Vulnerability index

Browse CVEs

2,810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Unclassified MEDIUM 6.3
CVE-2026-54206

Tobit Laboratories AG TeamDavid's Webbox 's sending email, fax, SMS, etc. functionality accepts a @@INCLUDE command, which can be set to network loc…

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 6.3
CVE-2026-54207

Tobit Laboratories AG TeamDavid's Webbox 's move archive functionality (“!ArcEntryMove”) accepts an arbitrary path, which can be set to network loca…

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 5.4
CVE-2026-16027

Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Request Forgery. This issue affe…

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 8.8
CVE-2026-62857

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the affected 1.9, 1.10, 2.0, 2.1…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 8.6
CVE-2026-53983

Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital-source configuration path th…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 6.4
CVE-2026-45573

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, when VAPID delivery …

No fix yet
Fix from $1,600 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-15732

A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functionality allows authenticated att…

No fix yet
Fix from $2,300 2026-08-06
Escriptorium HIGH 8.5
CVE-2026-18359

Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to ma…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 6.3
CVE-2026-19040

A flaw has been found in MissionSquad mcp-api up to 1.11.9. The affected element is an unknown function of the file src/services/dcrClients.ts. Execu…

No fix yet
Fix from $1,600 2026-08-06
Glassfish CRITICAL 9.6
CVE-2026-12605

In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled …

Fix: 8.0.4+
Fix from $2,300 2026-08-06
Unclassified HIGH 8.5
CVE-2026-18597

The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is restricted, an attacker could t…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 8.2
CVE-2026-16268

The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetching a user-supplied URL on the…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.3
CVE-2026-19000

A vulnerability was identified in JeecgBoot up to 3.9.2. The affected element is an unknown function of the file /airag/chat/send of the component An…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.3
CVE-2026-18973

A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitize_proxy_url of the file serve…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.6
CVE-2026-34966

Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiti…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.7
CVE-2026-55523

PraisonAI is a multi-agent teams system. In versions 1.5.128 through 1.6.57, the praisonaiagents.tools.web_crawl_tools.web_crawl() function is vulner…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.5
CVE-2026-55524

PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the initially supplied URL, …

No fix yet
Fix from $1,950 2026-08-05
Langflow HIGH 7.1
CVE-2026-9081

IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_pro…

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow MEDIUM 6.5
CVE-2026-7657

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and ineffective SSRF protection enfor…

Fix: 1.11.0+
Fix from $1,600 2026-08-05
Application Gateway Operator CRITICAL 9.8
CVE-2026-17617

IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specif…

Fix: after 26.6.0
Fix from $2,300 2026-08-05
Unclassified HIGH 8.5
CVE-2026-9203

A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged ro…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 5.9
CVE-2026-70605

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-b…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 8.5
CVE-2026-71280

go-shiori's DownloadBookmark (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Client with no custom DialContext …

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.6
CVE-2026-71270

Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated with the CustomHtmlSanitizer/SsrfProtectionService SS…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.5
CVE-2026-71271

Memos' webhook URL validation, isReservedIP (internal/webhook/validate.go), checks a candidate IP against a reservedCIDRs list that omits 0.0.0.0/8 a…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.5
CVE-2026-71244

Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, ac…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 7.1
CVE-2026-71211

MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no …

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.5
CVE-2026-71208

KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cluster custom resource's conne…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 6.8
CVE-2026-70620

Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attackers to direct the server to pr…

No fix yet
Fix from $1,600 2026-08-04
Unclassified HIGH 7.5
CVE-2026-66901

Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credenti…

No fix yet
Fix from $1,950 2026-08-04