Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 7.4 CVE-2026-53782 Summarize before 0.17.0 contains a server-side request forgery vulnerability that allows attackers who control a podcast RSS feed to direct the host … Patch available Fix from $1,9502026-06-11 HIGH 7.7 CVE-2026-47170 Garlic-Hub manages digital signage network — devices, content, and playlists — from a single self-hosted interface. Prior to version 1.1, authenticat… Patch available Fix from $1,9502026-06-11 MEDIUM 5.3 CVE-2026-46698 Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.9, Fediverse Embeds registered the unauthenticated AJAX action wp_aj… Patch available Fix from $1,6002026-06-11 MEDIUM 6.5 CVE-2026-47157 aiograpi is an asynchronous Instagram API for Python. aiograpi versions before 0.9.10 accepted server-supplied signup challenge paths and used them t… Patch available Fix from $1,6002026-06-11 HIGH 7.5 CVE-2026-46697 Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.8, Fediverse Embeds registered an unauthenticated REST route ftf/med… Patch available Fix from $1,9502026-06-11 HIGH 8.6 CVE-2026-44492 Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. Wh… Axios 0.32.0 / 1.16.0+ Fix from $1,9502026-06-11 MEDIUM 5.4 CVE-2026-3341 IBM Langflow Desktop 1.0.0 through 1.9.2 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker t… Langflow Desktop 1.9.3+ Fix from $1,6002026-06-11 MEDIUM 5.3 CVE-2026-48998 guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host header validation when parsing … Psr 7 2.10.2+ Fix from $1,6002026-06-11 MEDIUM 6.5 CVE-2026-9204 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that un… GitLab 18.10.8 / 18.11.5+ Fix from $1,6002026-06-11 HIGH 8.6 CVE-2026-40999 When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebService… Mitigation only Fix from $1,9502026-06-11 HIGH 8.6 CVE-2026-50131 Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Fedify previously addressed SSRF/internal network access in… No fix yet Fix from $1,9502026-06-10 MEDIUM 6.9 CVE-2026-46683 Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.0, there is a SSRF and local f… Mitigation only Fix from $1,6002026-06-10 MEDIUM 5.9 CVE-2026-50127 Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_RESTRICT_PRIVATE did not properly account for som… Patch available Fix from $1,6002026-06-10 HIGH 7.6 CVE-2026-20252 In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.4.2604.3, 10.3.2512.12, 10.2.2510… Splunk 9.3.13 / 9.3.2411.132+ Fix from $1,9502026-06-10 MEDIUM 6.5 CVE-2026-48858 Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ftp_internal module) allows FTP bounce attacks and SSRF via an unvalidated PASV r… Erlang\/inets 1.2.3.1 / 1.2.4.1+ Fix from $1,6002026-06-10 MEDIUM 6.5 CVE-2026-45561 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the /smon/agent/{version,uptime… Mitigation only Fix from $1,6002026-06-10 CRITICAL 10.0 CVE-2026-47938 Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could resu… Campaign after 7.4.2 Fix from $2,3002026-06-09 MEDIUM 5.0 CVE-2026-45502EPSS 20% Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. Exchange Server 15.02.2562.043+ Fix from $1,6002026-06-09 MEDIUM 6.5 CVE-2026-45503 Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. Exchange Server 15.02.2562.043+ Fix from $1,6002026-06-09 HIGH 8.8 CVE-2026-45504 Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. Exchange Server 15.02.2562.043+ Fix from $1,9502026-06-09 MEDIUM 6.1 CVE-2026-45501 Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. Exchange Server 15.02.2562.043+ Fix from $1,6002026-06-09 MEDIUM 6.5 CVE-2026-41854 Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed … Spring Framework 6.2.18.1 / 7.0.7.1+ Fix from $1,6002026-06-09 HIGH 7.3 CVE-2026-11437 A flaw has been found in perfree go-fastdfs-web up to 1.3.7. Affected is the function checkServer of the file /install/checkServer of the component I… Mitigation only Fix from $1,9502026-06-06 HIGH 8.3 CVE-2026-11424 A server-side request forgery (SSRF) vulnerability exists in a GraphQL service component shared by Altium Enterprise Server and Altium 365. An authen… Mitigation only Fix from $1,9502026-06-05 HIGH 8.7 CVE-2026-46391 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 9.0.1 and prior to version 26.0.0 of @haxtheweb/open-apis, m… Mitigation only Fix from $1,9502026-06-05 HIGH 7.1 CVE-2026-46393 HAX CMS helps manage microsite universe with PHP or NodeJs backends. An authenticated Server-Side Request Forgery (SSRF) vulnerability in versions pr… Mitigation only Fix from $1,9502026-06-05 MEDIUM 5.3 CVE-2026-11346 A Server-Side Request Forgery (SSRF) vulnerability in the custom process creation feature of linqi allows an authenticated attacker to probe internal… Mitigation only Fix from $1,6002026-06-05 HIGH 7.2 CVE-2026-10586 The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in al… Mitigation only Fix from $1,9502026-06-05 CRITICAL 9.9 CVE-2026-43986 Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose a public `/image/<hash>` route that re… Mitigation only Fix from $2,3002026-06-04 HIGH 7.3 CVE-2026-10771 A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-common/src/main/java/com/zbkj… Mitigation only Fix from $1,9502026-06-03