Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 7.7 CVE-2026-41413 Istio is an open platform to connect, manage, and secure microservices. Prior to versions 1.28.6 and 1.29.2, when a RequestAuthentication resource is… Istio 1.28.6 / 1.29.2+ Fix from $1,9502026-05-07 MEDIUM 6.8 CVE-2026-42194 Admidio is an open-source user management solution. Prior to version 5.0.9, the incomplete SSRF fix in Admidio's fetch_metadata.php validates the res… Mitigation only Fix from $1,6002026-05-07 HIGH 8.6 CVE-2026-44116 OpenClaw before 2026.4.22 contains a server-side request forgery vulnerability in the Zalo plugin's sendPhoto function that fails to validate outboun… Openclaw 2026.4.22+ Fix from $1,9502026-05-06 MEDIUM 5.8 CVE-2026-44117 OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in QQBot direct media upload that skips URL validation. Attackers can … Openclaw 2026.4.20+ Fix from $1,6002026-05-06 HIGH 7.7 CVE-2026-43576 OpenClaw before 2026.4.5 contains a server-side request forgery vulnerability in the CDP /json/version WebSocket endpoint that allows attackers to pi… Openclaw 2026.4.5+ Fix from $1,9502026-05-06 HIGH 7.2 CVE-2026-20035 A vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to conduct SSRF attacks through an … Unity Connection 14.0+ Fix from $1,9502026-05-06 MEDIUM 5.0 CVE-2026-35527 Incus is an open source container and virtual machine manager. In versions prior to 7.0.0, the image import flow issues an outbound HEAD request to a… Incus 7.0.0+ Fix from $1,6002026-05-05 HIGH 7.2 CVE-2026-39383 Gotenberg is an API-based document conversion tool. In version 8.29.1, an unauthenticated attacker with network access can force the server to make o… Gotenberg 8.31.0+ Fix from $1,9502026-05-05 HIGH 7.5 CVE-2026-40280 Gotenberg is an API-based document conversion tool. In versions 8.30.1 and earlier, the default private-IP deny-lists for the --webhook-deny-list and… Gotenberg 8.31.0+ Fix from $1,9502026-05-05 CRITICAL 9.8 CVE-2026-34084 PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3… Phpspreadsheet 1.30.3 / 2.1.15+ Fix from $2,3002026-05-05 HIGH 8.3 CVE-2026-33975 Twenty is an open source CRM built with NestJS (Node.js). In versions 1.18.0 and earlier, the SSRF protection in twenty-server's SecureHttpClientServ… Mitigation only Fix from $1,9502026-05-05 HIGH 8.6 CVE-2026-7412 In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, the Operation Delegation feature fails to validate the destination URI of dele… Mitigation only Fix from $1,9502026-05-05 HIGH 7.7 CVE-2026-43573 OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in existing-session browser interaction routes. Attacker… Openclaw 2026.4.10+ Fix from $1,9502026-05-05 HIGH 8.5 CVE-2026-42439 OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in the browser tabs action select and close routes. Atta… Openclaw 2026.4.10+ Fix from $1,9502026-05-05 CRITICAL 9.3 CVE-2026-43526 OpenClaw before 2026.4.12 contains a server-side request forgery vulnerability in QQBot reply media URL handling that allows attackers to fetch arbit… Openclaw 2026.4.12+ Fix from $2,3002026-05-05 HIGH 7.7 CVE-2026-43527 OpenClaw before 2026.4.14 contains a server-side request forgery vulnerability in browser SSRF policy that allows private-network navigation by defau… Openclaw 2026.4.14+ Fix from $1,9502026-05-05 MEDIUM 6.4 CVE-2026-2948 The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to… Mitigation only Fix from $1,6002026-05-05 MEDIUM 6.3 CVE-2026-7729 A security flaw has been discovered in pixelsock directus-mcp 1.0.0. This issue affects the function validateUrl of the file index.ts of the componen… Patch available Fix from $1,6002026-05-04 HIGH 7.2 CVE-2026-6229 The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1057. This is due … Mitigation only Fix from $1,9502026-05-02 MEDIUM 6.3 CVE-2026-7605 A security flaw has been discovered in JeecgBoot up to 3.9.1. This vulnerability affects the function CommonController.uploadImgByHttp/HttpFileToMult… Mitigation only Fix from $1,6002026-05-02 HIGH 7.2 CVE-2026-7049 The PixelYourSite Pro – Your smart PIXEL (TAG) Manager plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and i… Mitigation only Fix from $1,9502026-05-02 MEDIUM 6.3 CVE-2026-7603 A vulnerability was determined in JeecgBoot up to 3.9.1. Affected by this issue is the function checkPathTraversalBatch of the file FileDownloadUtils… Mitigation only Fix from $1,6002026-05-02 MEDIUM 6.3 CVE-2026-7604 A vulnerability was identified in JeecgBoot up to 3.9.1. This affects the function OpenApiController.add/OpenApiController.call of the file OpenApiCo… Mitigation only Fix from $1,6002026-05-02 HIGH 7.2 CVE-2026-42404 Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an appli… Neethi 3.2.2+ Fix from $1,9502026-05-01 MEDIUM 6.5 CVE-2026-3340 IBM Langflow Desktop 1.0.0 through 1.8.4 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker t… Langflow Desktop after 1.8.4 Fix from $1,6002026-04-30 MEDIUM 5.0 CVE-2026-36764 A Server-Side Request Forgery (SSRF) in the /ureport/datasource/testConnection endpoint of SpringBlade v4.8.0 allows authenticated attackers to scan … Mitigation only Fix from $1,6002026-04-30 MEDIUM 5.4 CVE-2026-36756 A Server-Side Request Forgery (SSRF) in the /plugins/-/install-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal res… Mitigation only Fix from $1,6002026-04-30 MEDIUM 6.5 CVE-2026-36759 A Server-Side Request Forgery (SSRF) in the /themes/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal… Mitigation only Fix from $1,6002026-04-30 HIGH 7.3 CVE-2026-7417 A vulnerability was found in Algovate xhs-mcp 0.8.11. This affects the function xhs_publish_content of the file src/server/mcp.server.ts of the compo… Mitigation only Fix from $1,9502026-04-29 MEDIUM 5.4 CVE-2026-42641 Server-Side Request Forgery (SSRF) vulnerability in ILLID Share This Image share-this-image allows Server Side Request Forgery.This issue affects Sha… Mitigation only Fix from $1,6002026-04-29