Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 7.5 CVE-2025-50180 esm.sh is a no-build content delivery network (CDN) for web development. In version 136, esm.sh is vulnerable to a full-response SSRF, allowing an at… Esm.sh 137+ Fix from $1,9502026-02-25 MEDIUM 5.0 CVE-2026-2479 The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.1. This… Mitigation only Fix from $1,6002026-02-25 HIGH 7.5 CVE-2026-3163 A vulnerability has been found in SourceCodester Website Link Extractor 1.0. This vulnerability affects the function file_get_contents of the compone… Website Link Extractor No fix yet Fix from $1,9502026-02-25 HIGH 8.6 CVE-2026-27696 changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, changedetection.io is vulnerable to Server-Side… Changedetection 0.54.1+ Fix from $1,9502026-02-25 MEDIUM 5.9 CVE-2026-27477 Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versio… Mastodon 4.4.14 / 4.5.7+ Fix from $1,6002026-02-24 CRITICAL 9.8 CVE-2026-26222 Altec DocLink (now maintained by Beyond Limits Inc.) version 4.0.336.0 exposes insecure .NET Remoting endpoints over TCP and HTTP/SOAP via Altec.RDCH… Altec Doclink Mitigation only Fix from $2,3002026-02-24 HIGH 8.1 CVE-2026-27732 WWBN AVideo is an open source video platform. Prior to version 22.0, the `aVideoEncoder.json.php` API endpoint accepts a `downloadURL` parameter and … Avideo 22.0+ Fix from $1,9502026-02-24 MEDIUM 6.5 CVE-2026-27129 Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s Gr… Craft Cms 4.16.19 / 5.8.23+ Fix from $1,6002026-02-24 HIGH 7.7 CVE-2026-3052 A vulnerability was found in DataLinkDC dinky up to 1.2.5. The impacted element is the function proxyUba of the file dinky-admin/src/main/java/org/di… Dinky after 1.2.5 Fix from $1,9502026-02-24 HIGH 8.6 CVE-2026-25545 Astro is a web framework. Prior to version 9.5.4, Server-Side Rendered pages that return an error with a prerendered custom error page (eg. `404.astr… \@astrojs\/node 9.5.4+ Fix from $1,9502026-02-24 HIGH 7.3 CVE-2026-3026 A vulnerability has been found in erzhongxmu JEEWMS 3.7. Affected by this issue is some unknown functionality of the file /plug-in/ueditor/jsp/getRem… Jeewms after 3.7 Fix from $1,9502026-02-23 MEDIUM 6.3 CVE-2026-2985 A security flaw has been discovered in Tiandy Video Surveillance System 视频监控平台 7.17.0. This impacts the function downloadImage of the file /com… Mitigation only Fix from $1,6002026-02-23 MEDIUM 6.5 CVE-2026-2945 A weakness has been identified in JeecgBoot 3.9.0. Affected by this vulnerability is an unknown functionality of the file /sys/common/uploadImgByHttp… Jeecg Boot No fix yet Fix from $1,6002026-02-22 HIGH 7.3 CVE-2026-27488 OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, Cron webhook delivery in src/gateway/server-cron.ts uses fetch() directly, so w… Openclaw after 2026.2.17 Fix from $1,9502026-02-21 HIGH 7.7 CVE-2026-27479 Wallos is an open-source, self-hostable personal subscription tracker. Versions 4.6.0 and below contain a Server-Side Request Forgery (SSRF) vulnerab… Wallos 4.6.1+ Fix from $1,9502026-02-21 HIGH 7.1 CVE-2026-27170 OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. In versions 1.1.2-alpha and below, URL ingest… Opensift 1.1.3+ Fix from $1,9502026-02-21 HIGH 8.8 CVE-2019-25451 phpMoAdmin 1.1.5 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized database operations by crafting ma… Phpmoadmin No fix yet Fix from $1,9502026-02-20 HIGH 7.2 CVE-2025-69299 Server-Side Request Forgery (SSRF) vulnerability in Laborator Oxygen oxygen allows Server Side Request Forgery.This issue affects Oxygen: from n/a th… No fix yet Fix from $1,9502026-02-20 HIGH 7.6 CVE-2026-26322 OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Gateway tool accepted a tool-supplied `gatewayUrl` without sufficient r… Openclaw 2026.2.14+ Fix from $1,9502026-02-19 HIGH 7.5 CVE-2026-26324 OpenClaw is a personal AI assistant. Prior to version 2026.2.14, OpenClaw's SSRF protection could be bypassed using full-form IPv4-mapped IPv6 litera… Openclaw 2026.2.14+ Fix from $1,9502026-02-19 MEDIUM 5.3 CVE-2025-8055 Server-Side Request Forgery (SSRF) vulnerability in OpenText™ XM Fax allows Server Side Request Forgery.  The vulnerability could allow an attacker … Xm Fax Mitigation only Fix from $1,6002026-02-19 HIGH 8.5 CVE-2026-26286 SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines,… Sillytavern 1.16.0+ Fix from $1,9502026-02-19 CRITICAL 9.8 CVE-2026-26339 Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the argument injection vulnerability… Alfresco Transform Service 4.2.3 / 5.2.4+ Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2026-26338 Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve server-side request forgery (SSRF) through the document processing… Alfresco Transform Service 4.3 / 5.3.0+ Fix from $2,3002026-02-19 HIGH 8.5 CVE-2026-2274 A SSRF and Arbitrary File Read vulnerability in AppSheet Core in Google AppSheet prior to 2025-11-23 allows an authenticated remote attacker to read … Mitigation only Fix from $1,9502026-02-19 CRITICAL 9.1 CVE-2025-55853 SoftVision webPDF before 10.0.2 is vulnerable to Server-Side Request Forgery (SSRF). The PDF converter function does not check if internal or externa… Webpdf 10.0.2+ Fix from $2,3002026-02-19 MEDIUM 5.5 CVE-2026-25385 Server-Side Request Forgery (SSRF) vulnerability in KaizenCoders URL Shortify url-shortify allows Server Side Request Forgery.This issue affects URL … Mitigation only Fix from $1,6002026-02-19 MEDIUM 6.4 CVE-2026-23803 Server-Side Request Forgery (SSRF) vulnerability in Burhan Nasir Smart Auto Upload Images smart-auto-upload-images allows Server Side Request Forgery… Mitigation only Fix from $1,6002026-02-19 MEDIUM 5.6 CVE-2026-2711 A vulnerability has been found in zhutoutoutousan worldquant-miner up to 1.0.9. The impacted element is an unknown function of the file worldquant-mi… Mitigation only Fix from $1,6002026-02-19 MEDIUM 6.4 CVE-2025-12375 The Printful Integration for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.2.… Mitigation only Fix from $1,6002026-02-19