Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 7.1 CVE-2026-24902 TrustTunnel is an open-source VPN protocol with a server-side request forgery and and private network restriction bypass in versions prior to 0.9.114… Trusttunnel 0.9.114+ Fix from $1,9502026-01-29 MEDIUM 6.4 CVE-2026-24767 NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a blind Server-Side Request Forgery (SSRF) vulnerability exists … Nocodb 0.301.0+ Fix from $1,6002026-01-28 CRITICAL 9.9 CVE-2025-68662 Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, a hostname validation issue in Final… Discourse 3.5.4 / 2025.11.2+ Fix from $2,3002026-01-28 HIGH 7.2 CVE-2025-14610 The TableMaster for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3.6. This is … Mitigation only Fix from $1,9502026-01-28 HIGH 7.1 CVE-2026-24779 vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.14.1, a Server-Side Request Forgery (SSRF) vulnerability… Vllm 0.14.1+ Fix from $1,9502026-01-27 HIGH 8.8 CVE-2026-24736 Squidex is an open source headless content management system and content management hub. Versions of the application up to and including 7.21.0 allow… Squidex after 7.21.0 Fix from $1,9502026-01-27 MEDIUM 6.4 CVE-2026-0746 The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.3.2 via the 'get_audio' funct… Mitigation only Fix from $1,6002026-01-27 CRITICAL 9.9 CVE-2026-22039 Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have a critical authorization bo… Kyverno 1.15.3 / 1.16.3+ Fix from $2,3002026-01-27 HIGH 8.1 CVE-2026-24470 Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.24.0, when running Skipper as an Ingress controller, users wi… Skipper 0.24.0+ Fix from $1,9502026-01-26 MEDIUM 5.3 CVE-2025-9522 Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests to internal services, which ma… Omada Controller 6.0+ Fix from $1,6002026-01-26 HIGH 7.2 CVE-2026-0807 The Frontis Blocks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.1.6. This is due to insu… Mitigation only Fix from $1,9502026-01-24 MEDIUM 5.4 CVE-2026-24548 Server-Side Request Forgery (SSRF) vulnerability in princeahmed Radio Player radio-player allows Server Side Request Forgery.This issue affects Radio… Mitigation only Fix from $1,6002026-01-23 HIGH 7.5 CVE-2026-24138 FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1754 and below contain an unauthenticated SSRF vu… Mitigation only Fix from $1,9502026-01-23 MEDIUM 5.3 CVE-2026-24117 Rekor is a software supply chain transparency log. In versions 1.4.3 and below, attackers can trigger SSRF to arbitrary internal services because /ap… Rekor 1.5.0+ Fix from $1,6002026-01-22 MEDIUM 5.4 CVE-2026-24381 Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods PhotoMe photome allows Server Side Request Forgery.This issue affects PhotoMe: from n/… Mitigation only Fix from $1,6002026-01-22 MEDIUM 5.4 CVE-2026-22358 Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Electrician - Electrical Service WordPress electrician allows Server Side Request F… Mitigation only Fix from $1,6002026-01-22 HIGH 7.2 CVE-2025-68030 Server-Side Request Forgery (SSRF) vulnerability in WP Messiah Frontis Blocks frontis-blocks allows Server Side Request Forgery.This issue affects Fr… Mitigation only Fix from $1,9502026-01-22 MEDIUM 6.4 CVE-2025-67961 Server-Side Request Forgery (SSRF) vulnerability in Marco van Wieren WPO365 wpo365-login allows Server Side Request Forgery.This issue affects WPO365… Mitigation only Fix from $1,6002026-01-22 MEDIUM 5.4 CVE-2025-62741 Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Pool Services pool-services allows Server Side Request Forgery.This issue affects P… Mitigation only Fix from $1,6002026-01-22 HIGH 7.5 CVE-2025-56589 A Local File Inclusion (LFI) and a Server-Side Request Forgery (SSRF) vulnerability was found in the InsertFromHtmlString() function of the Apryse HT… Html2pdf after 11.7.0 Fix from $1,9502026-01-22 MEDIUM 5.8 CVE-2026-1180 A flaw was identified in Keycloak’s OpenID Connect Dynamic Client Registration feature when clients authenticate using private_key_jwt. The issue all… No fix yet Fix from $1,6002026-01-20 HIGH 7.7 CVE-2026-22219 Chainlit versions prior to 2.9.4 contain a server-side request forgery (SSRF) vulnerability in the /project/element update flow when configured with … Chainlit 2.9.4+ Fix from $1,9502026-01-20 HIGH 7.5 CVE-2026-23845 Mailpit is an email testing tool and API for developers. Versions prior to 1.28.3 are vulnerable to Server-Side Request Forgery (SSRF) via HTML Check… Mailpit 1.28.3+ Fix from $1,9502026-01-19 HIGH 7.5 CVE-2025-68616 WeasyPrint helps web developers to create PDF documents. Prior to version 68.0, a server-side request forgery (SSRF) protection bypass exists in Weas… Weasyprint 68.0+ Fix from $1,9502026-01-19 CRITICAL 9.8 CVE-2026-1062 A flaw has been found in xiweicheng TMS up to 2.28.0. This affects the function Summary of the file src/main/java/com/lhjz/portal/util/HtmlUtil.java.… Teamwork Management System after 2.28.0 Fix from $2,3002026-01-17 HIGH 7.7 CVE-2026-23529 Kafka Connect BigQuery Connector is an implementation of a sink connector from Apache Kafka to Google BigQuery. Prior to 2.11.0, there is an arbitrar… Patch available Fix from $1,9502026-01-16 MEDIUM 5.3 CVE-2025-15104 Nu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arbitrary HTTP/HTTPS requests to… Validator 2026-01-11+ Fix from $1,6002026-01-16 HIGH 7.5 CVE-2026-0613 The Librarian contains an internal port scanning vulnerability, facilitated by the `web_fetch` tool, which can be used with SSRF-style behavior to pe… The Librarian Mitigation only Fix from $1,9502026-01-16 MEDIUM 5.0 CVE-2025-14793 The DK PDF – WordPress PDF Generator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.3.0 vi… Mitigation only Fix from $1,6002026-01-16 MEDIUM 6.1 CVE-2026-23768 lucy-xss-filter before commit 7c1de6d allows an attacker to induce server-side HEAD requests to arbitrary URLs when the ObjectSecurityListener or Emb… Lucy Xss Filter 2025-06-08+ Fix from $1,6002026-01-16