Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 7.1 CVE-2026-41272 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the core security wrappers (secureAxiosReque… Flowise 3.1.0+ Fix from $1,9502026-04-23 HIGH 8.5 CVE-2026-41461 SocialEngine versions 7.8.0 and prior contain a blind server-side request forgery vulnerability in the /core/link/preview endpoint where user-supplie… Socialengine after 7.8.0 Fix from $1,9502026-04-23 HIGH 8.5 CVE-2026-41455 WeKan before 8.35 contains a server-side request forgery vulnerability in webhook integration URL handling where the URL scheme field accepts any str… Patch available Fix from $1,9502026-04-22 HIGH 7.2 CVE-2026-41170 Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the `RestoreController.PostRestoreJ… Patch available Fix from $1,9502026-04-22 HIGH 7.3 CVE-2026-41171 Squidex is an open source headless content management system and content management hub. Versions prior to 7.23.0 have a Server-Side Request Forgery … Patch available Fix from $1,9502026-04-22 HIGH 7.3 CVE-2026-41172 Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, an SSRF vulnerability allows a user… Patch available Fix from $1,9502026-04-22 MEDIUM 5.5 CVE-2026-41177 Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the Squidex Restore API is vulnerab… Patch available Fix from $1,6002026-04-22 HIGH 8.5 CVE-2026-35548 An issue was discovered in guardsix (formerly Logpoint) ODBC Enrichment Plugins before 5.2.1 (5.2.1 is used in guardsix 7.9.0.0). A logic flaw allowe… Logpoint 5.2.1 / 7.9.0+ Fix from $1,9502026-04-22 MEDIUM 5.5 CVE-2026-41129 Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14 are vulnerable to Server-… Patch available Fix from $1,6002026-04-22 MEDIUM 5.5 CVE-2026-41130 Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14, the `resource-js` end… Patch available Fix from $1,6002026-04-22 HIGH 8.9 CVE-2026-5921 A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to extract sensitive environme… Enterprise Server 3.14.26 / 3.15.21+ Fix from $1,9502026-04-21 MEDIUM 6.5 CVE-2026-41060 WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isSSRFSafeURL()` function in `objects/functions.php` contains a same-d… Avideo after 29.0 Fix from $1,6002026-04-21 MEDIUM 5.3 CVE-2026-41055 WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete SSRF fix in AVideo's LiveLinks proxy adds `isSSRFSafeURL()` v… Avideo after 29.0 Fix from $1,6002026-04-21 MEDIUM 6.3 CVE-2026-6744 A vulnerability was found in Bagisto up to 2.3.15. Affected is the function copy of the component Downloadable Link Handler. The manipulation results… Mitigation only Fix from $1,6002026-04-21 MEDIUM 6.3 CVE-2026-41302 OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functionality that allows remote at… Openclaw 2026.3.31+ Fix from $1,6002026-04-21 HIGH 7.6 CVE-2026-41297 OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functionality that allows attackers… Openclaw 2026.3.31+ Fix from $1,9502026-04-21 HIGH 8.8 CVE-2026-35587 Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, a Server-Side Request Forgery (SSRF) vulnerability exists in… Glances 4.5.4+ Fix from $1,9502026-04-21 HIGH 7.5 CVE-2026-33626EPSS 45% LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions prior to 0.12.3 have a Server-Side Request Forgery (SSR… Lmdeploy 0.12.3+ Fix from $1,9502026-04-20 HIGH 7.7 CVE-2026-34428 Vvveb prior to 1.0.8.1 contains a server-side request forgery vulnerability in the oEmbedProxy action of the editor/editor module where the url param… Patch available Fix from $1,9502026-04-20 MEDIUM 5.8 CVE-2026-25883 Vexa is an open-source, self-hostable meeting bot API and meeting transcription API. Prior to 0.10.0-260419-1910, the Vexa webhook feature allows aut… Vexa after 0.10 Fix from $1,6002026-04-20 MEDIUM 6.3 CVE-2026-6649 A vulnerability was determined in Qibo CMS 1.0. Affected by this issue is some unknown functionality of the file /index/image/headers. Executing a ma… Mitigation only Fix from $1,6002026-04-20 HIGH 7.3 CVE-2026-6625 A security vulnerability has been detected in moxi624 Mogu Blog v2 up to 5.2. Affected by this vulnerability is the function LocalFileServiceImpl.upl… Mitigation only Fix from $1,9502026-04-20 MEDIUM 6.3 CVE-2026-6618 A flaw has been found in langgenius dify up to 1.13.3. This issue affects the function parse_openai_plugin_json_to_tool_bundle of the file api/core/t… Mitigation only Fix from $1,6002026-04-20 MEDIUM 6.3 CVE-2026-6616 A security vulnerability has been detected in TransformerOptimus SuperAGI up to 0.0.14. This affects the function extract_with_bs4/extract_with_3k/ex… Mitigation only Fix from $1,6002026-04-20 MEDIUM 6.3 CVE-2026-6617 A vulnerability was detected in langgenius dify up to 0.6.9. This vulnerability affects the function get_api_tool_provider_remote_schema of the file … Mitigation only Fix from $1,6002026-04-20 HIGH 7.3 CVE-2026-6604 A vulnerability was identified in modelscope agentscope up to 1.0.18. Affected by this issue is the function _parse_url/prepare_image/openai_audio_to… Mitigation only Fix from $1,9502026-04-20 HIGH 7.3 CVE-2026-6605 A security flaw has been discovered in modelscope agentscope up to 1.0.18. This affects the function _get_bytes_from_web_url of the file src/agentsco… Mitigation only Fix from $1,9502026-04-20 HIGH 7.3 CVE-2026-6606 A weakness has been identified in modelscope agentscope up to 1.0.18. This vulnerability affects the function _process_audio_block of the file src/ag… Mitigation only Fix from $1,9502026-04-20 MEDIUM 6.3 CVE-2026-6587 A security flaw has been discovered in vibrantlabsai RAGAS up to 0.4.3. The affected element is the function _try_process_local_file/_try_process_url… Mitigation only Fix from $1,6002026-04-20 MEDIUM 6.3 CVE-2026-6573 A vulnerability was detected in PHPEMS 11.0. This affects the function temppage of the file /app/exam/controller/exams.master.php of the component In… Mitigation only Fix from $1,6002026-04-19