Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 5.4 CVE-2026-34590 Postiz is an AI social media scheduling tool. Prior to version 2.21.4, the POST /webhooks/ endpoint for creating webhooks uses WebhooksDto which vali… Postiz 2.21.4+ Fix from $1,6002026-04-02 MEDIUM 5.0 CVE-2026-34526 SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines,… Sillytavern 1.17.0+ Fix from $1,6002026-04-02 HIGH 7.3 CVE-2026-5346 A vulnerability was determined in huimeicloud hm_editor up to 2.2.3. Impacted is the function client.get of the file src/mcp-server.js of the compone… Mitigation only Fix from $1,9502026-04-02 CRITICAL 10.0 CVE-2026-32871 FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clien… Fastmcp 3.2.0+ Fix from $2,3002026-04-02 MEDIUM 6.4 CVE-2026-0688 The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.6.2 via the 'Tools::read' fu… Mitigation only Fix from $1,6002026-04-02 HIGH 7.2 CVE-2026-0686 The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.6.2 in the 'MF2::parse_autho… Mitigation only Fix from $1,9502026-04-02 MEDIUM 5.3 CVE-2026-5323 A vulnerability was found in priyankark a11y-mcp up to 1.0.5. This vulnerability affects the function A11yServer of the file src/index.js. The manipu… Patch available Fix from $1,6002026-04-02 HIGH 7.5 CVE-2026-34515 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the static resource handler may e… Aiohttp 3.13.4+ Fix from $1,9502026-04-01 HIGH 7.7 CVE-2026-34746 Payload is a free and open source headless content management system. Prior to version 3.79.1, an authenticated Server-Side Request Forgery (SSRF) vu… Payload 3.79.1+ Fix from $1,9502026-04-01 HIGH 7.4 CVE-2026-34076 Clerk JavaScript is the official JavaScript repository for Clerk authentication. In @clerk/hono from versions 0.1.0 to before 0.1.5, @clerk/express f… Mitigation only Fix from $1,9502026-04-01 CRITICAL 9.1 CVE-2026-33990 Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Prior to version 1.1.25, Docker Model Runner contains a… Model Runner 1.1.25+ Fix from $2,3002026-04-01 MEDIUM 6.1 CVE-2026-20041 A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights could allow an unauthenticated, remote attacker to conduct a server-side … No fix yet Fix from $1,6002026-04-01 HIGH 7.3 CVE-2026-0932 Blind server-side request forgery (SSRF) vulnerability in legacy connection methods of document co-authoring features in M-Files Server before 26.3 a… M Files Server 26.3.15818.5+ Fix from $1,9502026-04-01 MEDIUM 6.3 CVE-2026-5259 A vulnerability was determined in AutohomeCorp frostmourne up to 1.0. The affected element is an unknown function of the file frostmourne-monitor/src… Mitigation only Fix from $1,6002026-04-01 MEDIUM 5.3 CVE-2026-34443 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, checkIpByMask() in app/Misc/Helper.php c… Freescout 1.8.211+ Fix from $1,6002026-03-31 MEDIUM 6.5 CVE-2026-34740 WWBN AVideo is an open source video platform. In versions 26.0 and prior, the EPG (Electronic Program Guide) link feature in AVideo allows authentica… Avideo after 26.0 Fix from $1,6002026-03-31 HIGH 8.1 CVE-2026-34366 InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version … Invoiceshelf 2.2.0+ Fix from $1,9502026-03-31 HIGH 8.7 CVE-2026-34367 InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version … Invoiceshelf 2.2.0+ Fix from $1,9502026-03-31 HIGH 8.1 CVE-2026-34365 InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version … Invoiceshelf 2.2.0+ Fix from $1,9502026-03-31 MEDIUM 5.0 CVE-2026-33185 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l… Discourse 2026.1.3 / 2026.2.2+ Fix from $1,6002026-03-31 MEDIUM 6.3 CVE-2026-5205 A vulnerability was identified in chatwoot up to 4.11.2. Affected by this vulnerability is the function Webhooks::Trigger in the library lib/webhooks… Mitigation only Fix from $1,6002026-03-31 MEDIUM 5.8 CVE-2026-34360 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the /loadIG HTTP end… Hl7 Fhir Core 6.9.4+ Fix from $1,6002026-03-31 HIGH 8.3 CVE-2026-34504 OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows… Openclaw 2026.3.28+ Fix from $1,9502026-03-31 HIGH 7.7 CVE-2026-34163 FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, FastGPT's MCP (Model Context Protocol) tools endpoints (/api/core/app/mcpTools/g… Fastgpt 4.14.9.5+ Fix from $1,9502026-03-31 CRITICAL 10.0 CVE-2026-34162 FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exp… Fastgpt 4.14.9.5+ Fix from $2,3002026-03-31 MEDIUM 5.8 CVE-2026-3881 The Performance Monitor WordPress plugin through 1.0.6 does not validate a parameter before making a request to it, which could allow unauthenticated… Mitigation only Fix from $1,6002026-03-31 MEDIUM 5.0 CVE-2026-34881 OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authen… Glance 29.1.1 / 30.1.1+ Fix from $1,6002026-03-31 CRITICAL 9.8 CVE-2026-4789 Kyverno, versions 1.16.0 and later, are vulnerable to SSRF due to unrestricted CEL HTTP functions. Kyverno after 1.17.1 Fix from $2,3002026-03-30 HIGH 7.5 CVE-2026-27018 Gotenberg is an API for converting document formats. Prior to version 8.29.0, the fix introduced for CVE-2024-21527 can be bypassed using mixed-case … Gotenberg 8.29.0+ Fix from $1,9502026-03-30 MEDIUM 5.3 CVE-2026-31804 Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /pms_image_proxy endpoint accepts a user-… Tautulli 2.17.0+ Fix from $1,6002026-03-30