Vulnerability index

Browse CVEs

2,810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Unclassified HIGH 8.6
CVE-2026-14869

The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an…

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 7.7
CVE-2026-59931

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through …

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 7.2
CVE-2026-54605

OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parse…

No fix yet
Fix from $1,950 2026-07-28
Java Client HIGH 8.2
CVE-2026-43910

Appium Java Client is the Java language binding for writing Appium tests that conform to the W3C WebDriver protocol. From 8.2.1 until 10.1.1, when di…

Fix: 10.1.1+
Fix from $1,950 2026-07-28
Unclassified MEDIUM 5.1
CVE-2026-67173

Pivotick did not validate the URL scheme of node imagePath values derived from graph data before assigning them to SVG image resources. An attacker a…

No fix yet
Fix from $1,600 2026-07-28
Unclassified HIGH 7.2
CVE-2026-65442

Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.

No fix yet
Fix from $1,950 2026-07-27
Unclassified HIGH 7.2
CVE-2026-61953

Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.

No fix yet
Fix from $1,950 2026-07-27
Artifactory MEDIUM 6.5
CVE-2026-65618

Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifacto…

Fix: 7.133.6+
Fix from $1,600 2026-07-27
Artifactory MEDIUM 6.8
CVE-2026-65923

A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause …

Fix: 7.111.18 / 7.117.25+
Fix from $1,600 2026-07-27
Artifactory MEDIUM 6.5
CVE-2026-65924

JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user …

Fix: 7.111.18 / 7.117.25+
Fix from $1,600 2026-07-27
Artifactory MEDIUM 6.5
CVE-2026-65925

A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.

Fix: 7.111.18 / 7.117.25+
Fix from $1,600 2026-07-27
Next.js MEDIUM 6.5
CVE-2026-64649

Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server A…

Fix: 15.5.21 / 16.2.11+
Fix from $1,600 2026-07-27
Unclassified HIGH 8.4
CVE-2026-16481

A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch-page tool of googleapis/mcp-…

No fix yet
Fix from $1,950 2026-07-27
Next.js MEDIUM 6.1
CVE-2026-64645

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() o…

Fix: 15.5.21 / 16.2.11+
Fix from $1,600 2026-07-27
Unclassified MEDIUM 6.9
CVE-2026-54272

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF thr…

No fix yet
Fix from $1,600 2026-07-27
Unclassified CRITICAL 9.1
CVE-2026-17552

Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call. When the rewr…

No fix yet
Fix from $2,300 2026-07-27
Unclassified HIGH 8.5
CVE-2026-17192

A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to intern…

No fix yet
Fix from $1,950 2026-07-27
Unclassified MEDIUM 5.4
CVE-2026-65558

Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.

No fix yet
Fix from $1,600 2026-07-27
Unclassified HIGH 7.2
CVE-2026-59552

Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer &amp; Embedder <= 1.4.2 versions.

No fix yet
Fix from $1,950 2026-07-27
Unclassified MEDIUM 5.5
CVE-2026-17534

Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal denylist in assertSafeFetchTa…

No fix yet
Fix from $1,600 2026-07-27
Unclassified HIGH 8.6
CVE-2025-15662

The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it se…

No fix yet
Fix from $1,950 2026-07-27
Unclassified MEDIUM 6.3
CVE-2026-17458

A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.t…

No fix yet
Fix from $1,600 2026-07-26
Purview Data Governance CRITICAL 10.0
CVE-2026-57106

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-07-24
Unclassified MEDIUM 5.5
CVE-2026-16910

A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers accept user-supplied URLs withou…

No fix yet
Fix from $1,600 2026-07-24
Unclassified HIGH 8.8
CVE-2026-16870

Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltrati…

No fix yet
Fix from $1,950 2026-07-24
Azure Ai Search HIGH 8.8
CVE-2026-56167

Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 7.7
CVE-2026-63313

9Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The endpoint accepts a user-controll…

No fix yet
Fix from $1,950 2026-07-23
Unclassified HIGH 7.2
CVE-2026-21653

Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery. This issue affects CCure …

No fix yet
Fix from $1,950 2026-07-23
Unclassified HIGH 7.2
CVE-2026-65516

Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.

No fix yet
Fix from $1,950 2026-07-23
Unclassified CRITICAL 9.8
CVE-2026-64873

Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services.

No fix yet
Fix from $2,300 2026-07-23