Vulnerability index

Browse CVEs

2,810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Unclassified HIGH 8.7
CVE-2026-54729

DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_url_safe can treat localhost …

No fix yet
Fix from $1,950 2026-07-31
Unclassified MEDIUM 5.3
CVE-2026-59231

Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to cause outbound HTTP GET requ…

No fix yet
Fix from $1,600 2026-07-31
Mcp Toolbox For Databases MEDIUM 6.1
CVE-2026-14540

A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through…

Fix: 1.5.0+
Fix from $1,600 2026-07-31
Unclassified MEDIUM 6.4
CVE-2026-67530

WACRM is a self-hostable CRM template for WhatsApp. In 0.7.0 and earlier, the automation send_webhook action in src/lib/automations/engine.ts and its…

No fix yet
Fix from $1,600 2026-07-30
Unclassified HIGH 8.5
CVE-2026-66415

Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal res…

No fix yet
Fix from $1,950 2026-07-30
Unclassified MEDIUM 5.3
CVE-2026-64870

MaxKB is an open-source AI assistant for enterprise. In versions 2.0.0 through 2.10.4-lts, UpdateStoreTool.update_tool passes caller-supplied downloa…

No fix yet
Fix from $1,600 2026-07-30
Sglang MEDIUM 6.5
CVE-2026-15974

SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitized image_url, allowing access …

Fix: after 0.5.15
Fix from $1,600 2026-07-30
Unclassified HIGH 8.5
CVE-2026-57862

Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass SSRF protections by supplyin…

No fix yet
Fix from $1,950 2026-07-30
Unclassified HIGH 8.6
CVE-2026-67346

Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery vulnerability in the _is_safe_url function that fails to valida…

No fix yet
Fix from $1,950 2026-07-30
Unclassified MEDIUM 6.9
CVE-2026-54885

Server-Side Request Forgery vulnerability in malach-it Boruta allows an unauthenticated remote attacker to cause the OAuth/OpenID authorization serve…

No fix yet
Fix from $1,600 2026-07-30
Cost Management Metrics Operator MEDIUM 6.8
CVE-2026-18378

A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an a…

No fix yet
Fix from $1,600 2026-07-30
Cost Management Metrics Operator HIGH 7.6
CVE-2026-18381

A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to…

No fix yet
Fix from $1,950 2026-07-30
Cost Management Metrics Operator MEDIUM 6.8
CVE-2026-18382

A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an…

No fix yet
Fix from $1,600 2026-07-30
Unclassified MEDIUM 5.8
CVE-2026-18369

A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP…

No fix yet
Fix from $1,600 2026-07-30
Unclassified HIGH 8.8
CVE-2026-18353

PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and checks its **unverified** `iss` claim against an issuer allowlist using Python's `urlp…

No fix yet
Fix from $1,950 2026-07-30
Pydantic Ai MEDIUM 5.9
CVE-2026-46678

Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.56.0 through 1.98.0, when an application opts a URL in…

Fix: 1.99.0+
Fix from $1,600 2026-07-29
Pydantic Ai MEDIUM 6.8
CVE-2026-54249

Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and 2.0.0b1 through 2.0.0b5, a c…

Fix: 1.105.0+
Fix from $1,600 2026-07-29
Unclassified MEDIUM 6.0
CVE-2026-67435

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to version 6.0.0, lib.url.fetch() …

No fix yet
Fix from $1,600 2026-07-29
Unclassified HIGH 8.3
CVE-2026-67436

Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In 6.0.0 and earlier, the redfi…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 8.5
CVE-2026-67428

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules including src/core/modules/third_par…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 8.5
CVE-2026-67424

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the HTTP modules http.get, http.request, and http.batch in…

No fix yet
Fix from $1,950 2026-07-29
Unclassified CRITICAL 9.3
CVE-2026-67426

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/veri…

No fix yet
Fix from $2,300 2026-07-29
Unclassified HIGH 8.6
CVE-2026-16328

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to overrid…

No fix yet
Fix from $1,950 2026-07-29
Prebid Server CRITICAL 10.0
CVE-2026-54735

Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in …

Mitigation only
Fix from $2,300 2026-07-29
Unclassified HIGH 7.4
CVE-2026-54660

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts getRemo…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 6.1
CVE-2026-54663

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts warmUpR…

No fix yet
Fix from $1,600 2026-07-29
Traffic Server HIGH 7.5
CVE-2026-58189

Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects Apache Traf…

Fix: 9.2.15 / 10.1.4+
Fix from $1,950 2026-07-29
Datamodel Code Generator HIGH 7.5
CVE-2026-55391

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf,…

Fix: 0.63.0+
Fix from $1,950 2026-07-28
Datamodel Code Generator HIGH 8.2
CVE-2026-54690

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf,…

Fix: 0.61.0+
Fix from $1,950 2026-07-28
Unclassified HIGH 8.2
CVE-2026-54691

datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61.0, src/datamodel_code_generator/http.py http.get…

No fix yet
Fix from $1,950 2026-07-28