Vulnerability index

Browse CVEs

2,810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 6.3 CVE-2026-74842 A vulnerability was found in Kira-Pgr PromptShopMCP up to 5bc0cd17358e19a5415d11a531088170d7b81452. Affected is the function download_image of the fi… Fix unknown Fix from $4,0002026-08-17 MEDIUM 5.9 CVE-2026-13700 The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side request and attaches stored third-part… Fix unknown Fix from $4,0002026-08-17 MEDIUM 6.3 CVE-2026-19984 A flaw has been found in jkawamoto mcp-florence2 up to 0.3.13. Affected by this issue is the function get_images of the file src/mcp_florence2/__init… Fix unknown Fix from $4,0002026-08-17 MEDIUM 6.3 CVE-2026-19957 A vulnerability was identified in graphlit graphlit-mcp-server 1.0.1. This affects the function fetch of the file src/tools.ts of the component ssrf-… No fix yet Fix from $4,0002026-08-16 MEDIUM 6.3 CVE-2026-19956 A vulnerability has been found in gomarble-ai facebook-ads-mcp-server 0.1.0. The impacted element is the function fetch_pagination_url of the file se… No fix yet Fix from $4,0002026-08-16 MEDIUM 5.8 CVE-2026-73058 stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blocklist, allowing unauthenticated attackers to bypass … No fix yet Fix from $4,0002026-08-16 HIGH 8.8 CVE-2026-17123 The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form … No fix yet Fix from $4,9002026-08-16 MEDIUM 6.3 CVE-2026-19927 A vulnerability was found in OpenBoxes up to 0.9.7. The impacted element is the function Upload of the file grails-app/controllers/org/pih/warehouse/… No fix yet Fix from $4,0002026-08-16 MEDIUM 5.3 CVE-2026-73845 CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in s… No fix yet Fix from $4,0002026-08-14 MEDIUM 6.7 CVE-2026-46380 compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSFetcher._do_fetch() method pas… No fix yet Fix from $4,0002026-08-14 MEDIUM 5.3 CVE-2026-19770 A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is the function downloadReport of the file src/smadex-… No fix yet Fix from $4,0002026-08-14 MEDIUM 6.3 CVE-2026-19765 A security flaw has been discovered in eyaushev swagger-testcase-mcp 5babb27c951fb404bc2b25ec80593616e49054e5. This vulnerability affects the functio… No fix yet Fix from $4,0002026-08-14 HIGH 7.3 CVE-2026-19753 A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of the file src/mcp-rdf-explorer/… No fix yet Fix from $4,9002026-08-13 HIGH 8.5 CVE-2026-72855 Budibase before 3.40.0 contains server-side request forgery vulnerabilities in OpenAPI query import and REST query execution that allow authenticated… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.3 CVE-2026-19751 A flaw has been found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82. The affected element is the function axios.g… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.3 CVE-2026-19752 A vulnerability was found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82. This affects the function parse-pdf of t… No fix yet Fix from $4,0002026-08-13 HIGH 7.7 CVE-2026-73530 Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that allows attackers to reach internal services by suppl… No fix yet Fix from $4,9002026-08-13 HIGH 8.6 CVE-2026-72777 Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation th… No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-59765 SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata No fix yet Fix from $4,9002026-08-13 MEDIUM 6.3 CVE-2026-58441 SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-58442 Repository migration SSRF via multi-answer DNS allow-list bypass No fix yet Fix from $4,0002026-08-13 HIGH 7.7 CVE-2026-58314 Two SSRF findings in Gitea 1.26.2 No fix yet Fix from $4,9002026-08-13 HIGH 8.5 CVE-2026-57894 Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration No fix yet Fix from $4,9002026-08-13 HIGH 7.4 CVE-2026-49857 auth-fetch-mcp is an MCP server that lets AI assistants fetch content from authenticated web pages. Version 3.0.1 implements SSRF protection in `asse… No fix yet Fix from $4,9002026-08-13 HIGH 7.2 CVE-2026-66704 Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions. No fix yet Fix from $4,9002026-08-13 MEDIUM 6.0 CVE-2026-66654 Subscriber Server Side Request Forgery (SSRF) in Vehica Core <= 1.0.104 versions. No fix yet Fix from $4,0002026-08-13 HIGH 8.7 CVE-2026-49478 Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly foll… No fix yet Fix from $4,9002026-08-13 HIGH 8.5 CVE-2026-73629 Serendipity before 2.6.0 contains a server-side request forgery vulnerability in the serendipity_url_allowed() filter that fails to block hex-encoded… No fix yet Fix from $4,9002026-08-13 HIGH 8.7 CVE-2026-46382 The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, a user-supplied private/local U… No fix yet Fix from $4,9002026-08-13 HIGH 8.1 CVE-2026-18952 Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user … No fix yet Fix from $4,9002026-08-12