Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 6.5 CVE-2026-40346 NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.37, NocoBase's … Nocobase 2.0.37+ Fix from $1,6002026-04-18 HIGH 7.7 CVE-2026-40348 Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can trigger server… Movary 0.71.1+ Fix from $1,9502026-04-18 MEDIUM 6.3 CVE-2026-40516 OpenHarness before commit bd4df81 contains a server-side request forgery vulnerability in the web_fetch and web_search tools that allows attackers to… Openharness 2026-04-11+ Fix from $1,6002026-04-17 MEDIUM 6.3 CVE-2026-6497 A vulnerability was determined in prasathmani TinyFileManager up to 2.6. Affected by this vulnerability is an unknown functionality of the file /file… Mitigation only Fix from $1,6002026-04-17 HIGH 7.5 CVE-2026-31317 Craftql v1.3.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the vendor/markh… Mitigation only Fix from $1,9502026-04-17 MEDIUM 6.9 CVE-2026-5131 GREENmod uses named pipes for communication between plugins, the web portal, and the system service, but the access control lists for these pipes are… Mitigation only Fix from $1,6002026-04-17 HIGH 8.6 CVE-2026-5052 Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This may lead to these requests be… Vault 1.19.16 / 1.20.10+ Fix from $1,9502026-04-17 MEDIUM 5.0 CVE-2026-33440 Weblate is a web based localization tool. In versions prior to 5.17, the ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and … Weblate 5.17+ Fix from $1,6002026-04-15 MEDIUM 5.0 CVE-2026-34244 Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by the per-project "Administrat… Weblate 5.17+ Fix from $1,6002026-04-15 HIGH 8.1 CVE-2026-35032 Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the LiveTV M3U tuner endpoint (POST /… Jellyfin 10.11.7+ Fix from $1,9502026-04-14 HIGH 7.2 CVE-2026-33715 Chamilo LMS is an open-source learning management system. In version 2.0-RC.2, the file public/main/inc/ajax/install.ajax.php is accessible without a… Chamilo Lms Mitigation only Fix from $1,9502026-04-14 HIGH 8.6 CVE-2026-34160 Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the PENS (Package Exchange Notification Services) plugin e… Chamilo Lms after 1.11.38 Fix from $1,9502026-04-14 HIGH 8.5 CVE-2026-38527 A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resourc… Mitigation only Fix from $1,9502026-04-14 HIGH 7.4 CVE-2026-39418 MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, sandbox network protection can be bypassed by using socket.sendto()… Maxkb 2.8.0+ Fix from $1,9502026-04-14 MEDIUM 6.3 CVE-2026-6215 A weakness has been identified in DbGate up to 7.1.4. The impacted element is the function apiServerUrl1 of the file packages/rest/src/openApiDriver.… Mitigation only Fix from $1,6002026-04-13 HIGH 7.1 CVE-2026-34476 Server-Side Request Forgery via SW-URL Header vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are re… Skywalking Mcp 0.2.0+ Fix from $1,9502026-04-13 CRITICAL 9.8 CVE-2026-5936 An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. Thi… Pdf Services Api 2026-04-07+ Fix from $2,3002026-04-13 MEDIUM 6.3 CVE-2026-6119 A vulnerability was identified in AstrBotDevs AstrBot up to 4.22.1. The affected element is the function post_data.get of the component API Endpoint.… Mitigation only Fix from $1,6002026-04-12 MEDIUM 6.5 CVE-2026-6111 A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.1. This impacts the function decode_image of the file metagpt/utils/common.… Metagpt Patch available Fix from $1,6002026-04-12 MEDIUM 5.0 CVE-2026-4979 The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to blind Ser… Patch available Fix from $1,6002026-04-11 MEDIUM 6.5 CVE-2026-40242 Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.17.3, the /api/templates/fetch endpoint accepts a ca… Arcane 1.17.3+ Fix from $1,6002026-04-10 MEDIUM 6.3 CVE-2026-39921 GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery vulnerability that allows authenticated users with docum… Geonode 4.4.5 / 5.0.2+ Fix from $1,6002026-04-10 MEDIUM 6.3 CVE-2026-39922 GeoNode versions 4.4.5 and 5.0.2 (and prior within their respective releases) contain a server-side request forgery vulnerability in the service regi… Geonode 4.4.5 / 5.0.2+ Fix from $1,6002026-04-10 HIGH 8.2 CVE-2026-40168 Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endpoint is vulnerable to SSRF. Although the application valida… Postiz 2.21.5+ Fix from $1,9502026-04-10 CRITICAL 9.6 CVE-2026-30232 Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 4.8.5, Chartb… Chartbrew 4.8.5+ Fix from $2,3002026-04-10 MEDIUM 6.5 CVE-2026-31941 Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains a Server-Side Request Forgery (SSRF) vulnerability… Chamilo Lms 1.11.38+ Fix from $1,6002026-04-10 MEDIUM 6.5 CVE-2026-40160 PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, web_crawl's httpx fallback path passes user-supplied URLs directly to httpx.AsyncCli… Praisonaiagents 1.5.128+ Fix from $1,6002026-04-10 MEDIUM 5.3 CVE-2026-40100 FastGPT is an AI Agent building platform. Prior to 4.14.10.3, the /api/core/app/mcpTools/runTool endpoint accepts arbitrary URLs without authenticati… Fastgpt 4.14.10.3+ Fix from $1,6002026-04-10 HIGH 8.1 CVE-2026-6011 A weakness has been identified in OpenClaw up to 2026.1.26. Affected by this issue is some unknown functionality of the file src/agents/tools/web-fet… Openclaw 2026.1.29+ Fix from $1,9502026-04-10 CRITICAL 10.0 CVE-2026-40114 PraisonAI is a multi-agent teams system. Prior to 4.5.128, the /api/v1/runs endpoint accepts an arbitrary webhook_url in the request body with no URL… Praisonai 4.5.128+ Fix from $2,3002026-04-09