Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 7.5 CVE-2026-55994 Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam… Camel 4.18.3 / 4.21.0+ Fix from $1,9502026-07-06 HIGH 7.5 CVE-2026-55993 Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam… Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 HIGH 7.5 CVE-2026-46726 Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam… Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 CRITICAL 9.1 CVE-2026-48203 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Validation, Server-Side Request Fo… Camel 4.14.8 / 4.18.3+ Fix from $2,3002026-07-06 CRITICAL 9.1 CVE-2026-48205 Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component. The camel-dns producers read DNS operatio… Camel 4.14.8 / 4.18.3+ Fix from $2,3002026-07-06 MEDIUM 6.3 CVE-2026-14748 A flaw has been found in AIAnytime Awesome-MCP-Server up to a884bb51bcd99e08e14fd712c749d55d9d9a13ab. Affected by this issue is some unknown function… Mitigation only Fix from $1,6002026-07-05 MEDIUM 6.5 CVE-2026-58418 SSRF via HTTP Redirect in Repository Migration Patch available Fix from $1,6002026-07-03 HIGH 7.4 CVE-2026-57993 Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. Edge Chromium 150.0.4078.48+ Fix from $1,9502026-07-03 MEDIUM 5.4 CVE-2026-58278 Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. Edge Chromium 150.0.4078.48+ Fix from $1,6002026-07-03 MEDIUM 6.5 CVE-2026-57987 Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. Edge Chromium 150.0.4078.48+ Fix from $1,6002026-07-03 CRITICAL 9.6 CVE-2026-22874 Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering. Patch available Fix from $2,3002026-07-03 HIGH 8.5 CVE-2026-10055 In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the … Mitigation only Fix from $1,9502026-07-03 MEDIUM 5.5 CVE-2026-11397 The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and including 3.9.30 via the wpie_i… No fix yet Fix from $1,6002026-07-03 HIGH 8.8 CVE-2026-45499 Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network. Azure Openai Mitigation only Fix from $1,9502026-07-02 HIGH 8.8 CVE-2026-57100 Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a ne… Entra Provisioning Service Mitigation only Fix from $1,9502026-07-02 MEDIUM 5.8 CVE-2026-59101 AutoBangumi before 3.2.8 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated remote attackers to probe internal n… Patch available Fix from $1,6002026-07-02 HIGH 7.7 CVE-2026-59095 LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attackers to direct internal HTTP req… Patch available Fix from $1,9502026-07-02 HIGH 7.5 CVE-2026-55113 A malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF) vulnerability found in UniFi Talk Application to exec… Unifi Talk Application 5.2.2+ Fix from $1,9502026-07-02 CRITICAL 9.9 CVE-2026-55115 A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to es… Unifi Protect 7.1.83+ Fix from $2,3002026-07-02 HIGH 8.8 CVE-2026-54401 A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such… Unifi Os Server after 5.1.15 Fix from $1,9502026-07-02 MEDIUM 6.4 CVE-2026-57681 Subscriber Server Side Request Forgery (SSRF) in GeoDirectory <= 2.8.161 versions. Mitigation only Fix from $1,6002026-07-02 HIGH 7.2 CVE-2026-57348 Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions. Mitigation only Fix from $1,9502026-07-02 MEDIUM 5.1 CVE-2026-54430 liboauth2 is vulnerable to Server-Side Request Forgery in oauth2_jose_jwks_aws_alb_resolve() function. The AWS ALB verifier reads both signer and kid… Patch available Fix from $1,6002026-07-02 HIGH 8.2 CVE-2026-14336 PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith(' https://ci.eclipse.org ') in is_issuer_known, pia… Mitigation only Fix from $1,9502026-07-02 MEDIUM 6.9 CVE-2026-55791 Craft CMS is a content management system (CMS). Versions 4.0.0-RC1 and above, prior to 4.18.0 and 5.0.0-RC1, and above, prior to 5.10.0, are vulnerab… Patch available Fix from $1,6002026-07-02 HIGH 7.8 CVE-2026-24242 NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause server-side request forgery. A successful exploit of this vul… Nemo Megatron Bridge 0.4.1+ Fix from $1,9502026-07-01 CRITICAL 9.0 CVE-2026-13603 The payment integration pretix-oppwa provides support for the payment providers VR Payment, Hobex, and potentially others based on Oppwa's technolo… Mitigation only Fix from $2,3002026-07-01 MEDIUM 5.0 CVE-2026-56399 Open WebUI before 0.6.27 contains a server-side request forgery vulnerability in the /api/v1/retrieval/process/web endpoint that allows authenticated… Patch available Fix from $1,6002026-06-30 CRITICAL 10.0 CVE-2026-13773 IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.… Websphere Extreme Scale after 8.6.1.6 Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-11714 IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled. Websphere Application Server 26.0.0.8+ Fix from $2,3002026-06-30