Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
CRITICAL 9.9 CVE-2026-26137 Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network. 365 Copilot Chat No fix yet Fix from $2,3002026-03-19 CRITICAL 10.0 CVE-2026-26138 Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. Purview Mitigation only Fix from $2,3002026-03-19 HIGH 8.6 CVE-2026-26139 Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. Purview No fix yet Fix from $1,9502026-03-19 HIGH 7.5 CVE-2026-26120 Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network. Bing No fix yet Fix from $1,9502026-03-19 HIGH 7.5 CVE-2026-30404 The backend database management connection test feature in wgcloud v3.6.3 has a server-side request forgery (SSRF) vulnerability. This issue can be e… Wgcloud after 3.6.3 Fix from $1,9502026-03-19 HIGH 7.1 CVE-2025-71258EPSS 17% BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component t… Footprints after 20.24.01.001 Fix from $1,9502026-03-19 HIGH 7.1 CVE-2025-71259EPSS 13% BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the externalfeed/RSS API comp… Footprints after 20.24.01.001 Fix from $1,9502026-03-19 MEDIUM 6.3 CVE-2026-31989 OpenClaw versions prior to 2026.3.1 contain a server-side request forgery vulnerability in web_search citation redirect resolution that uses a privat… Openclaw 2026.3.1+ Fix from $1,6002026-03-19 HIGH 8.6 CVE-2026-32255EPSS 9% Kan is an open-source project management tool. In versions 0.5.4 and below, the /api/download/attatchment endpoint has no authentication and no URL v… Kan 0.5.5+ Fix from $1,9502026-03-19 MEDIUM 5.8 CVE-2026-4366 A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirects when processing certain cli… Build Of Keycloak Mitigation only Fix from $1,6002026-03-18 HIGH 7.6 CVE-2026-22181 OpenClaw versions prior to 2026.3.2 contain a DNS pinning bypass vulnerability in strict URL fetch paths that allows attackers to circumvent SSRF gua… Openclaw 2026.3.2+ Fix from $1,9502026-03-18 CRITICAL 9.1 CVE-2026-25534 ### Impact Spinnaker updated URL Validation logic on user input to provide sanitation on user inputted URLs for clouddriver. However, they missed th… Patch available Fix from $2,3002026-03-17 MEDIUM 6.3 CVE-2026-4308 A weakness has been identified in frdel/agent0ai agent-zero 0.9.7. This affects the function handle_pdf_document of the file python/helpers/document_… Mitigation only Fix from $1,6002026-03-17 HIGH 7.3 CVE-2026-4231 A vulnerability was found in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is the function update_sql/run_sql of the file src/vanna/lega… Mitigation only Fix from $1,9502026-03-16 MEDIUM 6.3 CVE-2026-4215 A security flaw has been discovered in FlowCI flow-core-x up to 1.23.01. The impacted element is the function Save of the file core/src/main/java/com… Mitigation only Fix from $1,6002026-03-16 HIGH 7.3 CVE-2026-4200 A security flaw has been discovered in glowxq glowxq-oj up to 6f7c723090472057252040fd2bbbdaa1b5ed2393. This affects the function uploadTestcaseZipUr… Mitigation only Fix from $1,9502026-03-16 MEDIUM 5.4 CVE-2026-32412 Server-Side Request Forgery (SSRF) vulnerability in Gift Up! Gift Up Gift Cards for WordPress and WooCommerce gift-up allows Server Side Request Forg… No fix yet Fix from $1,6002026-03-13 MEDIUM 6.4 CVE-2026-32357 Server-Side Request Forgery (SSRF) vulnerability in Katsushi Kawamori Simple Blog Card simple-blog-card allows Server Side Request Forgery.This issue… Mitigation only Fix from $1,6002026-03-13 MEDIUM 6.4 CVE-2026-32353 Server-Side Request Forgery (SSRF) vulnerability in MailerPress Team MailerPress mailerpress allows Server Side Request Forgery.This issue affects Ma… Mitigation only Fix from $1,6002026-03-13 CRITICAL 9.3 CVE-2026-32301 Centrifugo is an open-source scalable real-time messaging server. Prior to 6.7.0, Centrifugo is vulnerable to Server-Side Request Forgery (SSRF) when… Centrifugo 6.7.0+ Fix from $2,3002026-03-13 HIGH 7.5 CVE-2026-32236 Backstage is an open framework for building developer portals. Prior to 0.27.1, a Server-Side Request Forgery (SSRF) vulnerability exists in @backsta… Backstage after 0.27.0 Fix from $1,9502026-03-12 HIGH 7.7 CVE-2026-21887 OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.8.16, the OpenCTI platform’s data ing… Opencti 6.8.16+ Fix from $1,9502026-03-12 MEDIUM 6.3 CVE-2026-3966 A vulnerability was detected in 648540858 wvp-GB28181-pro up to 2.7.4-20260107. Affected by this vulnerability is the function getDownloadFilePath of… Mitigation only Fix from $1,6002026-03-12 MEDIUM 6.3 CVE-2026-3961 A vulnerability was determined in zyddnys manga-image-translator up to beta-0.3. The affected element is the function to_pil_image of the file manga-… Mitigation only Fix from $1,6002026-03-11 MEDIUM 6.3 CVE-2026-3958 A vulnerability has been found in Woahai321 ListSync up to 0.6.6. This issue affects the function requests.post of the file list-sync-main/api_server… Mitigation only Fix from $1,6002026-03-11 CRITICAL 9.1 CVE-2026-32133 2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Prior to 6.1.0, a blind SSRF vulnerability … 2fauth 6.1.0+ Fix from $2,3002026-03-11 HIGH 8.3 CVE-2026-32110 SiYuan is a personal knowledge management system. Prior to 3.6.0, the /api/network/forwardProxy endpoint allows authenticated users to make arbitrary… Siyuan 3.6.0+ Fix from $1,9502026-03-11 MEDIUM 5.3 CVE-2026-32111 ha-mcp is a Home Assistant MCP Server. Prior to 7.0.0, the ha-mcp OAuth consent form (beta feature) accepts a user-supplied ha_url and makes a server… Home Assistant Mcp Server 7.0.0+ Fix from $1,6002026-03-11 HIGH 8.6 CVE-2026-32096 Plunk is an open-source email platform built on top of AWS SES. Prior to 0.7.0, a Server-Side Request Forgery (SSRF) vulnerability existed in the SNS… Plunk 0.7.0+ Fix from $1,9502026-03-11 MEDIUM 5.3 CVE-2026-31959 Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 contains a Server-Side Request Forgery (SSRF… Quill after 0.7.1 Fix from $1,6002026-03-11