Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
CRITICAL 9.8 CVE-2026-2654 A weakness has been identified in huggingface smolagents 1.24.0. Impacted is the function requests.get/requests.post of the component LocalPythonExec… Smolagents after 1.24.0 Fix from $2,3002026-02-18 HIGH 7.1 CVE-2026-22048 StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and configured to use Microsoft Entr… Mitigation only Fix from $1,9502026-02-18 HIGH 7.3 CVE-2025-32355 Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is misconfigured in a way that a… Trufusion Enterprise 7.10.5.0+ Fix from $1,9502026-02-17 MEDIUM 6.3 CVE-2026-2558 A flaw has been found in GeekAI up to 4.2.4. The affected element is the function Download of the file api/handler/net_handler.go. This manipulation … Mitigation only Fix from $1,6002026-02-16 MEDIUM 6.3 CVE-2026-2556 A security vulnerability has been detected in cskefu up to 8.0.1. This issue affects some unknown processing of the file com/cskefu/cc/controller/res… Cskefu after 8.0.1 Fix from $1,6002026-02-16 CRITICAL 9.8 CVE-2026-2532 A vulnerability was detected in lintsinghua DeepAudit up to 3.0.3. This issue affects some unknown processing of the file backend/app/api/v1/endpoint… Deepaudit after 3.0.3 Fix from $2,3002026-02-16 HIGH 7.3 CVE-2026-2531 A security vulnerability has been detected in MindsDB up to 25.14.1. This vulnerability affects the function clear_filename of the file mindsdb/utili… Mindsdb after 25.14.1 Fix from $1,9502026-02-16 MEDIUM 5.0 CVE-2026-1249 The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Server-Side Request Forgery in versions 5… Mitigation only Fix from $1,6002026-02-14 MEDIUM 5.5 CVE-2026-0745 The User Language Switch plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.10 due to missin… Mitigation only Fix from $1,6002026-02-14 HIGH 7.7 CVE-2026-25991 Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, there is a Blind Server-Side Req… Recipes 2.5.1+ Fix from $1,9502026-02-13 MEDIUM 5.0 CVE-2026-26005 ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #45, in Clip Bucket V5, The Remote Play allows creating video entries that r… Clipbucket 5.5.3-45+ Fix from $1,6002026-02-12 MEDIUM 5.4 CVE-2025-12575 GitLab has remediated an issue in GitLab EE affecting all versions from 18.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under ce… GitLab 18.6.6 / 18.7.4+ Fix from $1,6002026-02-11 MEDIUM 5.8 CVE-2026-25870 DoraCMS version 3.1 and prior contains a server-side request forgery (SSRF) vulnerability in its UEditor remote image fetch functionality. The applic… No fix yet Fix from $1,6002026-02-10 MEDIUM 6.5 CVE-2026-21512 Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network. Azure Devops Server 2022.2.0+ Fix from $1,6002026-02-10 CRITICAL 9.8 CVE-2025-11242 Server-Side Request Forgery (SSRF) vulnerability in Teknolist Computer Systems Software Publishing Industry and Trade Inc. Okulistik allows Server Si… No fix yet Fix from $2,3002026-02-10 MEDIUM 5.8 CVE-2026-25765 Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Prior to 2.14.1, Faraday's build_exclusive_u… Faraday 1.10.5 / 2.14.1+ Fix from $1,6002026-02-09 MEDIUM 5.8 CVE-2026-25528 LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. The LangSmith SDK's distributed tracing feature is vulnerable to Ser… Mitigation only Fix from $1,6002026-02-09 MEDIUM 6.5 CVE-2026-25492 Craft CMS is a content management system. In Craft versions 3.5.0 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the save_images_Asset GraphQL mutatio… Craft Cms 4.16.18 / 5.8.22+ Fix from $1,6002026-02-09 MEDIUM 6.5 CVE-2026-25493 Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQL… Craft Cms 4.16.18 / 5.8.22+ Fix from $1,6002026-02-09 MEDIUM 6.5 CVE-2026-25494 Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQ… Craft Cms 4.16.18 / 5.8.22+ Fix from $1,6002026-02-09 MEDIUM 5.4 CVE-2026-0632 The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.12 via t… Mitigation only Fix from $1,6002026-02-09 MEDIUM 5.8 CVE-2026-25904 The Pydantic-AI MCP Run Python tool configures the Deno sandbox with an overly permissive configuration that allows the underlying Python code to acc… Mitigation only Fix from $1,6002026-02-09 MEDIUM 5.3 CVE-2026-25123 Homarr is an open-source dashboard. Prior to 1.52.0, a public (unauthenticated) tRPC endpoint widget.app.ping accepts an arbitrary url and performs a… Homarr 1.52.0+ Fix from $1,6002026-02-06 HIGH 8.6 CVE-2026-25580 Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.0.26 to before 1.56.0, aServer-Side Reques… Pydantic Ai 1.56.0+ Fix from $1,9502026-02-06 HIGH 7.2 CVE-2026-1294 The All In One Image Viewer Block plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.2 due t… Mitigation only Fix from $1,9502026-02-05 CRITICAL 9.8 CVE-2025-62615 AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prio… Autogpt Platform 0.6.34+ Fix from $2,3002026-02-04 CRITICAL 9.8 CVE-2025-62616 AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prio… Autogpt Platform 0.6.34+ Fix from $2,3002026-02-04 CRITICAL 9.1 CVE-2026-22247 GLPI is a free asset and IT management software package. From version 11.0.0 to before 11.0.5, a GLPI administrator can perform SSRF request through … Glpi 11.0.5+ Fix from $2,3002026-02-04 MEDIUM 5.4 CVE-2026-24961 Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods Grand Blog grandblog allows Server Side Request Forgery.This issue affects Grand Blog:… Mitigation only Fix from $1,6002026-02-03 HIGH 7.1 CVE-2025-13096 IBM Business Automation Workflow containers V25.0.0 through V25.0.0-IF007, V24.0.1 - V24.0.1-IF007, V24.0.0 - V24.0.0-IF007 and IBM Business Automati… Business Automation Workflow after 24.0.0 Fix from $1,9502026-02-02