Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 7.7 CVE-2026-29925 Invoice Ninja v5.12.46 and v5.12.48 is vulnerable to Server-Side Request Forgery (SSRF) in CheckDatabaseRequest.php. Invoice Ninja No fix yet Fix from $1,9502026-03-30 MEDIUM 6.3 CVE-2026-5126 A flaw has been found in SourceCodester RSS Feed Parser 1.0. Affected by this issue is the function file_get_contents. This manipulation causes serve… Mitigation only Fix from $1,6002026-03-30 HIGH 7.6 CVE-2026-29954 In KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF vulnerability when processing the chartURL field of ResourceC… Kubeplus No fix yet Fix from $1,9502026-03-30 CRITICAL 9.8 CVE-2026-2286 CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services, facilitated by the RAG… Crewai Mitigation only Fix from $2,3002026-03-30 HIGH 7.5 CVE-2026-0560 A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/export-content`… Lollms after 2.1.0 Fix from $1,9502026-03-29 HIGH 7.3 CVE-2026-5016 A vulnerability was identified in elecV2 elecV2P up to 3.8.3. This affects the function eAxios of the file /mock of the component URL Handler. Such m… Mitigation only Fix from $1,9502026-03-28 HIGH 7.2 CVE-2025-12886 The Oxygen Theme theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.8 via the laborator_calc_… Mitigation only Fix from $1,9502026-03-28 MEDIUM 6.5 CVE-2026-33992 pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, PyLoad's download engine accepts arbitrary URLs … Pyload Patch available Fix from $1,6002026-03-27 HIGH 8.5 CVE-2026-33953 LinkAce is a self-hosted archive to collect website links. Versions prior to 2.5.3 block direct requests to private IP literals, but still performs s… Linkace 2.5.3+ Fix from $1,9502026-03-27 HIGH 7.7 CVE-2026-31945 LibreChat is a ChatGPT clone with additional features. Versions 0.8.2-rc2 through 0.8.2 are vulnerable to a server-side request forgery (SSRF) attack… Librechat No fix yet Fix from $1,9502026-03-27 HIGH 8.5 CVE-2026-31943 LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.3, `isPrivateIP()` in `packages/api/src/auth/domain.ts` fails to detect I… Librechat 0.8.3+ Fix from $1,9502026-03-27 MEDIUM 6.5 CVE-2026-4964 A security vulnerability has been detected in letta-ai letta 0.16.4. This vulnerability affects the function _convert_message_create_to_message of th… Letta No fix yet Fix from $1,6002026-03-27 HIGH 7.3 CVE-2026-4953 A weakness has been identified in mingSoft MCMS up to 5.5.0. This issue affects the function catchImage of the file net/mingsoft/cms/action/BaseActio… Mitigation only Fix from $1,9502026-03-27 MEDIUM 6.5 CVE-2026-33766 WWBN AVideo is an open source video platform. In versions up to and including 26.0, `isSSRFSafeURL()` validates URLs against private/reserved IP rang… Avideo after 26.0 Fix from $1,6002026-03-27 MEDIUM 5.5 CVE-2026-33205 calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a Server-Side Request Fo… Calibre 9.6.0+ Fix from $1,6002026-03-27 HIGH 7.5 CVE-2026-30637 Server-Side Request Forgery (SSRF) vulnerability exists in the AnnounContent of the /admin/read.php in OTCMS V7.66 and before. The vulnerability allo… Otcms after 7.66 Fix from $1,9502026-03-27 HIGH 8.6 CVE-2026-22742 Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimoda… Spring Ai 1.0.5 / 1.1.4+ Fix from $1,9502026-03-27 MEDIUM 6.3 CVE-2026-4907 A vulnerability was identified in Page-Replica Page Replica up to e4a7f52e75093ee318b4d5a9a9db6751050d2ad0. The impacted element is the function site… Mitigation only Fix from $1,6002026-03-27 MEDIUM 6.5 CVE-2026-33693 Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.7.0-beta.9, the `v4_is_invalid()` function in `activitypub-federation-rust… Patch available Fix from $1,6002026-03-27 MEDIUM 5.5 CVE-2026-33619 PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab v0.8.3 contains a server-side request forger… Pinchtab 0.8.4+ Fix from $1,6002026-03-26 MEDIUM 5.0 CVE-2026-33537 Lychee is a free, open-source photo-management tool. The patch introduced for GHSA-cpgw-wgf3-xc6v (SSRF via `Photo::fromUrl`) contains an incomplete … Lychee 7.5.1+ Fix from $1,6002026-03-26 MEDIUM 6.5 CVE-2026-33486 Roadiz is a polymorphic content management system based on a node system that can handle many types of services. A vulnerability in roadiz/documents … Core Bundle Dev App 2.3.42 / 2.5.44+ Fix from $1,6002026-03-26 HIGH 8.6 CVE-2026-32857 Firecrawl version 2.8.0 and prior contain a server-side request forgery (SSRF) protection bypass vulnerability in the Playwright scraping service whe… Mitigation only Fix from $1,9502026-03-26 HIGH 7.5 CVE-2026-33182 Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, when building the request URL, Saloon comb… Saloon 4.0.0+ Fix from $1,9502026-03-26 MEDIUM 5.4 CVE-2026-1015 IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated atta… Infosphere Information Server after 11.7.1.6 Fix from $1,6002026-03-25 MEDIUM 5.4 CVE-2026-1561 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is vulnerable to server-side request fo… Websphere Application Server 26.0.0.4+ Fix from $1,6002026-03-25 MEDIUM 5.4 CVE-2025-14912 IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated atta… Infosphere Information Server after 11.7.1.6 Fix from $1,6002026-03-25 MEDIUM 6.4 CVE-2026-24964 Server-Side Request Forgery (SSRF) vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Server Side Re… Mitigation only Fix from $1,6002026-03-25 MEDIUM 5.0 CVE-2026-3216 Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal Canvas allows Server Side Request Forgery.This issue affects Drupal Canvas: from 0.… Drupal Canvas 1.1.1+ Fix from $1,6002026-03-25 MEDIUM 6.1 CVE-2026-33347 league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerab… Commonmark 2.8.2+ Fix from $1,6002026-03-24