Vulnerability index

Browse CVEs

2,810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 8.5 CVE-2026-61430 PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostnames at check time but re-reso… Mitigation only Fix from $1,9502026-07-15 HIGH 8.2 CVE-2026-48290 CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the contex… C2pa after 0.84.0 Fix from $1,9502026-07-14 MEDIUM 6.3 CVE-2026-15750 A weakness has been identified in mastergo-design mastergo-magic-mcp up to 0.2.0. Impacted is the function z.string of the file src/tools/get-compone… Mitigation only Fix from $1,6002026-07-14 HIGH 7.7 CVE-2026-61520 Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery vulnerability in the image p… Mitigation only Fix from $1,9502026-07-14 HIGH 7.7 CVE-2026-48332EPSS 11% ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacke… Coldfusion Mitigation only Fix from $1,9502026-07-14 MEDIUM 6.8 CVE-2026-24234 NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal media fetching functions, where a network-accessible attacker could cause se… Mitigation only Fix from $1,6002026-07-14 HIGH 7.3 CVE-2026-15643 AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with AWS HealthLa… Mitigation only Fix from $1,9502026-07-14 HIGH 8.6 CVE-2026-48736 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, N… Symfony 5.4.43 / 6.4.41+ Fix from $1,9502026-07-14 CRITICAL 9.6 CVE-2026-48259 Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the conte… Experience Manager after 2020.5.0 Fix from $2,3002026-07-14 CRITICAL 10.0 CVE-2026-15409 KEVEPSS 74% A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attack… Sma6210 Firmware Mitigation only Fix from $2,3002026-07-14 MEDIUM 6.5 CVE-2026-55051 Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. Sharepoint Server 16.0.19725.20434+ Fix from $1,6002026-07-14 MEDIUM 5.1 CVE-2026-14645 Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, all… Mitigation only Fix from $1,6002026-07-14 CRITICAL 10.0 CVE-2026-62643 In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to… Webmail 1.6.17 / 1.7.2+ Fix from $2,3002026-07-14 MEDIUM 5.3 CVE-2026-7494 Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-trust… Mitigation only Fix from $1,6002026-07-14 MEDIUM 6.5 CVE-2026-58478 Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated … Sustainable Irrigation Platform after 5.2.16 Fix from $1,6002026-07-14 CRITICAL 9.2 CVE-2026-15183 Multiple input validation vulnerabilities in the Snowflake Spark Connector (spark-snowflake) versions prior to 3.2.1 can allow attackers to exfiltrat… Mitigation only Fix from $2,3002026-07-14 MEDIUM 6.3 CVE-2026-15668 A vulnerability has been found in louisho5 picobot up to 0.2.0. This vulnerability affects the function WebTool.Execute of the file internal/agent/to… Mitigation only Fix from $1,6002026-07-14 MEDIUM 6.3 CVE-2026-15628 A security flaw has been discovered in zhayujie chatgpt-on-wechat CowAgent up to 2.1.1. This issue affects the function Vision._download_to_data_url … Patch available Fix from $1,6002026-07-14 MEDIUM 6.3 CVE-2026-15624 A vulnerability has been found in nextlevelbuilder GoClaw 3.13.3-beta.3. Affected by this vulnerability is the function bytePlusDownloadVideo of the … Mitigation only Fix from $1,6002026-07-14 MEDIUM 6.3 CVE-2026-15620 A security vulnerability has been detected in mosaxiv clawlet up to 0.2.10. This affects the function tools.webFetch of the file tools/tool_web_fetch… Mitigation only Fix from $1,6002026-07-14 MEDIUM 6.3 CVE-2026-15619 A weakness has been identified in mosaxiv clawlet up to 0.2.10. The impacted element is the function web_fetch of the file tools/tool_web_fetch.go of… Mitigation only Fix from $1,6002026-07-14 HIGH 7.4 CVE-2026-62240 CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and bloc… Crewai 1.15.1+ Fix from $1,9502026-07-13 HIGH 8.6 CVE-2026-62242 Spring Boot Admin Server before 4.1.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers to register instance… Patch available Fix from $1,9502026-07-13 HIGH 8.5 CVE-2026-62197 OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebSocket URLs. Attackers with lower-tr… Openclaw 2026.6.6+ Fix from $1,9502026-07-13 HIGH 7.4 CVE-2026-49969 Laravel-Mediable before 7.0.0 contains a server-side request forgery vulnerability that allows remote attackers to issue arbitrary HTTP requests from… Patch available Fix from $1,9502026-07-13 HIGH 7.3 CVE-2025-45869 LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server-Side Request Forgery (SSRF). An unauthenticated attacker can exploit th… Mitigation only Fix from $1,9502026-07-13 MEDIUM 6.4 CVE-2026-57413 Server-Side Request Forgery (SSRF) vulnerability in bdthemes Instant Image Generator ai-image allows Server Side Request Forgery.This issue affects I… Mitigation only Fix from $1,6002026-07-13 HIGH 7.2 CVE-2026-57407 Server-Side Request Forgery (SSRF) vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp allows Server Side Request Forgery.Thi… Mitigation only Fix from $1,9502026-07-13 HIGH 7.2 CVE-2026-57372 Server-Side Request Forgery (SSRF) vulnerability in denishua WPJAM Basic wpjam-basic allows Server Side Request Forgery.This issue affects WPJAM Basi… No fix yet Fix from $1,9502026-07-13 MEDIUM 6.5 CVE-2026-49876 Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job temp… Gravitino 1.3.0+ Fix from $1,6002026-07-13