Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 6.5 CVE-2026-26379 Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configuration. This allows authenticat… Koha after 25.11.00 Fix from $1,6002026-06-03 HIGH 8.6 CVE-2026-20230 KEVEPSS 83% A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM … Unified Communications Manager 14su6+ Fix from $1,9502026-06-03 MEDIUM 6.3 CVE-2026-10690 A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of the file src/tools/filesystem… Patch available Fix from $1,6002026-06-03 MEDIUM 6.3 CVE-2026-10662 A vulnerability was found in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. The affected element is the function requests.get o… Patch available Fix from $1,6002026-06-02 HIGH 8.5 CVE-2026-49120 Medplum before 5.1.14 contains a server-side request forgery vulnerability in the subscription worker that allows authenticated users to perform unau… Patch available Fix from $1,9502026-06-02 MEDIUM 6.3 CVE-2026-10581 A flaw has been found in DedeCMS 5.7.88. Affected by this vulnerability is the function base64_decode of the file /plus/download.php?open=1. This man… Mitigation only Fix from $1,6002026-06-02 MEDIUM 5.0 CVE-2026-49138 Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the web_fetch tool that allows remote attackers to reach inter… Patch available Fix from $1,6002026-06-01 HIGH 7.0 CVE-2026-49139 Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handler that allows remote attacke… Patch available Fix from $1,9502026-06-01 HIGH 7.3 CVE-2026-10287 A vulnerability was determined in SourceCodester SEO Meta Tag Extractor 1.0. This vulnerability affects the function get_headers of the file /index.p… Mitigation only Fix from $1,9502026-06-01 MEDIUM 6.3 CVE-2026-10276 A vulnerability has been found in hekmon8 Jenkins-server-mcp 0.1.0. This vulnerability affects the function jobPath of the file src/index.ts of the c… Mitigation only Fix from $1,6002026-06-01 HIGH 7.3 CVE-2026-10280 A security flaw has been discovered in horizon921 mcpilot 0.1.0. The impacted element is an unknown function of the file client/src/app/api/mcp/call/… Mitigation only Fix from $1,9502026-06-01 MEDIUM 6.3 CVE-2026-10274 A vulnerability was determined in indrasishbanerjee aem-mcp-server up to b5f833aef9b5dfd17a5991b3b18a8a11edbdc583. This impacts the function getAsset… Mitigation only Fix from $1,6002026-06-01 MEDIUM 5.3 CVE-2026-49328 Server-Side Request Forgery (SSRF) in the UrlImageConverter component of Apache Fesod (Incubating) fesod-sheet before 2.0.2-incubating allows attacke… Fesod 2.0.2+ Fix from $1,6002026-06-01 MEDIUM 5.8 CVE-2026-10517 A flaw was found in Clair. The fetcher component makes outbound HTTP requests to attacker-supplied URIs from manifest layer descriptors without IP or… Mitigation only Fix from $1,6002026-06-01 MEDIUM 6.3 CVE-2026-10239 A vulnerability was determined in JeecgBoot up to 3.9.2. The affected element is the function WordUtil.addImage of the file /airag/word/edit. Executi… Mitigation only Fix from $1,6002026-06-01 MEDIUM 6.3 CVE-2026-10240 A vulnerability was identified in JeecgBoot up to 3.9.2. The impacted element is an unknown function of the file /airag/airagModel/test. The manipula… Mitigation only Fix from $1,6002026-06-01 MEDIUM 6.3 CVE-2026-10241 A security flaw has been discovered in jeecgboot The server processes these URLs up to 3.9.1. This affects the function FileDownloadUtils.download2Di… Mitigation only Fix from $1,6002026-06-01 MEDIUM 6.3 CVE-2026-10177 A security vulnerability has been detected in Aider-AI Aider 0.86.3. This affects the function requests.get of the file api_docs.py of the component … Patch available Fix from $1,6002026-05-31 HIGH 7.4 CVE-2026-48555 Spatie Laravel Media Library before version 11.23.0 contains a server-side request forgery vulnerability that allows remote attackers to cause the se… Patch available Fix from $1,9502026-05-29 HIGH 7.7 CVE-2026-44285 FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker … Mitigation only Fix from $1,9502026-05-29 HIGH 7.5 CVE-2026-49372 In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible Teamcity 2025.11.5+ Fix from $1,9502026-05-29 MEDIUM 6.9 CVE-2026-44652 SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines,… Mitigation only Fix from $1,6002026-05-29 HIGH 8.5 CVE-2026-46372 SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines,… Mitigation only Fix from $1,9502026-05-29 MEDIUM 5.4 CVE-2026-45660 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.22 and 6.18.1, the Glide image proxy's URL validation could be b… Mitigation only Fix from $1,6002026-05-29 HIGH 7.7 CVE-2026-10107 MoviePilot v2 contains a server-side request forgery vulnerability in the image proxy endpoint that allows authenticated attackers to request arbitra… Patch available Fix from $1,9502026-05-29 HIGH 7.3 CVE-2026-10068 A flaw has been found in Shibby Tomato 1.28. The affected element is the function send of the file usr/sbin/miniupnpd of the component SUBSCRIBE Call… Mitigation only Fix from $1,9502026-05-29 MEDIUM 6.5 CVE-2026-45609 mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mcp-security framework fails to… Mcp Security 0.1.9+ Fix from $1,6002026-05-29 MEDIUM 6.5 CVE-2026-45619 WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveAsync.json.php, and other locations do not use the… Avideo after 29.0 Fix from $1,6002026-05-29 MEDIUM 6.4 CVE-2026-9557 A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authe… Mitigation only Fix from $1,6002026-05-29 MEDIUM 6.5 CVE-2026-42965 A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQ… Openshift Container Platform Mitigation only Fix from $1,6002026-05-29