Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
CRITICAL 9.9 CVE-2026-42858 Open edX Platform enables the authoring and delivery of online learning at any scale. The sync_provider_data endpoint in SAMLProviderDataViewSet allo… Openedx 2026-04-24+ Fix from $2,3002026-05-11 HIGH 8.5 CVE-2026-42860 The Open edx Enterprise Service app provides enterprise features to the Open edX platform. From 7.0.2 to 7.0.4, the sync_provider_data endpoint in SA… Edx Enterprise 7.0.5+ Fix from $1,9502026-05-11 HIGH 8.3 CVE-2026-42313 pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SE… Pyload Ng 0.5.0b3.dev100+ Fix from $1,9502026-05-11 MEDIUM 5.1 CVE-2026-3048 An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be ab… Mitigation only Fix from $1,6002026-05-11 HIGH 7.1 CVE-2026-2393 A Server-Side Request Forgery (SSRF) vulnerability exists in MLflow versions prior to 3.9.0. The `_create_webhook()` function in `mlflow/server/handl… Mlflow 3.9.0+ Fix from $1,9502026-05-11 MEDIUM 6.3 CVE-2026-8193 A weakness has been identified in Akaunting 3.1.21. This issue affects some unknown processing of the file config/dompdf.php of the component Invoice… Mitigation only Fix from $1,6002026-05-09 CRITICAL 9.1 CVE-2026-44313 Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. Prior to version 2.13.0, a Server-… Mitigation only Fix from $2,3002026-05-09 MEDIUM 6.3 CVE-2026-44284 FastGPT is an AI Agent building platform. Prior to version 4.14.17, FastGPT had an inconsistent SSRF protection gap in MCP tool URL handling. The dir… Patch available Fix from $1,6002026-05-08 HIGH 8.6 CVE-2026-42352 pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23.3, OGC API process executio… Patch available Fix from $1,9502026-05-08 HIGH 7.7 CVE-2026-42345 FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packages/service/common/system/uti… Mitigation only Fix from $1,9502026-05-08 MEDIUM 6.5 CVE-2026-42346 Postiz is an AI social media scheduling tool. From version 2.16.6 to before version 2.21.7, all SSRF protections added in v2.21.4–v2.21.6 share a fun… Patch available Fix from $1,6002026-05-08 HIGH 7.1 CVE-2026-42339 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. In versions 0.11.9-alpha.1 and prior, the SS… New Api 0.11.9+ Fix from $1,9502026-05-08 MEDIUM 6.9 CVE-2026-41682 pupnp is an SDK for development of UPnP device and control point applications. Prior to version 1.18.5, pupnp is vulnerable to SRRF port confusion du… Patch available Fix from $1,6002026-05-08 MEDIUM 5.1 CVE-2026-42213 SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, th… Patch available Fix from $1,6002026-05-08 MEDIUM 6.3 CVE-2026-42180 Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy allows an authenticated low-privileged user to create a link … No fix yet Fix from $1,6002026-05-08 MEDIUM 6.5 CVE-2026-42181 Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy fetches metadata for user-supplied post URLs and, under the d… Mitigation only Fix from $1,6002026-05-08 CRITICAL 9.1 CVE-2026-44694 n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. From version 2.18.7 to before vers… N8n Mcp 2.50.2+ Fix from $2,3002026-05-08 HIGH 8.2 CVE-2026-42353 i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Prior to version 3.9.3, i18… Mitigation only Fix from $1,9502026-05-08 CRITICAL 9.8 CVE-2026-44335 PraisonAI is a multi-agent teams system. Prior to version 1.6.32, the URL checking logic in PraisonAI has a logical flaw that could be bypassed by at… Praisonaiagents 1.6.32+ Fix from $2,3002026-05-08 MEDIUM 5.3 CVE-2026-41423 Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions… Angular 19.2.21 / 20.3.19+ Fix from $1,6002026-05-08 HIGH 7.1 CVE-2026-42261 PromptHub is an all-in-one AI toolbox for prompt, skill, and agent management. From version 0.4.9 to before version 0.5.4, apps/web/src/routes/skills… Prompthub 0.5.4+ Fix from $1,9502026-05-08 CRITICAL 9.8 CVE-2026-8034 A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access … Enterprise Server 3.16.18 / 3.17.15+ Fix from $2,3002026-05-07 HIGH 8.1 CVE-2026-41105 Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network. Azure Monitor Action Group Notification System Mitigation only Fix from $1,9502026-05-07 HIGH 8.5 CVE-2026-42449 n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. In versions 2.47.4 through 2.47.13… N8n Mcp 2.47.14+ Fix from $1,9502026-05-07 HIGH 7.7 CVE-2026-41905 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, Helper::sanitizeRemoteUrl() in app/Misc/… Mitigation only Fix from $1,9502026-05-07 MEDIUM 6.3 CVE-2026-8081 A vulnerability has been found in router-for-me CLIProxyAPI 6.9.29. Affected by this issue is some unknown functionality of the file internal/api/han… Cliproxyapi Mitigation only Fix from $1,6002026-05-07 HIGH 7.7 CVE-2026-41688 Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the incomplete SSRF fix in Wallos validates webho… Patch available Fix from $1,9502026-05-07 MEDIUM 6.0 CVE-2026-41689 Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the webhook notification feature reuses an admini… Mitigation only Fix from $1,6002026-05-07 HIGH 8.1 CVE-2026-41654 Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS … Weblate 5.17.1+ Fix from $1,9502026-05-07 HIGH 7.1 CVE-2026-41644 monetr is a budgeting application for recurring expenses. Prior to version 1.12.5, a server-side request forgery (SSRF) vulnerability in monetr's Lun… Monetr 1.12.5+ Fix from $1,9502026-05-07