Vulnerability index

Browse CVEs

2,810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Unclassified MEDIUM 6.3
CVE-2026-54020

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolved a hostname during URL vali…

No fix yet
Fix from $1,600 2026-08-04
Unclassified HIGH 7.1
CVE-2026-70485

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebUI checked whether a user-supp…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.7
CVE-2026-70479

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, with WEB_LOADER_ENGINE=playwright, the…

No fix yet
Fix from $1,950 2026-08-04
Dynamo HIGH 7.5
CVE-2026-47616

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery. A successfu…

Fix: after 1.1.0
Fix from $1,950 2026-08-04
Dynamo HIGH 7.5
CVE-2026-47617

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery via DNS rebi…

Fix: after 1.1.0
Fix from $1,950 2026-08-04
Dynamo HIGH 7.5
CVE-2026-47618

NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause server-side request forgery. A su…

Fix: after 1.1.0
Fix from $1,950 2026-08-04
Dynamo HIGH 7.5
CVE-2026-47613

NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying…

Fix: after 1.1.0
Fix from $1,950 2026-08-04
Dynamo HIGH 7.5
CVE-2026-47614

NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful exploit of this vulnerability …

Fix: after 1.1.0
Fix from $1,950 2026-08-04
Dynamo HIGH 7.5
CVE-2026-47615

NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a crafted URL in a multimodal r…

Fix: after 1.1.0
Fix from $1,950 2026-08-04
Unclassified HIGH 7.6
CVE-2026-69257

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.…

No fix yet
Fix from $1,950 2026-08-04
Unclassified MEDIUM 6.3
CVE-2026-18774

A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file agent/image_gen_provider.py of …

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.3
CVE-2026-18775

A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browser_snapshot of the file tools/…

No fix yet
Fix from $1,600 2026-08-04
Django HIGH 8.8
CVE-2026-15307

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as…

No fix yet
Fix from $1,950 2026-08-04
Unclassified MEDIUM 5.4
CVE-2026-70367

A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS proxy mode. This flaw allows a …

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 5.3
CVE-2026-16536

The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL before performing a server-side …

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.8
CVE-2026-14939

The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetching it server-side, allowing u…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 5.8
CVE-2026-10526

The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoin…

No fix yet
Fix from $1,600 2026-08-04
Edge Chromium MEDIUM 6.1
CVE-2026-66325

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Fix: 151.0.4129.59+
Fix from $1,600 2026-08-04
Campaign CRITICAL 10.0
CVE-2026-48331

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitatio…

Fix: after 7.4.2
Fix from $2,300 2026-08-03
Unclassified HIGH 7.2
CVE-2026-69246

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header sep…

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 5.0
CVE-2026-18736

Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the server to issue arbitrary HTTP GET…

No fix yet
Fix from $1,600 2026-08-03
Unclassified HIGH 7.3
CVE-2026-18647

A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue affects the function isValidT…

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 6.9
CVE-2026-69198

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classificatio…

No fix yet
Fix from $1,600 2026-08-03
Unclassified HIGH 7.7
CVE-2026-69192

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 8.8
CVE-2026-69078

CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report PDF-generation functionality. User-controlled CTI …

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 6.8
CVE-2026-67311

Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fails to validate HTTP redirects …

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 5.3
CVE-2026-13604

The Pixelavo WordPress plugin before 1.5.4 registers an unauthenticated AJAX action, gated only by a nonce that it emits publicly on every front-end…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.5
CVE-2026-52371

A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger component of xxl-job v3.4.0 allows authenticated attackers to scan resource…

No fix yet
Fix from $1,600 2026-07-31
Unclassified HIGH 8.2
CVE-2026-53500

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() …

No fix yet
Fix from $1,950 2026-07-31
Unclassified CRITICAL 9.6
CVE-2026-54725

vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in …

Mitigation only
Fix from $2,300 2026-07-31