Vulnerability index

Browse CVEs

2,810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 6.3 CVE-2026-54020 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolved a hostname during URL vali… No fix yet Fix from $1,6002026-08-04 HIGH 7.1 CVE-2026-70485 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebUI checked whether a user-supp… No fix yet Fix from $1,9502026-08-04 HIGH 7.7 CVE-2026-70479 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, with WEB_LOADER_ENGINE=playwright, the… No fix yet Fix from $1,9502026-08-04 HIGH 7.5 CVE-2026-47616 NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery. A successfu… Dynamo after 1.1.0 Fix from $1,9502026-08-04 HIGH 7.5 CVE-2026-47617 NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery via DNS rebi… Dynamo after 1.1.0 Fix from $1,9502026-08-04 HIGH 7.5 CVE-2026-47618 NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause server-side request forgery. A su… Dynamo after 1.1.0 Fix from $1,9502026-08-04 HIGH 7.5 CVE-2026-47613 NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying… Dynamo after 1.1.0 Fix from $1,9502026-08-04 HIGH 7.5 CVE-2026-47614 NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful exploit of this vulnerability … Dynamo after 1.1.0 Fix from $1,9502026-08-04 HIGH 7.5 CVE-2026-47615 NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a crafted URL in a multimodal r… Dynamo after 1.1.0 Fix from $1,9502026-08-04 HIGH 7.6 CVE-2026-69257 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.… No fix yet Fix from $1,9502026-08-04 MEDIUM 6.3 CVE-2026-18774 A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file agent/image_gen_provider.py of … No fix yet Fix from $1,6002026-08-04 MEDIUM 6.3 CVE-2026-18775 A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browser_snapshot of the file tools/… No fix yet Fix from $1,6002026-08-04 HIGH 8.8 CVE-2026-15307 An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as… Django No fix yet Fix from $1,9502026-08-04 MEDIUM 5.4 CVE-2026-70367 A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS proxy mode. This flaw allows a … No fix yet Fix from $1,6002026-08-04 MEDIUM 5.3 CVE-2026-16536 The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL before performing a server-side … No fix yet Fix from $1,6002026-08-04 MEDIUM 6.8 CVE-2026-14939 The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetching it server-side, allowing u… No fix yet Fix from $1,6002026-08-04 MEDIUM 5.8 CVE-2026-10526 The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoin… No fix yet Fix from $1,6002026-08-04 MEDIUM 6.1 CVE-2026-66325 Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. Edge Chromium 151.0.4129.59+ Fix from $1,6002026-08-04 CRITICAL 10.0 CVE-2026-48331 Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitatio… Campaign after 7.4.2 Fix from $2,3002026-08-03 HIGH 7.2 CVE-2026-69246 Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header sep… No fix yet Fix from $1,9502026-08-03 MEDIUM 5.0 CVE-2026-18736 Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the server to issue arbitrary HTTP GET… No fix yet Fix from $1,6002026-08-03 HIGH 7.3 CVE-2026-18647 A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue affects the function isValidT… No fix yet Fix from $1,9502026-08-03 MEDIUM 6.9 CVE-2026-69198 ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classificatio… No fix yet Fix from $1,6002026-08-03 HIGH 7.7 CVE-2026-69192 ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a… No fix yet Fix from $1,9502026-08-03 HIGH 8.8 CVE-2026-69078 CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report PDF-generation functionality. User-controlled CTI … No fix yet Fix from $1,9502026-08-03 MEDIUM 6.8 CVE-2026-67311 Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fails to validate HTTP redirects … No fix yet Fix from $1,6002026-08-01 MEDIUM 5.3 CVE-2026-13604 The Pixelavo WordPress plugin before 1.5.4 registers an unauthenticated AJAX action, gated only by a nonce that it emits publicly on every front-end… No fix yet Fix from $1,6002026-08-01 MEDIUM 6.5 CVE-2026-52371 A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger component of xxl-job v3.4.0 allows authenticated attackers to scan resource… No fix yet Fix from $1,6002026-07-31 HIGH 8.2 CVE-2026-53500 Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() … No fix yet Fix from $1,9502026-07-31 CRITICAL 9.6 CVE-2026-54725 vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in … Mitigation only Fix from $2,3002026-07-31