Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 6.5 CVE-2026-40150 PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praisonaiagents/tools/web_crawl_tools.py accepts arbitra… Praisonaiagents 1.5.128+ Fix from $1,6002026-04-09 HIGH 7.4 CVE-2026-35629 OpenClaw before 2026.3.25 contains a server-side request forgery vulnerability in multiple channel extensions that fail to properly guard configured … Openclaw 2026.3.25+ Fix from $1,9502026-04-09 MEDIUM 6.5 CVE-2026-40107 SiYuan is a personal knowledge management system. Prior to 3.6.4, SiYuan configures Mermaid.js with securityLevel: "loose" and htmlLabels: true. In t… Siyuan 3.6.4+ Fix from $1,6002026-04-09 CRITICAL 9.9 CVE-2026-40089 Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audio Streaming Stack dashboard contains a Server-Sid… Radio Audio Streaming Stack 1.7.2+ Fix from $2,3002026-04-09 HIGH 7.2 CVE-2026-40072 web3.py allows you to interact with the Ethereum blockchain using Python. From 6.0.0b3 to before 7.15.0 and 8.0.0b2, web3.py implements CCIP Read / O… Web3.py 7.15.0+ Fix from $1,9502026-04-09 HIGH 8.5 CVE-2026-39974 n8n-MCP is a Model Context Protocol (MCP) server that provides AI assistants with comprehensive access to n8n node documentation, properties, and ope… N8n Mcp 2.47.4+ Fix from $1,9502026-04-09 HIGH 7.7 CVE-2026-39843 Plane is an an open-source project management tool. From 0.28.0 to before 1.3.0, the remediation of GHSA-jcc6-f9v6-f7jw is incomplete which could lea… Plane 1.3.0+ Fix from $1,9502026-04-09 CRITICAL 9.9 CVE-2025-62718 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization … Axios 0.31.0 / 1.15.0+ Fix from $2,3002026-04-09 CRITICAL 9.1 CVE-2025-50228 Jizhicms v2.5.4 is vulnerable to Server-Side Request Forgery (SSRF) in User Evaluation, Message, and Comment modules. Jizhicms Mitigation only Fix from $2,3002026-04-09 HIGH 7.3 CVE-2026-5832 A weakness has been identified in atototo api-lab-mcp up to 0.2.1. This affects the function analyze_api_spec/generate_test_scenarios/test_http_endpo… Mitigation only Fix from $1,9502026-04-09 MEDIUM 6.3 CVE-2026-5803 A security flaw has been discovered in bigsk1 openai-realtime-ui up to 188ccde27fdf3d8fab8da81f3893468f53b2797c. The affected element is an unknown f… Patch available Fix from $1,6002026-04-08 HIGH 7.5 CVE-2026-39885 FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 2.3.0, the mcp-from-openapi library uses @apidevtools/json-sc… \@frontmcp\/adapters 1.0.4 / 2.3.0+ Fix from $1,9502026-04-08 HIGH 7.1 CVE-2026-39362 InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, when INVENTREE_DOWNLOAD_FROM_URL is enabled (opt-in), authenticate… Inventree 1.2.7+ Fix from $1,9502026-04-08 MEDIUM 5.5 CVE-2026-32591 A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy ca… Mirror Registry For Red Hat Openshift Mitigation only Fix from $1,6002026-04-08 HIGH 7.7 CVE-2026-33458 Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and exe… Kibana 9.3.3+ Fix from $1,9502026-04-08 CRITICAL 9.1 CVE-2026-31017 A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where us… Erpnext Mitigation only Fix from $2,3002026-04-08 MEDIUM 6.5 CVE-2026-2377 A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products allows an authenticated user to … Mirror Registry For Red Hat Openshift Mitigation only Fix from $1,6002026-04-08 CRITICAL 9.1 CVE-2023-46945 QD 20230821 is vulnerable to Server-side request forgery (SSRF) via a crafted request Qd after 20230821 Fix from $2,3002026-04-08 MEDIUM 5.4 CVE-2026-39695 Server-Side Request Forgery (SSRF) vulnerability in podigee Podigee podigee allows Server Side Request Forgery.This issue affects Podigee: from n/a t… No fix yet Fix from $1,6002026-04-08 MEDIUM 6.0 CVE-2026-39670 Server-Side Request Forgery (SSRF) vulnerability in Brecht Visual Link Preview visual-link-preview allows Server Side Request Forgery.This issue affe… Mitigation only Fix from $1,6002026-04-08 MEDIUM 5.4 CVE-2026-39645 Server-Side Request Forgery (SSRF) vulnerability in Global Payments GlobalPayments WooCommerce global-payments-woocommerce allows Server Side Request… Mitigation only Fix from $1,6002026-04-08 MEDIUM 5.4 CVE-2026-39647 Server-Side Request Forgery (SSRF) vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar allows Se… Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2026-39630 Server-Side Request Forgery (SSRF) vulnerability in Getty Images Getty Images getty-images allows Server Side Request Forgery.This issue affects Gett… Mitigation only Fix from $1,6002026-04-08 MEDIUM 5.5 CVE-2026-39464 Server-Side Request Forgery (SSRF) vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd coming-soon allows S… Mitigation only Fix from $1,6002026-04-08 HIGH 7.2 CVE-2026-1343 IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces… Security Verify Access after 11.0.2.0 Fix from $1,9502026-04-08 HIGH 7.1 CVE-2026-39370 WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoder.json.php still allows attacker-controlled downloadURL… Avideo after 26.0 Fix from $1,9502026-04-07 MEDIUM 6.5 CVE-2026-39368 WWBN AVideo is an open source video platform. In versions 26.0 and prior, the Live restream log callback flow accepted an attacker-controlled restrea… Avideo after 26.0 Fix from $1,6002026-04-07 HIGH 7.7 CVE-2026-39361 OpenObserve is a cloud-native observability platform. In 0.70.3 and earlier, the validate_enrichment_url function in src/handler/http/request/enrichm… Openobserve after 0.70.3 Fix from $1,9502026-04-07 MEDIUM 6.0 CVE-2026-35572 ChurchCRM is an open-source church management system. Prior to 6.5.3, it is possible to trigger server-side HTTP/HTTPS requests to arbitrary hosts (S… Churchcrm 6.5.3+ Fix from $1,6002026-04-07 MEDIUM 5.0 CVE-2026-35516 LinkAce is a self-hosted archive to collect website links. Prior to 2.5.4, LinkRepository::update and CheckLinksCommand::checkLink do not check for p… Linkace 2.5.4+ Fix from $1,6002026-04-07