CVE-2026-54204

Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot” parameter, which can be set to network locations using UNC…

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 6.3
CVE-2026-54205

Tobit Laboratories AG TeamDavid's Webbox 's link storing functionality (//ServerClient_celink.htm) accepts a “pathname” parameter, which can be set …

No fix yet
Fix from $1,600 2026-08-07