Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 6.3 CVE-2026-7305 A weakness has been identified in Xuxueli xxl-job up to 3.3.2. The affected element is the function triggerJob of the file xxl-job-admin/src/main/jav… Patch available Fix from $1,6002026-04-28 MEDIUM 6.3 CVE-2026-7291 A weakness has been identified in o2oa up to 10.0. This affects the function FileAction of the file FileAction.java of the component URL Fetching. Ex… Mitigation only Fix from $1,6002026-04-28 MEDIUM 6.5 CVE-2026-42430 OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in Playwright redirect handling that allows attackers to bypass strict … Openclaw 2026.4.8+ Fix from $1,6002026-04-28 HIGH 8.5 CVE-2026-41914 OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in QQ Bot media download paths that bypass SSRF protection. Attackers c… Openclaw 2026.4.8+ Fix from $1,9502026-04-28 HIGH 7.6 CVE-2026-41912 OpenClaw before 2026.4.8 contains a server-side request forgery policy bypass vulnerability allowing attackers to trigger navigations bypassing norma… Openclaw 2026.4.8+ Fix from $1,9502026-04-28 MEDIUM 6.3 CVE-2026-24231 NVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could cause a server-side request … Nemoclaw 0.0.13+ Fix from $1,6002026-04-28 HIGH 7.3 CVE-2026-7223 A vulnerability was identified in BigSweetPotatoStudio HyperChat up to 2.0.0-alpha.63. Affected by this issue is the function fetch of the file packa… Mitigation only Fix from $1,9502026-04-28 HIGH 7.3 CVE-2026-7221 A vulnerability was found in TencentCloudBase CloudBase-MCP up to 2.17.0. Affected is the function openUrl of the file mcp/src/interactive-server.ts … Patch available Fix from $1,9502026-04-28 HIGH 7.3 CVE-2026-7178 A weakness has been identified in ChatGPTNextWeb NextChat up to 2.16.1. This affects the function storeUrl of the file app/api/artifacts/route.ts of … Nextchat No fix yet Fix from $1,9502026-04-27 HIGH 7.3 CVE-2026-7177 A security flaw has been discovered in ChatGPTNextWeb NextChat up to 2.16.1. Affected by this issue is the function proxyHandler of the file app/api/… Nextchat No fix yet Fix from $1,9502026-04-27 HIGH 7.3 CVE-2026-7158 A vulnerability has been found in dmitryglhf mcp-url-downloader up to 4b8cf2de55f6e8864a77d108e8a94a5b8e4394c6. Affected by this issue is the functio… Mitigation only Fix from $1,9502026-04-27 MEDIUM 6.3 CVE-2026-7150 A vulnerability was found in dh1011 auto-favicon up to f189116a9259950c2393f114dbcb94dde0ad864b. This issue affects the function generate_favicon_fro… Mitigation only Fix from $1,6002026-04-27 HIGH 7.3 CVE-2026-7147 A vulnerability was detected in JoeCastrom mcp-chat-studio up to 1.5.0. Affected by this issue is some unknown functionality of the file server/route… Mitigation only Fix from $1,9502026-04-27 HIGH 7.3 CVE-2026-7146 A security vulnerability has been detected in AlejandroArciniegas mcp-data-vis up to de5a51525a69822290eaee569a1ab447b490746d. Affected by this vulne… Mitigation only Fix from $1,9502026-04-27 HIGH 7.3 CVE-2026-7094 A vulnerability was determined in ShadowCloneLabs GlutamateMCPServers up to e2de73280b01e5d943593dd1aa2c01c5b9112f78. Affected by this issue is some … Glutamate Mcp Servers after 2025-06-26 Fix from $1,9502026-04-27 MEDIUM 6.3 CVE-2026-7084 A vulnerability was found in HBAI-Ltd Toonflow-app up to 1.1.1. This affects the function fetch of the file src/routes/setting/vendorConfig/getCodeBy… Mitigation only Fix from $1,6002026-04-27 HIGH 7.3 CVE-2026-7065 A vulnerability has been found in BidingCC BuildingAI up to 26.0.1. Impacted is the function uploadRemoteFile of the file packages/core/src/modules/u… Mitigation only Fix from $1,9502026-04-27 HIGH 7.3 CVE-2026-7025 A vulnerability was found in Typecho up to 1.3.0. This vulnerability affects the function Service::sendPingHandle of the file var/Widget/Service.php … Mitigation only Fix from $1,9502026-04-26 MEDIUM 6.3 CVE-2026-6981 A vulnerability was found in IhateCreatingUserNames2 AiraHub2 up to 3e4b77fd7d48ed811ffe5b8d222068c17c76495e. Affected is the function connect_stream… Mitigation only Fix from $1,6002026-04-25 MEDIUM 6.3 CVE-2026-6979 A flaw has been found in devlikeapro WAHA up to 2026.3.4. This affects an unknown function of the file src/api/media.controller.ts of the component A… Mitigation only Fix from $1,6002026-04-25 MEDIUM 6.5 CVE-2026-41481 LangChain is a framework for building agents and LLM-powered applications. Prior to langchain-text-splitters 1.1.2, HTMLHeaderTextSplitter.split_tex… Langchain Text Splitters 1.1.2+ Fix from $1,6002026-04-24 CRITICAL 10.0 CVE-2026-42043 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axio… Axios 0.31.1 / 1.15.1+ Fix from $2,3002026-04-24 HIGH 7.5 CVE-2026-42038 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, he fix for no_proxy hostname normalization bypass is in… Axios 0.31.1 / 1.15.1+ Fix from $1,9502026-04-24 CRITICAL 9.1 CVE-2026-41323 Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.18.0-rc1, 1.17.2-rc1, and 1.16.4, Kyverno's apiC… Kyverno 1.16.4 / 1.17.2+ Fix from $2,3002026-04-24 HIGH 7.1 CVE-2026-41361 OpenClaw before 2026.3.28 contains an SSRF guard bypass vulnerability that fails to block four IPv6 special-use ranges. Attackers can exploit this by… Openclaw 2026.3.28+ Fix from $1,9502026-04-23 CRITICAL 10.0 CVE-2026-35431 Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network. Entra Id Mitigation only Fix from $2,3002026-04-23 HIGH 7.5 CVE-2026-32210 Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network. Dynamics 365 Mitigation only Fix from $1,9502026-04-23 CRITICAL 10.0 CVE-2026-26150 Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. Purview Ediscovery Mitigation only Fix from $2,3002026-04-23 HIGH 8.3 CVE-2026-41270 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) protect… Flowise 3.1.0+ Fix from $1,9502026-04-23 HIGH 8.3 CVE-2026-41271 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) vulnera… Flowise 3.1.0+ Fix from $1,9502026-04-23