Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 5.4 CVE-2026-24548 Server-Side Request Forgery (SSRF) vulnerability in princeahmed Radio Player radio-player allows Server Side Request Forgery.This issue affects Radio… Mitigation only Fix from $1,6002026-01-23 HIGH 7.5 CVE-2026-24138 FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1754 and below contain an unauthenticated SSRF vu… Mitigation only Fix from $1,9502026-01-23 MEDIUM 5.3 CVE-2026-24117 Rekor is a software supply chain transparency log. In versions 1.4.3 and below, attackers can trigger SSRF to arbitrary internal services because /ap… Rekor 1.5.0+ Fix from $1,6002026-01-22 MEDIUM 5.4 CVE-2026-24381 Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods PhotoMe photome allows Server Side Request Forgery.This issue affects PhotoMe: from n/… Mitigation only Fix from $1,6002026-01-22 MEDIUM 5.4 CVE-2026-22358 Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Electrician - Electrical Service WordPress electrician allows Server Side Request F… Mitigation only Fix from $1,6002026-01-22 HIGH 7.2 CVE-2025-68030 Server-Side Request Forgery (SSRF) vulnerability in WP Messiah Frontis Blocks frontis-blocks allows Server Side Request Forgery.This issue affects Fr… Mitigation only Fix from $1,9502026-01-22 MEDIUM 6.4 CVE-2025-67961 Server-Side Request Forgery (SSRF) vulnerability in Marco van Wieren WPO365 wpo365-login allows Server Side Request Forgery.This issue affects WPO365… Mitigation only Fix from $1,6002026-01-22 MEDIUM 5.4 CVE-2025-62741 Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Pool Services pool-services allows Server Side Request Forgery.This issue affects P… Mitigation only Fix from $1,6002026-01-22 HIGH 7.5 CVE-2025-56589 A Local File Inclusion (LFI) and a Server-Side Request Forgery (SSRF) vulnerability was found in the InsertFromHtmlString() function of the Apryse HT… Html2pdf after 11.7.0 Fix from $1,9502026-01-22 MEDIUM 5.8 CVE-2026-1180 A flaw was identified in Keycloak’s OpenID Connect Dynamic Client Registration feature when clients authenticate using private_key_jwt. The issue all… No fix yet Fix from $1,6002026-01-20 HIGH 7.7 CVE-2026-22219 Chainlit versions prior to 2.9.4 contain a server-side request forgery (SSRF) vulnerability in the /project/element update flow when configured with … Chainlit 2.9.4+ Fix from $1,9502026-01-20 HIGH 7.5 CVE-2026-23845 Mailpit is an email testing tool and API for developers. Versions prior to 1.28.3 are vulnerable to Server-Side Request Forgery (SSRF) via HTML Check… Mailpit 1.28.3+ Fix from $1,9502026-01-19 HIGH 7.5 CVE-2025-68616 WeasyPrint helps web developers to create PDF documents. Prior to version 68.0, a server-side request forgery (SSRF) protection bypass exists in Weas… Weasyprint 68.0+ Fix from $1,9502026-01-19 CRITICAL 9.8 CVE-2026-1062 A flaw has been found in xiweicheng TMS up to 2.28.0. This affects the function Summary of the file src/main/java/com/lhjz/portal/util/HtmlUtil.java.… Teamwork Management System after 2.28.0 Fix from $2,3002026-01-17 HIGH 7.7 CVE-2026-23529 Kafka Connect BigQuery Connector is an implementation of a sink connector from Apache Kafka to Google BigQuery. Prior to 2.11.0, there is an arbitrar… Patch available Fix from $1,9502026-01-16 MEDIUM 5.3 CVE-2025-15104 Nu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arbitrary HTTP/HTTPS requests to… Validator 2026-01-11+ Fix from $1,6002026-01-16 HIGH 7.5 CVE-2026-0613 The Librarian contains an internal port scanning vulnerability, facilitated by the `web_fetch` tool, which can be used with SSRF-style behavior to pe… The Librarian Mitigation only Fix from $1,9502026-01-16 MEDIUM 5.0 CVE-2025-14793 The DK PDF – WordPress PDF Generator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.3.0 vi… Mitigation only Fix from $1,6002026-01-16 MEDIUM 6.1 CVE-2026-23768 lucy-xss-filter before commit 7c1de6d allows an attacker to induce server-side HEAD requests to arbitrary URLs when the ObjectSecurityListener or Emb… Lucy Xss Filter 2025-06-08+ Fix from $1,6002026-01-16 CRITICAL 9.1 CVE-2025-67647 SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.49.5, SvelteKit is vulnerable to a serve… Adapter Node 2.49.5 / 5.5.1+ Fix from $2,3002026-01-15 MEDIUM 5.3 CVE-2021-47776 Umbraco CMS v8.14.1 contains a server-side request forgery vulnerability that allows attackers to manipulate baseUrl parameters in multiple dashboard… Umbraco Cms No fix yet Fix from $1,6002026-01-15 MEDIUM 6.2 CVE-2026-0600 Server-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository 3 versions 3.0.0 and later allows authenticated administrators to confi… Mitigation only Fix from $1,6002026-01-14 HIGH 8.6 CVE-2026-0532 External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disc… Mitigation only Fix from $1,9502026-01-14 HIGH 7.2 CVE-2025-14613 The GetContentFromURL plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0. This is due to the… Mitigation only Fix from $1,9502026-01-14 MEDIUM 5.4 CVE-2026-20958 Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. Sharepoint Server 16.0.19127.20442+ Fix from $1,6002026-01-13 MEDIUM 6.5 CVE-2025-65784 Insecure permissions in Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows authenticated attackers with low-level privileges to access other … Hub No fix yet Fix from $1,6002026-01-13 HIGH 8.6 CVE-2026-22805 Metabase is an open-source data analytics platform. Prior to 55.13, 56.3, and 57.1, self-hosted Metabase instances that allow users to create subscri… Metabase 0.55.13 / 0.56.3+ Fix from $1,9502026-01-12 MEDIUM 5.3 CVE-2026-22772 Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.5, Fulcio's metaRegex() f… Fulcio 1.8.5+ Fix from $1,6002026-01-12 HIGH 7.5 CVE-2026-22245 Mastodon is a free, open-source social network server based on ActivityPub. By nature, Mastodon performs a lot of outbound requests to user-provided … Mastodon 4.2.29 / 4.3.17+ Fix from $1,9502026-01-08 MEDIUM 6.5 CVE-2026-21885 Miniflux 2 is an open source feed reader. Prior to version 2.2.16, Miniflux's media proxy endpoint (`GET /proxy/{encodedDigest}/{encodedURL}`) can be… Miniflux 2.2.16+ Fix from $1,6002026-01-08