Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 7.7 CVE-2026-49093 Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configure… Kibana 9.3.3+ Fix from $1,9502026-05-28 HIGH 7.7 CVE-2026-42398 Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured con… Kibana 9.2.8 / 9.3.2+ Fix from $1,9502026-05-28 MEDIUM 5.8 CVE-2026-49129 Music Player Daemon (MPD) before version 0.24.11 contains a server-side request forgery vulnerability in CurlInputPlugin where CURLOPT_FOLLOWLOCATION… Patch available Fix from $1,6002026-05-28 MEDIUM 5.0 CVE-2026-46526 Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.10, the URL checking logic in local-deep-research … Patch available Fix from $1,6002026-05-28 MEDIUM 5.0 CVE-2026-43979 Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.0, PDFService._markdown_to_html() constructs an HT… Patch available Fix from $1,6002026-05-28 MEDIUM 5.0 CVE-2026-46561 pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the PREREQFUNCTION-based private IP check was not appli… Mitigation only Fix from $1,6002026-05-28 HIGH 7.4 CVE-2026-45310 CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.22, the fetch_url tool validates the initial URL's resolved IP address against … Mitigation only Fix from $1,9502026-05-28 HIGH 7.4 CVE-2026-45373 CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, although SSRF is validated against hostnames that resolve to private IPv6 a… Mitigation only Fix from $1,9502026-05-28 HIGH 8.5 CVE-2026-44797 Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot's Webhook data model and associated featur… Nautobot 2.4.33 / 3.1.2+ Fix from $1,9502026-05-28 CRITICAL 9.9 CVE-2026-9813 FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL probe functionality in app/ca… Flowintel 3.3.0+ Fix from $2,3002026-05-28 MEDIUM 6.5 CVE-2026-5737 The Independent Analytics plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.14.9. This is due… Mitigation only Fix from $1,6002026-05-28 MEDIUM 5.3 CVE-2026-48148 Budibase is an open-source low-code platform. Prior to 3.35.3, the VectorDB configuration endpoint in Budibase accepts a host parameter that undergo… No fix yet Fix from $1,6002026-05-27 HIGH 8.5 CVE-2026-48153 Budibase is an open-source low-code platform. Prior to 3.39.0, fetchToken in the OAuth2 SDK makes a POST to a builder-supplied URL with plain node-fe… Mitigation only Fix from $1,9502026-05-27 MEDIUM 5.1 CVE-2026-48128 Budibase is an open-source low-code platform. Prior to 3.39.0, the executeQuery automation step in Budibase accepts a queryId from automation step in… Mitigation only Fix from $1,6002026-05-27 HIGH 7.7 CVE-2026-48146 Budibase is an open-source low-code platform. Prior to 3.39.0, the OAuth2 token fetch function in packages/server/src/sdk/workspace/oauth2/utils.ts u… Mitigation only Fix from $1,9502026-05-27 HIGH 7.7 CVE-2026-45548 Budibase is an open-source low-code platform. Prior to 3.34.8, the processUrlFile function in packages/server/src/automations/steps/ai/extract.ts use… Mitigation only Fix from $1,9502026-05-27 HIGH 7.7 CVE-2026-45715 Budibase is an open-source low-code platform. Prior to 3.38.1, the REST datasource integration (packages/server/src/integrations/rest.ts) follows HTT… Mitigation only Fix from $1,9502026-05-27 HIGH 7.7 CVE-2026-45061 Budibase is an open-source low-code platform. Prior to 3.35.10, the Plugin URL upload endpoint (POST /api/plugin) validates the submitted URL with a … Mitigation only Fix from $1,9502026-05-27 MEDIUM 6.6 CVE-2026-48916 Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals. Ldap after 793.v754d6b_41b_ea_4 Fix from $1,6002026-05-27 MEDIUM 6.6 CVE-2026-48918 Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default. Active Directory after 2.41 Fix from $1,6002026-05-27 HIGH 8.2 CVE-2026-44971 GuardDog is a CLI tool to identify malicious PyPI packages. From 1.0.0 to 2.9.0, the programmatic remote project scanning path rewrites attacker-cont… Mitigation only Fix from $1,9502026-05-27 HIGH 8.8 CVE-2026-42184 Tauri is a framework for building binaries for all major desktop platforms. From 2.0 to 2.11.0, a flaw in Tauri's is_local_url() function causes it t… Tauri 2.10.3+ Fix from $1,9502026-05-27 HIGH 8.2 CVE-2026-9312EPSS 7% A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafte… Enterprise Server 3.16.19 / 3.17.16+ Fix from $1,9502026-05-27 MEDIUM 5.9 CVE-2026-8606 A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause the server to issue H… Enterprise Server 3.16.19 / 3.17.16+ Fix from $1,6002026-05-27 HIGH 8.6 CVE-2026-45298 Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (the documented quickstart, no DOZZLE_AUTH_PROVIDE… Dozzle 10.5.2+ Fix from $1,9502026-05-26 MEDIUM 6.3 CVE-2026-45412 MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, SSRF via work_flow_template Import. Authenticated users can supply arbitrary URL… Mitigation only Fix from $1,6002026-05-26 MEDIUM 6.3 CVE-2026-42335 MaxKB is an open-source AI assistant for enterprise. Prior to 2.8.1, MaxKB v2.8.0 and prior are vulnerable to a server-side request forgery (SSRF) by… Mitigation only Fix from $1,6002026-05-26 MEDIUM 5.1 CVE-2026-42336 MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a server-side request forgery (SSRF) bypass in the OSS f… Mitigation only Fix from $1,6002026-05-26 CRITICAL 9.2 CVE-2026-2264 A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and ex… Mitigation only Fix from $2,3002026-05-26 MEDIUM 5.4 CVE-2025-14290 IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM webMethods Integration is vu… Webmethods Integration Server Mitigation only Fix from $1,6002026-05-26