Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 7.7 CVE-2026-33399 Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the SSRF fix applied in version 4.6.2 for CVE-2026-308… Wallos 4.7.0+ Fix from $1,9502026-03-24 MEDIUM 6.5 CVE-2026-33401 Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the patch introduced in commit e8a513591 (CVE-2026-308… Wallos 4.7.0+ Fix from $1,6002026-03-24 CRITICAL 9.1 CVE-2026-33407 Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, Wallos endpoints/logos/search.php accepts HTTP_PROXY a… Wallos 4.7.0+ Fix from $2,3002026-03-24 CRITICAL 9.1 CVE-2026-33340EPSS 22% LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side Request Forgery (SSRF) vulner… Lollms Web Ui No fix yet Fix from $2,3002026-03-24 HIGH 7.4 CVE-2026-33679 Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DownloadImage` function in `pkg/utils/avatar.go` uses a … Vikunja 2.2.1+ Fix from $1,9502026-03-24 MEDIUM 5.4 CVE-2026-33675 Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the migration helper functions `DownloadFile` and `DownloadFi… Vikunja 2.2.1+ Fix from $1,6002026-03-24 HIGH 7.3 CVE-2026-4623 A security vulnerability has been detected in DefaultFuction Jeson-Customer-Relationship-Management-System up to 1b4679c4d06b90d31dd521c2b000bfdec5a3… Patch available Fix from $1,9502026-03-24 MEDIUM 6.8 CVE-2026-32279 Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and includi… Connect Cms 1.41.1 / 2.41.1+ Fix from $1,6002026-03-23 HIGH 8.2 CVE-2026-33502 WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated server-side request forgery vulnerability in `… Avideo after 26.0 Fix from $1,9502026-03-23 HIGH 8.6 CVE-2026-33480 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `isSSRFSafeURL()` function in AVideo can be bypassed using IP… Avideo after 26.0 Fix from $1,9502026-03-23 MEDIUM 6.3 CVE-2026-4589 A vulnerability was identified in kalcaddle kodbox 1.64. The affected element is the function PathDriverUrl of the file /workspace/source-code/app/co… Mitigation only Fix from $1,6002026-03-23 CRITICAL 9.1 CVE-2026-33351 WWBN AVideo is an open source video platform. Prior to version 26.0, a Server-Side Request Forgery (SSRF) vulnerability exists in `plugin/Live/standA… Avideo 26.0+ Fix from $2,3002026-03-23 HIGH 7.3 CVE-2026-4528 A vulnerability was determined in trueleaf ApiFlow 0.9.7. The impacted element is the function validateUrlSecurity of the file packages/server/src/se… Mitigation only Fix from $1,9502026-03-21 HIGH 7.2 CVE-2026-3478 The Content Syndication Toolkit plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3 via the r… Mitigation only Fix from $1,9502026-03-21 HIGH 7.2 CVE-2026-1648 The Performance Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.6. This is due to… Mitigation only Fix from $1,9502026-03-21 HIGH 8.3 CVE-2026-1313 The MimeTypes Link Icons plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.2.20. This is due … Mitigation only Fix from $1,9502026-03-21 HIGH 7.2 CVE-2026-4302 The WowOptin: Next-Gen Popup Maker plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.29. Th… Mitigation only Fix from $1,9502026-03-21 MEDIUM 5.5 CVE-2026-33237 WWBN AVideo is an open source video platform. Prior to version 26.0, the Scheduler plugin's `run()` function in `plugin/Scheduler/Scheduler.php` call… Avideo 26.0+ Fix from $1,6002026-03-21 HIGH 8.7 CVE-2026-33226 Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions from 3.30.6 and prior, the REST datasource quer… Budibase after 3.30.6 Fix from $1,9502026-03-20 MEDIUM 5.7 CVE-2026-33060 CKAN MCP Server is a tool for querying CKAN open data portals. Versions prior to 0.4.85 provide tools including ckan_package_search and sparql_query … Ckan Mcp Server 0.4.85+ Fix from $1,6002026-03-20 HIGH 8.6 CVE-2026-33039 WWBN AVideo is an open source video platform. In versions 25.0 and below, the plugin/LiveLinks/proxy.php endpoint validates user-supplied URLs agains… Avideo 26.0+ Fix from $1,9502026-03-20 CRITICAL 9.1 CVE-2026-33024 AVideo is a video-sharing Platform. Versions prior to 8.0 contain a Server-Side Request Forgery vulnerability (CWE-918) in the public thumbnail endpo… Avideo Encoder 8.0+ Fix from $2,3002026-03-20 HIGH 7.5 CVE-2026-32949 SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a Server-Side Request Forgery (SS… Sqlbot 1.7.0+ Fix from $1,9502026-03-20 MEDIUM 6.8 CVE-2026-32812 Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, unrestricted URL fetch in the SSO Metadata API can result in SSR… Admidio 5.0.7+ Fix from $1,6002026-03-20 MEDIUM 5.3 CVE-2026-29107 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, it is p… Suitecrm 7.15.1 / 8.9.3+ Fix from $1,6002026-03-19 HIGH 7.5 CVE-2026-29097 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions prior to 7.15.1 and 8.9.3 contain … Suitecrm 7.15.1 / 8.9.3+ Fix from $1,9502026-03-19 MEDIUM 6.5 CVE-2026-32037 OpenClaw versions prior to 2026.2.22 fail to consistently validate redirect chains against configured mediaAllowHosts allowlists during MSTeams media… Openclaw 2026.2.22+ Fix from $1,6002026-03-19 MEDIUM 5.3 CVE-2026-32019 OpenClaw versions prior to 2026.2.22 contain incomplete IPv4 special-use range validation in the isPrivateIpv4() function, allowing requests to RFC-r… Openclaw 2026.2.22+ Fix from $1,6002026-03-19 HIGH 7.6 CVE-2026-33321 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, users with the `Notes - my… Openemr 8.0.0.2+ Fix from $1,9502026-03-19 CRITICAL 9.8 CVE-2026-32169 Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network. Azure Cloud Shell Mitigation only Fix from $2,3002026-03-19