Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 6.5 CVE-2026-10546 IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the URL component ( src/lfx/src/lfx/components/da… Langflow after 1.9.3 Fix from $1,6002026-06-30 HIGH 8.2 CVE-2026-10564 IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). The legacy RSSReaderComponent in rss.py and SearXNG component in … Langflow after 1.9.6 Fix from $1,9502026-06-30 CRITICAL 9.8 CVE-2026-11546 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-… Websphere Application Server 26.0.0.8+ Fix from $2,3002026-06-30 HIGH 8.5 CVE-2026-10129 IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) protection bypass vulnerability in the API Request component. An a… Langflow after 1.9.3 Fix from $1,9502026-06-30 HIGH 8.6 CVE-2026-48285 ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security fe… Coldfusion Mitigation only Fix from $1,9502026-06-30 HIGH 8.5 CVE-2026-57947 Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint that allows authenticated users to r… Mitigation only Fix from $1,9502026-06-29 HIGH 8.6 CVE-2026-56285 Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded default HMAC key, allowing unauthen… Patch available Fix from $1,9502026-06-29 CRITICAL 9.6 CVE-2026-13751 Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request forgery. The SQL statement reade… Snowflake Cli 3.19.0+ Fix from $2,3002026-06-29 MEDIUM 6.3 CVE-2026-13540 A security flaw has been discovered in GitBucket up to 4.46.1. This affects the function Git.cloneRepository.setURI of the file src/main/scala/gitbuc… Patch available Fix from $1,6002026-06-29 CRITICAL 10.0 CVE-2026-49869 Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().… Kestra 1.0.45 / 1.3.21+ Fix from $2,3002026-06-26 HIGH 7.1 CVE-2026-54353 Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypass Budibase's SSRF blacklist t… Budibase 3.39.9+ Fix from $1,9502026-06-26 HIGH 8.5 CVE-2026-56663 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.52, an authen… Mitigation only Fix from $1,9502026-06-26 MEDIUM 5.0 CVE-2026-28385 In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import functionality allows authenticated… Lxd after 6.9 Fix from $1,6002026-06-26 MEDIUM 6.4 CVE-2026-56026 Subscriber Server Side Request Forgery (SSRF) in utm.codes <= 1.9.0 versions. Mitigation only Fix from $1,6002026-06-26 MEDIUM 6.5 CVE-2026-4339 Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in… Mattermost Server 10.11.19 / 11.5.7+ Fix from $1,6002026-06-26 CRITICAL 10.0 CVE-2026-2053 The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled inpu… Api Manager 3.1.0.360 / 3.2.0.465+ Fix from $2,3002026-06-26 MEDIUM 6.4 CVE-2026-13318 A server-side request forgery (SSRF) flaw was found in KubeVirt's virt-api port-forward handler. When processing a port-forward request to a VirtualM… Kubevirt after 4.22.0 Fix from $1,6002026-06-26 HIGH 7.4 CVE-2026-12992 A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.wsdl.importDocuments feature. W… Build Of Apicurio Registry after 3.2 Fix from $1,9502026-06-25 HIGH 8.2 CVE-2026-12473 Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter without validation. A global aut… Mitigation only Fix from $1,9502026-06-25 HIGH 8.5 CVE-2026-56771 NewsBlur before version 14.5.0 contains a server-side request forgery vulnerability in the add_url endpoint that allows authenticated users to make a… Patch available Fix from $1,9502026-06-25 MEDIUM 6.4 CVE-2026-56779 MaxKB before 2.10.0 contains a server-side request forgery vulnerability in tool creation and update endpoints that allows authenticated users to mak… Patch available Fix from $1,6002026-06-25 HIGH 8.5 CVE-2026-56769 Huly Platform through 0.7.423, fixed in commit 68cbf8a contains an authenticated server-side request forgery vulnerability in the /import endpoint of… Patch available Fix from $1,9502026-06-25 HIGH 8.3 CVE-2026-55412 ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts… Mitigation only Fix from $1,9502026-06-25 MEDIUM 6.5 CVE-2026-54033 LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, LibreChat allows users to configure custom OpenAI-com… Librechat after 0.8.3 Fix from $1,6002026-06-25 CRITICAL 9.1 CVE-2026-55455 Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the outbound HTTP host filter applied by WebClientUtils (… Appsmith 2.1+ Fix from $2,3002026-06-24 HIGH 7.2 CVE-2026-50189 Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, Appsmith's bundled supervisord exposes an XML-RPC interfa… Appsmith 2.1+ Fix from $1,9502026-06-24 HIGH 8.7 CVE-2026-52805 Gogs is an open source self-hosted Git service. Prior to 0.14.3, a Server-Side Request Forgery (SSRF) vulnerability exists in the repository migratio… Patch available Fix from $1,9502026-06-24 HIGH 8.3 CVE-2026-47267 Gogs is an open source self-hosted Git service. Prior to 0.14.3, the fix for CVE-2022-1285 prevents adding webooks or running webhooks with URLs with… Patch available Fix from $1,9502026-06-24 HIGH 8.7 CVE-2026-46348 Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, the list of disallowed IP address ra… Mitigation only Fix from $1,9502026-06-24 HIGH 8.6 CVE-2026-47389 Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, when using Ruby versions older than … Mitigation only Fix from $1,9502026-06-24