Vulnerability index

Browse CVEs

2,810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 7.4 CVE-2026-50236 An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without … No fix yet Fix from $4,9002026-08-11 HIGH 7.4 CVE-2026-50237 A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelm… No fix yet Fix from $4,9002026-08-11 HIGH 8.7 CVE-2026-73160 Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_search_events endpoints. The URL validation rou… No fix yet Fix from $4,9002026-08-11 CRITICAL 9.1 CVE-2026-19516 A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the… No fix yet Fix from $5,7502026-08-11 MEDIUM 6.3 CVE-2026-72916 Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, PrivateAddressCheck.pri… No fix yet Fix from $4,0002026-08-10 MEDIUM 6.9 CVE-2026-72761 The webhook URL validator in `website/notifications/webhooks.py` uses `ip.is_global` to reject non-public addresses after DNS resolution. IPv6 transi… No fix yet Fix from $4,0002026-08-10 HIGH 7.7 CVE-2026-72591 A server-side request forgery (SSRF) vulnerability in gabehf/Koito through v0.3.2 allows an authenticated user to make the server perform HTTP reques… No fix yet Fix from $4,9002026-08-10 HIGH 8.6 CVE-2026-72581 A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to make the Xiaomi smart spe… No fix yet Fix from $4,9002026-08-10 HIGH 7.7 CVE-2026-72566 A server-side request forgery (SSRF) vulnerability in automatisch through commit 41f3c56 allows a low-privileged authenticated user with 'manage Flow… No fix yet Fix from $4,9002026-08-10 MEDIUM 5.0 CVE-2026-19075 All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=<post_id>` on any `aiovg_videos` post (`public/… No fix yet Fix from $4,0002026-08-10 MEDIUM 5.3 CVE-2026-14860 The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side request built from user-supplied input, allowing… No fix yet Fix from $4,0002026-08-10 MEDIUM 6.3 CVE-2026-19375 A vulnerability was detected in dmitriiweb article-scraper-mcp 1.0.0. This vulnerability affects the function fetch_article of the file news_scraper_… No fix yet Fix from $4,0002026-08-10 MEDIUM 5.3 CVE-2026-19373 A weakness has been identified in PhialsBasement KoboldCPP-MCP-Server 1.0.0. Affected by this issue is the function makeRequest of the file src/index… No fix yet Fix from $4,0002026-08-09 HIGH 7.3 CVE-2026-19374 A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of… No fix yet Fix from $4,9002026-08-09 MEDIUM 5.3 CVE-2026-19369 A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. This affects the function axios.get of the file src/index.ts of the component add_attac… No fix yet Fix from $4,0002026-08-09 MEDIUM 6.3 CVE-2026-19367 A vulnerability has been found in NocteDefensor LudusMCP 1.0.24. Affected by this vulnerability is an unknown functionality of the file src/tools/ran… No fix yet Fix from $4,0002026-08-09 MEDIUM 6.3 CVE-2026-19339 A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is the function ReadResourceReques… No fix yet Fix from $4,0002026-08-09 MEDIUM 6.3 CVE-2026-19340 A weakness has been identified in anubissbe ProjectHub-Mcp up to 5.0.0. This affects an unknown function of the file backend-fix/complete_backend.js … No fix yet Fix from $4,0002026-08-09 MEDIUM 5.3 CVE-2026-19337 A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/index.ts of the component rea… No fix yet Fix from $4,0002026-08-09 HIGH 7.7 CVE-2026-67620 Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_L… No fix yet Fix from $1,9502026-08-08 HIGH 8.7 CVE-2026-47662 Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling … No fix yet Fix from $1,9502026-08-07 HIGH 8.6 CVE-2026-47664 Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling … No fix yet Fix from $1,9502026-08-07 MEDIUM 6.3 CVE-2026-19246 A vulnerability has been found in HKUDS nanobot up to 0.2.1. This affects the function _download_image_data_url of the file nanobot/providers/image_g… No fix yet Fix from $1,6002026-08-07 HIGH 8.7 CVE-2026-47659 Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling … No fix yet Fix from $1,9502026-08-07 HIGH 8.7 CVE-2026-47660 Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling … No fix yet Fix from $1,9502026-08-07 MEDIUM 5.1 CVE-2026-17597 Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification feature. A user holding the ne… No fix yet Fix from $1,6002026-08-07 MEDIUM 6.5 CVE-2026-16637 OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers … No fix yet Fix from $1,6002026-08-07 HIGH 7.1 CVE-2026-15570 An improper restriction of URL schemes and destinations in the SmartCenter browserseturl command in the Telefunken TE24553B45V2DZ Smart TV running on… No fix yet Fix from $1,9502026-08-07 HIGH 7.7 CVE-2026-54204 Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot” parameter, which can be set to network locations using UNC… No fix yet Fix from $1,9502026-08-07 MEDIUM 6.3 CVE-2026-54205 Tobit Laboratories AG TeamDavid's Webbox 's link storing functionality (//ServerClient_celink.htm) accepts a “pathname” parameter, which can be set … No fix yet Fix from $1,6002026-08-07