Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 5.0 CVE-2026-31878 Frappe is a full-stack web application framework. Prior to 14.100.1, 15.100.0, and 16.6.0, a malicious user could send a crafted request to an endpoi… Frappe 14.100.1 / 15.100.0+ Fix from $1,6002026-03-11 HIGH 7.5 CVE-2025-70027 An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. This allows attackers to obtain se… Sunbirded Portal Mitigation only Fix from $1,9502026-03-11 MEDIUM 5.5 CVE-2026-21293 Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a Server-Side Request Forgery (… Commerce 1.3.3 / 2.4.4+ Fix from $1,6002026-03-11 MEDIUM 5.5 CVE-2026-21294 Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a Server-Side Request Forgery (… Commerce 1.3.3 / 2.4.4+ Fix from $1,6002026-03-11 HIGH 8.8 CVE-2026-31829 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.0.13, Flowise exposes an HTTP Node in AgentFlow a… Flowise 3.0.13+ Fix from $1,9502026-03-10 MEDIUM 6.5 CVE-2026-30953 LinkAce is a self-hosted archive to collect website links. When a user creates a link via POST /links, the server fetches HTML metadata from the prov… Linkace after 2.0.0 Fix from $1,6002026-03-10 HIGH 8.2 CVE-2026-27826EPSS 14% MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.17.0, an unauthenticated atta… Mcp Atlassian 0.17.0+ Fix from $1,9502026-03-10 HIGH 7.5 CVE-2026-26801 Server-Side Request Forgery (SSRF) vulnerability in pdfmake versions 0.3.0-beta.2 through 0.3.5 allows a remote attacker to obtain sensitive informat… Pdfmake after 0.3.5 Fix from $1,9502026-03-10 HIGH 8.8 CVE-2026-26118 Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network. Azure Mcp Server 2.0.0+ Fix from $1,9502026-03-10 HIGH 7.5 CVE-2026-26121 Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a network. Azure Iot Explorer 0.15.14+ Fix from $1,9502026-03-10 MEDIUM 6.4 CVE-2026-24316 SAP NetWeaver Application Server for ABAP provides an ABAP Report for testing purposes, which allows to send HTTP requests to arbitrary internal or e… Netweaver Application Server Abap Mitigation only Fix from $1,6002026-03-10 CRITICAL 9.0 CVE-2026-25737 Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.24.0 and earlier, an arbitrary file upload vulnerabili… Budibase after 3.24.0 Fix from $2,3002026-03-09 CRITICAL 9.8 CVE-2026-25960 vLLM is an inference and serving engine for large language models (LLMs). The SSRF protection fix for CVE-2026-24779 add in 0.15.1 can be bypassed in… Vllm 0.17.0+ Fix from $2,3002026-03-09 MEDIUM 5.5 CVE-2026-3588 A server-side request forgery (SSRF) vulnerability in IKEA Dirigera v2.866.4 allows an attacker to exfiltrate private keys by sending a crafted reque… Dirigera Firmware Mitigation only Fix from $1,6002026-03-09 CRITICAL 9.8 CVE-2025-70042 An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in oslabs-beta ThermaKube master. Thermakube Mitigation only Fix from $2,3002026-03-09 HIGH 8.8 CVE-2026-3788 A security vulnerability has been detected in Bytedesk up to 1.3.9. This impacts the function getModels of the file source-code/src/main/java/com/byt… Bytedesk 1.4.5.4+ Fix from $1,9502026-03-09 HIGH 8.8 CVE-2026-3789 A vulnerability was detected in Bytedesk up to 1.3.9. Affected is the function getModels of the file source-code/src/main/java/com/bytedesk/ai/spring… Bytedesk 1.4.5.4+ Fix from $1,9502026-03-09 HIGH 7.2 CVE-2026-3750 A security vulnerability has been detected in ContiNew Admin up to 4.2.0. This issue affects the function URI.create of the file continew-system/src/… Continew Admin after 4.1.0 Fix from $1,9502026-03-08 MEDIUM 6.3 CVE-2026-3733 A vulnerability was detected in xuxueli xxl-job up to 3.3.2. This impacts an unknown function of the file source-code/src/main/java/com/xxl/job/admin… Mitigation only Fix from $1,6002026-03-08 MEDIUM 6.3 CVE-2026-3683 A vulnerability was detected in bufanyun HotGo up to 2.0. This issue affects the function ImageTransferStorage of the file /server/internal/logic/com… Mitigation only Fix from $1,6002026-03-08 MEDIUM 6.3 CVE-2026-3681 A weakness has been identified in welovemedia FFmate up to 2.0.15. This affects the function fireWebhook of the file /internal/service/webhook/webhoo… Mitigation only Fix from $1,6002026-03-07 HIGH 7.5 CVE-2026-30858 WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.0, a DNS rebinding vulnerab… Weknora 0.3.0+ Fix from $1,9502026-03-07 HIGH 7.5 CVE-2026-30834 PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. Prior to version 0.7.7, a Server-Side Request Forgery… Pinchtab 0.7.7+ Fix from $1,9502026-03-07 CRITICAL 9.1 CVE-2026-30832 Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.4, an authenticated SSH user can force the s… Soft Serve 0.11.4+ Fix from $2,3002026-03-07 HIGH 8.8 CVE-2026-30840 Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, there is a server-side request forgery vulnerability i… Wallos 4.6.2+ Fix from $1,9502026-03-07 HIGH 7.5 CVE-2026-30828 Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, the url parameter can be used to retrieve local system… Wallos 4.6.2+ Fix from $1,9502026-03-07 MEDIUM 5.3 CVE-2026-27797 Homarr is an open-source dashboard. Prior to version 1.54.0, an unauthenticated Server-Side Request Forgery (SSRF) vulnerability allows a remote atta… Homarr 1.54.0+ Fix from $1,6002026-03-07 HIGH 7.5 CVE-2026-30247 WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, the application's "Impo… Weknora 0.2.12+ Fix from $1,9502026-03-07 HIGH 8.5 CVE-2026-30242 Plane is an an open-source project management tool. Prior to version 1.2.3, the webhook URL validation in plane/app/serializers/webhook.py only check… Plane 1.2.3+ Fix from $1,9502026-03-06 HIGH 8.1 CVE-2026-30844 Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 are vulnerable to Server-Side Request Forgery (SSRF) via attachment URL… Wekan Patch available Fix from $1,9502026-03-06