Vulnerability index

Browse CVEs

2,810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 6.9 CVE-2026-73297 Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, _is_blocked_ip in ufo/utils/url_security… No fix yet Fix from $4,0002026-08-12 HIGH 8.8 CVE-2026-65941 In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitra… No fix yet Fix from $4,9002026-08-12 MEDIUM 5.1 CVE-2026-73432 Vulnerability-Lookup contains a server-side request forgery (SSRF) vulnerability in the remote-instance synchronization functionality. Remote instanc… No fix yet Fix from $4,0002026-08-12 HIGH 7.6 CVE-2026-73264 Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration access could supply an unvalidate… No fix yet Fix from $4,9002026-08-12 MEDIUM 6.4 CVE-2026-19050 The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the capability or nonce of the requ… No fix yet Fix from $4,0002026-08-12 HIGH 7.1 CVE-2026-16294 The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode URL settings before performi… No fix yet Fix from $4,9002026-08-12 HIGH 8.6 CVE-2026-73247 Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/functions/Ht… No fix yet Fix from $4,9002026-08-11 MEDIUM 5.4 CVE-2026-48762 TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI "Create Transcription" action handler fetches a user-supplied audio URL using … No fix yet Fix from $4,0002026-08-11 MEDIUM 5.8 CVE-2026-73243 kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated GET /addTask endpoint in kkFileView i… No fix yet Fix from $4,0002026-08-11 MEDIUM 5.8 CVE-2026-73212 Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.1, good_peer_addr() in src/server/ns_turn_server.c uses ioa_addr_i… No fix yet Fix from $4,0002026-08-11 MEDIUM 5.3 CVE-2026-73082 Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the POST /api/v1/projects/:projectId/mcp-server/validate-agent-mcp-t… No fix yet Fix from $4,0002026-08-11 HIGH 8.8 CVE-2026-70324 Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. Sharepoint Server 16.0.19725.20522+ Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-70326 Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. Sharepoint Server 16.0.19725.20522+ Fix from $4,9002026-08-11 CRITICAL 9.1 CVE-2026-69223 Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommend… Allura No fix yet Fix from $5,7502026-08-11 HIGH 8.8 CVE-2026-65813 Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. Exchange Server No fix yet Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-62902 Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network. Visual Studio 2022 8.0.30 / 9.0.19+ Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-58639 Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Sharepoint Server 16.0.19725.20522+ Fix from $4,0002026-08-11 HIGH 7.5 CVE-2026-58612 Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network. Powershell No fix yet Fix from $4,9002026-08-11 MEDIUM 5.4 CVE-2026-48483 TypeBot is a chatbot builder tool. Prior to version 3.17.0, Typebot's WhatsApp status forwarding feature stores a workspace-configured webhook forwar… No fix yet Fix from $4,0002026-08-11 CRITICAL 9.3 CVE-2026-73080 SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a caller-supp… No fix yet Fix from $5,7502026-08-11 MEDIUM 5.1 CVE-2026-73210 A Server-Side Request Forgery (SSRF) vulnerability existed in Lookyloo's PlaywrightCapture when the only_global_lookup option was enabled. Playwrigh… No fix yet Fix from $4,0002026-08-11 HIGH 8.5 CVE-2026-51583 An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF) via the Webhook validation … No fix yet Fix from $4,9002026-08-11 MEDIUM 5.4 CVE-2026-72784 Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulnerability in the GraphQL save<… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.4 CVE-2026-72768 n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node that allows authenticated use… No fix yet Fix from $4,0002026-08-11 HIGH 7.5 CVE-2026-72606 A server-side request forgery vulnerability in Pinry through 2.1.13 allows unauthenticated remote attackers to make the server issue HTTP requests to… No fix yet Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-72597 A server-side request forgery vulnerability in Friendica through the 2026.08-dev branch allows authenticated users with a free self-registered accoun… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-72598 A server-side request forgery vulnerability in Apioo Fusio 8.8.3 allows authenticated consumer-role users to make the server issue HTTP requests to i… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-72560 A server-side request forgery vulnerability in HumanSignal Label Studio through 1.24.0.dev0 exists because SSRF_PROTECTION_ENABLED is set to false by… No fix yet Fix from $4,0002026-08-11 HIGH 7.5 CVE-2026-72552 A server-side request forgery vulnerability in Dub as of 2026-07-10 allows unauthenticated remote attackers to make the server issue HTTP requests to… No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-13739 A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrar… No fix yet Fix from $4,9002026-08-11