Vulnerability index

Browse CVEs

2,810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 6.3 CVE-2026-54206 Tobit Laboratories AG TeamDavid's Webbox 's sending email, fax, SMS, etc. functionality accepts a @@INCLUDE command, which can be set to network loc… No fix yet Fix from $1,6002026-08-07 MEDIUM 6.3 CVE-2026-54207 Tobit Laboratories AG TeamDavid's Webbox 's move archive functionality (“!ArcEntryMove”) accepts an arbitrary path, which can be set to network loca… No fix yet Fix from $1,6002026-08-07 MEDIUM 5.4 CVE-2026-16027 Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Request Forgery. This issue affe… No fix yet Fix from $1,6002026-08-07 HIGH 8.8 CVE-2026-62857 Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the affected 1.9, 1.10, 2.0, 2.1… No fix yet Fix from $1,9502026-08-06 HIGH 8.6 CVE-2026-53983 Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital-source configuration path th… No fix yet Fix from $1,9502026-08-06 MEDIUM 6.4 CVE-2026-45573 Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, when VAPID delivery … No fix yet Fix from $1,6002026-08-06 CRITICAL 9.8 CVE-2026-15732 A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functionality allows authenticated att… No fix yet Fix from $2,3002026-08-06 HIGH 8.5 CVE-2026-18359 Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to ma… Escriptorium No fix yet Fix from $1,9502026-08-06 MEDIUM 6.3 CVE-2026-19040 A flaw has been found in MissionSquad mcp-api up to 1.11.9. The affected element is an unknown function of the file src/services/dcrClients.ts. Execu… No fix yet Fix from $1,6002026-08-06 CRITICAL 9.6 CVE-2026-12605 In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled … Glassfish 8.0.4+ Fix from $2,3002026-08-06 HIGH 8.5 CVE-2026-18597 The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is restricted, an attacker could t… No fix yet Fix from $1,9502026-08-06 HIGH 8.2 CVE-2026-16268 The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetching a user-supplied URL on the… No fix yet Fix from $1,9502026-08-06 HIGH 7.3 CVE-2026-19000 A vulnerability was identified in JeecgBoot up to 3.9.2. The affected element is an unknown function of the file /airag/chat/send of the component An… No fix yet Fix from $1,9502026-08-06 HIGH 7.3 CVE-2026-18973 A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitize_proxy_url of the file serve… No fix yet Fix from $1,9502026-08-06 HIGH 7.6 CVE-2026-34966 Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiti… No fix yet Fix from $1,9502026-08-05 HIGH 7.7 CVE-2026-55523 PraisonAI is a multi-agent teams system. In versions 1.5.128 through 1.6.57, the praisonaiagents.tools.web_crawl_tools.web_crawl() function is vulner… No fix yet Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-55524 PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the initially supplied URL, … No fix yet Fix from $1,9502026-08-05 HIGH 7.1 CVE-2026-9081 IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_pro… Langflow 1.11.0+ Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-7657 IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and ineffective SSRF protection enfor… Langflow 1.11.0+ Fix from $1,6002026-08-05 CRITICAL 9.8 CVE-2026-17617 IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specif… Application Gateway Operator after 26.6.0 Fix from $2,3002026-08-05 HIGH 8.5 CVE-2026-9203 A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged ro… No fix yet Fix from $1,9502026-08-05 MEDIUM 5.9 CVE-2026-70605 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-b… No fix yet Fix from $1,6002026-08-05 HIGH 8.5 CVE-2026-71280 go-shiori's DownloadBookmark (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Client with no custom DialContext … No fix yet Fix from $1,9502026-08-05 HIGH 8.6 CVE-2026-71270 Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated with the CustomHtmlSanitizer/SsrfProtectionService SS… No fix yet Fix from $1,9502026-08-05 HIGH 8.5 CVE-2026-71271 Memos' webhook URL validation, isReservedIP (internal/webhook/validate.go), checks a candidate IP against a reservedCIDRs list that omits 0.0.0.0/8 a… No fix yet Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-71244 Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, ac… No fix yet Fix from $1,6002026-08-05 HIGH 7.1 CVE-2026-71211 MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no … No fix yet Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-71208 KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cluster custom resource's conne… No fix yet Fix from $1,6002026-08-05 MEDIUM 6.8 CVE-2026-70620 Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attackers to direct the server to pr… No fix yet Fix from $1,6002026-08-04 HIGH 7.5 CVE-2026-66901 Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credenti… No fix yet Fix from $1,9502026-08-04