Vulnerability index

Browse CVEs

2,810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Unclassified HIGH 7.5
CVE-2026-64799

Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image UR…

No fix yet
Fix from $1,950 2026-07-23
Telerik Ui For Asp.net Ajax MEDIUM 6.5
CVE-2026-13192

In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature may allow an…

Fix: 2026.2.708+
Fix from $1,600 2026-07-22
N8n MEDIUM 5.4
CVE-2026-65593

n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that la…

Fix: 1.123.64 / 2.29.8+
Fix from $1,600 2026-07-22
Unclassified HIGH 8.6
CVE-2026-65317

Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows un…

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 8.6
CVE-2026-65318

Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to ca…

Mitigation only
Fix from $1,950 2026-07-21
Unclassified HIGH 8.2
CVE-2026-65056

mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loo…

No fix yet
Fix from $1,950 2026-07-21
Unclassified CRITICAL 9.3
CVE-2026-65057

Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary …

Mitigation only
Fix from $2,300 2026-07-21
Lmdeploy HIGH 8.6
CVE-2026-63764

LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within t…

Fix: after 0.14.0
Fix from $1,950 2026-07-21
Unclassified HIGH 7.1
CVE-2026-47695

CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to version 1.119.0, CC-Tweaked's HTTP API …

No fix yet
Fix from $1,950 2026-07-21
Unclassified MEDIUM 6.5
CVE-2026-46556

FlaskBB is a Forum Software written in Python using the micro framework Flask. Prior to version 2.2.1, a Server-Side Request Forgery (SSRF) vulnerabi…

No fix yet
Fix from $1,600 2026-07-21
Unclassified MEDIUM 5.5
CVE-2026-47390

PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `spider_tools` URL…

No fix yet
Fix from $1,600 2026-07-21
Unclassified MEDIUM 6.8
CVE-2026-15927

A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/mirror.py accept an exte…

No fix yet
Fix from $1,600 2026-07-21
Unclassified MEDIUM 6.4
CVE-2026-64626

AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the encoder download-by-URL flow du…

No fix yet
Fix from $1,600 2026-07-20
Unclassified HIGH 7.5
CVE-2026-51031

FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. This allows a remote attacker …

No fix yet
Fix from $1,950 2026-07-20
Unclassified MEDIUM 5.3
CVE-2026-44583

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the PayPal webhook endpoint /ext…

No fix yet
Fix from $1,600 2026-07-20
Unclassified MEDIUM 5.0
CVE-2026-63730

HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to make reques…

No fix yet
Fix from $1,600 2026-07-20
Unclassified HIGH 7.7
CVE-2026-63731

HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to arbitrary i…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.7
CVE-2026-63769

Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated us…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.7
CVE-2026-63107

LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey template endpoint that allows authen…

No fix yet
Fix from $1,950 2026-07-20
Unclassified MEDIUM 5.1
CVE-2026-60033

Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to an SSRF vulne…

No fix yet
Fix from $1,600 2026-07-20
Mailpit MEDIUM 5.8
CVE-2026-45709

Mailpit is an email testing tool and API for developers. The fix for GHSA-6jxm-fv7w-rw5j (CVE-2026-23845, "Server-Side Request Forgery (SSRF) via HTM…

Fix: 1.30.0+
Fix from $1,600 2026-07-20
Syncope HIGH 8.1
CVE-2026-62418

Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources check. This issue af…

Fix: 4.0.7 / 4.1.2+
Fix from $1,950 2026-07-20
Surrealdb MEDIUM 6.4
CVE-2026-63743

SurrealDB before 3.1.0 contains a capability bypass vulnerability in HTTP redirect handling that allows authenticated users to circumvent port-scoped…

Fix: 3.1.0+
Fix from $1,600 2026-07-20
Unclassified MEDIUM 6.3
CVE-2026-16223

A vulnerability was determined in 1Panel-dev CordysCRM up to 1.4.1. Impacted is the function getSqlBotSrc of the file backend/crm/src/main/java/cn/co…

No fix yet
Fix from $1,600 2026-07-19
Unclassified MEDIUM 6.3
CVE-2026-16222

A vulnerability was found in 1Panel-dev CordysCRM up to 1.4.1. This issue affects some unknown processing of the file backend/crm/src/main/java/cn/co…

No fix yet
Fix from $1,600 2026-07-19
Unclassified MEDIUM 6.3
CVE-2026-16196

A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Impacted is the function isPrivateOrRestrictedIP of the file pkg/tools/integration/web…

No fix yet
Fix from $1,600 2026-07-18
Unclassified MEDIUM 6.3
CVE-2026-16194

A vulnerability was determined in zhayujie CowAgent up to 2.1.1. This affects the function WebFetch.execute of the file agent/tools/web_fetch/web_fet…

No fix yet
Fix from $1,600 2026-07-18
Unclassified HIGH 7.3
CVE-2026-16128

A security flaw has been discovered in zevorn rt-claw up to 0.2.0. This impacts the function receiver_thread of the file claw/services/swarm/swarm.c …

No fix yet
Fix from $1,950 2026-07-18
Unclassified HIGH 7.3
CVE-2026-16127

A vulnerability was identified in zevorn rt-claw up to 0.2.0. This affects the function claw_net_get/claw_net_post of the file claw/tools/tool_net.c …

No fix yet
Fix from $1,950 2026-07-18
Unclassified MEDIUM 6.3
CVE-2026-16124

A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.15.0-beta.32. This affects the function CheckSSRF/isPrivateIP of the fi…

No fix yet
Fix from $1,600 2026-07-18