Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
CRITICAL 9.1 CVE-2026-9006 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an a… Websphere Application Server 8.5.5.30 / 9.0.5.29+ Fix from $2,3002026-06-22 MEDIUM 6.0 CVE-2026-7253 IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send specially crafted SQL stateme… Watson Speech Services Cartridge 5.3.1+ Fix from $1,6002026-06-22 MEDIUM 6.3 CVE-2026-12813 A vulnerability was detected in activepieces up to 0.83.0. This vulnerability affects the function handleUrlFile in the library packages/server/engin… Mitigation only Fix from $1,6002026-06-21 MEDIUM 6.3 CVE-2026-12798 A weakness has been identified in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function load_openapi_spec_async of the file li… Litellm after 1.82.2 Fix from $1,6002026-06-21 MEDIUM 6.3 CVE-2026-12774 A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function _execute_with_mcp_client o… Litellm after 1.82.2 Fix from $1,6002026-06-21 MEDIUM 6.8 CVE-2026-56342 AVideo through version 27.0 contains a server-side request forgery vulnerability in plugin/Live/test.php that allows authenticated administrators to … Mitigation only Fix from $1,6002026-06-20 MEDIUM 5.4 CVE-2026-56227 Capgo before 12.128.2 contains a server-side request forgery vulnerability in webhook URL validation that allows loopback and internal addresses. Org… Mitigation only Fix from $1,6002026-06-20 MEDIUM 5.3 CVE-2026-49345 Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, a Server-Side Request Forgery… Mitigation only Fix from $1,6002026-06-19 MEDIUM 6.3 CVE-2026-12726 A flaw was found in the AWX GitHub webhook integration. When processing GitHub pull_request webhooks, the controller stores the pull_request.statuses… Mitigation only Fix from $1,6002026-06-19 MEDIUM 6.5 CVE-2026-49359 PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/php-weasyprint` fetches the c… Patch available Fix from $1,6002026-06-19 MEDIUM 6.4 CVE-2026-4328 The Advanced Import plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.6. This is due to the… Mitigation only Fix from $1,6002026-06-19 MEDIUM 6.5 CVE-2026-11989 The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Server-Side Request… Mitigation only Fix from $1,6002026-06-19 HIGH 7.7 CVE-2026-54017 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the terminal-server reverse proxy … Open Webui 0.9.6+ Fix from $1,9502026-06-18 HIGH 8.2 CVE-2025-58175 GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.27.3, a GeoServer that uses `E… Geoserver 2.26.4 / 2.27.3+ Fix from $1,9502026-06-18 HIGH 7.2 CVE-2026-11395 The CF7 to Webhook plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.0 via the pull_the_tri… Mitigation only Fix from $1,9502026-06-18 HIGH 8.2 CVE-2026-48764 TypeBot is a chatbot builder tool. In versions prior to 3.17.2, SSRF validation is implemented by resolving a hostname once and checking whether the … Patch available Fix from $1,9502026-06-18 HIGH 7.5 CVE-2026-48818 Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \… Starlette 1.1.0+ Fix from $1,9502026-06-17 MEDIUM 6.8 CVE-2026-48782 Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.56.0 through 1.101.0, 2.0.0b1, and … Pydantic Ai 1.102.0+ Fix from $1,6002026-06-17 MEDIUM 6.5 CVE-2026-53859 OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparisons using trailing-dot notation… Openclaw 2026.5.26+ Fix from $1,6002026-06-16 HIGH 7.7 CVE-2026-47684 Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.3.0, the private IP blockl… Mitigation only Fix from $1,9502026-06-16 CRITICAL 9.1 CVE-2026-50887 A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internal resourc… Mitigation only Fix from $2,3002026-06-15 HIGH 8.1 CVE-2026-50888 An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Benjamin Jonard Koillection v1.8.0 allows attackers … Mitigation only Fix from $1,9502026-06-15 MEDIUM 6.3 CVE-2026-12210 A vulnerability was detected in universal-tool-calling-protocol python-utcp 1.1.0. This affects an unknown function of the component utcp-gql/utcp-we… Mitigation only Fix from $1,6002026-06-15 MEDIUM 6.5 CVE-2026-53827 OpenClaw before 2026.5.2 contains a credential exposure vulnerability in message.action forwarding that allows model-controlled metadata to forward a… Openclaw 2026.5.2+ Fix from $1,6002026-06-12 MEDIUM 6.4 CVE-2026-47268 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 0.20.0 to before version 2.0.10, an auth… Mitigation only Fix from $1,6002026-06-12 HIGH 7.7 CVE-2026-46717 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, nezha's d… Mitigation only Fix from $1,9502026-06-12 HIGH 7.6 CVE-2026-45012 ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 contain an authenticated server-side request f… Mitigation only Fix from $1,9502026-06-12 MEDIUM 6.3 CVE-2026-50552 Koel is a free, open-source music streaming solution. Prior to version 9.7.1, Koel contains a Server-Side Request Forgery (SSRF) vulnerability in the… Patch available Fix from $1,6002026-06-12 HIGH 7.7 CVE-2026-47260 Koel is a free, open-source music streaming solution. Prior to version 9.3.5, Koel validates the podcast feed URL via the SafeUrl rule (DNS resolutio… Patch available Fix from $1,9502026-06-12 HIGH 7.7 CVE-2026-53812 OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows authenticated users to bypass private-n… Openclaw 2026.5.18+ Fix from $1,9502026-06-11