Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 5.4 CVE-2026-53946 Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, when re-rendering posts, Ghost would refetch missing image dimensions by issu… Mitigation only Fix from $1,6002026-06-24 MEDIUM 5.8 CVE-2026-53944 Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, when making an external request, it is possible to bypass the IP filter that e… Mitigation only Fix from $1,6002026-06-24 HIGH 8.2 CVE-2026-44016 Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. FIn versions >= 2.82.0… Docling 2.91.0+ Fix from $1,9502026-06-24 HIGH 7.3 CVE-2026-12986 A critical vulnerability in Admin GUI in Payara Server Full 4.x, 5.x, 6.x, 7.x, 7.2026.x, 6.2025.x, 6.2024.x on All platforms that allows the attacke… Mitigation only Fix from $1,9502026-06-24 HIGH 7.1 CVE-2026-57303 Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers able to co… Assembla after 1.4 Fix from $1,9502026-06-24 MEDIUM 6.9 CVE-2026-13150 Server-Side Request Forgery (SSRF) (CWE-918) in the PDF generation endpoint GET /api/reports/{id}/pdf (backend/main.py) in ccyl13 Pentestify 1.0.0 an… Patch available Fix from $1,6002026-06-24 MEDIUM 6.4 CVE-2026-11370 The WP Meta SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.5.18 via the 'new_link' par… Mitigation only Fix from $1,6002026-06-24 HIGH 7.2 CVE-2026-12095 The Kargo Takip plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2 via the 'api_url' paramet… Mitigation only Fix from $1,9502026-06-24 HIGH 7.2 CVE-2026-12100 The URL Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0 via the 'url' parameter. … Mitigation only Fix from $1,9502026-06-24 MEDIUM 5.3 CVE-2026-54514 jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, … Jackson Databind 2.18.8 / 2.21.4+ Fix from $1,6002026-06-23 MEDIUM 5.1 CVE-2026-53927 NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the spreadsheet-fetch endpoint (axiosRequestMake) accepted URLs whose … Mitigation only Fix from $1,6002026-06-23 MEDIUM 5.1 CVE-2026-53930 NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the base-migration endpoint accepted a caller-supplied URL that the mi… Mitigation only Fix from $1,6002026-06-23 MEDIUM 6.9 CVE-2026-53931 NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the spreadsheet-import endpoint axiosRequestMake could be used as a ge… Mitigation only Fix from $1,6002026-06-23 MEDIUM 5.3 CVE-2026-47382 NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the connection-test endpoint opened a raw TCP socket to the user-suppl… Mitigation only Fix from $1,6002026-06-23 HIGH 7.5 CVE-2026-53754 Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.8, the Docker API server's SSRF protection (validate_webhook_url / valida… Crawl4ai 0.8.8+ Fix from $1,9502026-06-23 HIGH 7.5 CVE-2026-53755 Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.9, the Docker API server applied its SSRF destination check to the crawl … Crawl4ai 0.8.9+ Fix from $1,9502026-06-23 HIGH 7.7 CVE-2026-54018 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the SafePlaywrightURLLoader implem… Open Webui 0.9.6+ Fix from $1,9502026-06-23 CRITICAL 9.0 CVE-2026-54157 LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.57, the /webapi/proxy end… Mitigation only Fix from $2,3002026-06-23 HIGH 8.5 CVE-2026-54008 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, backend/open_webui/utils/oauth.py:… Open Webui 0.9.6+ Fix from $1,9502026-06-23 MEDIUM 5.2 CVE-2026-49860 Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when a WebSocket connection was opened, Deno checked the destination hostn… Deno 2.8.1+ Fix from $1,6002026-06-23 MEDIUM 5.4 CVE-2026-50221 In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Dele… Swift 2.35.3 / 2.36.2+ Fix from $1,6002026-06-23 MEDIUM 5.2 CVE-2026-49859 Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when fetch() was called, Deno checked the destination hostname against --d… Deno 2.8.1+ Fix from $1,6002026-06-23 HIGH 7.1 CVE-2026-56275 Flowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node that allows attackers to bypass security validatio… Flowise 3.1.0+ Fix from $1,9502026-06-23 CRITICAL 9.9 CVE-2026-56348 n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options endpoint that allows authenticat… N8n 2.20.0+ Fix from $2,3002026-06-22 HIGH 8.6 CVE-2026-56266 Crawl4AI before 0.8.7 contains a server-side request forgery vulnerability in the /crawl, /crawl/stream, /md, and /llm endpoints that fetch arbitrary… Crawl4ai 0.8.7+ Fix from $1,9502026-06-22 MEDIUM 5.8 CVE-2026-55599 phpseclib is a PHP secure communications library. From 0.1.1 until 1.0.30, 2.0.55, and 3.0.54, when an application validates an untrusted X.509 certi… Phpseclib 1.0.30 / 2.0.55+ Fix from $1,6002026-06-22 HIGH 7.5 CVE-2026-54299 Astro is a web framework. Prior to 6.4.6, Astro SSR apps with prerendered error pages (/404 or /500 using export const prerender = true) fetch those … Astro 6.4.6+ Fix from $1,9502026-06-22 MEDIUM 5.3 CVE-2026-54300 @astrojs/netlify is an adapter that allows Astro to deploy your hybrid or server rendered site to Netlify. Prior to 7.0.13, @astrojs/netlify converts… Mitigation only Fix from $1,6002026-06-22 HIGH 8.2 CVE-2026-50168 Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-r… Angular 19.2.23 / 20.3.22+ Fix from $1,9502026-06-22 MEDIUM 6.1 CVE-2026-46417 Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-n… Angular 19.2.22 / 20.3.21+ Fix from $1,6002026-06-22