Vulnerability index

Browse CVEs

2,810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 8.7 CVE-2026-54729 DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_url_safe can treat localhost … No fix yet Fix from $1,9502026-07-31 MEDIUM 5.3 CVE-2026-59231 Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to cause outbound HTTP GET requ… No fix yet Fix from $1,6002026-07-31 MEDIUM 6.1 CVE-2026-14540 A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through… Mcp Toolbox For Databases 1.5.0+ Fix from $1,6002026-07-31 MEDIUM 6.4 CVE-2026-67530 WACRM is a self-hostable CRM template for WhatsApp. In 0.7.0 and earlier, the automation send_webhook action in src/lib/automations/engine.ts and its… No fix yet Fix from $1,6002026-07-30 HIGH 8.5 CVE-2026-66415 Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal res… No fix yet Fix from $1,9502026-07-30 MEDIUM 5.3 CVE-2026-64870 MaxKB is an open-source AI assistant for enterprise. In versions 2.0.0 through 2.10.4-lts, UpdateStoreTool.update_tool passes caller-supplied downloa… No fix yet Fix from $1,6002026-07-30 MEDIUM 6.5 CVE-2026-15974 SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitized image_url, allowing access … Sglang after 0.5.15 Fix from $1,6002026-07-30 HIGH 8.5 CVE-2026-57862 Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass SSRF protections by supplyin… No fix yet Fix from $1,9502026-07-30 HIGH 8.6 CVE-2026-67346 Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery vulnerability in the _is_safe_url function that fails to valida… No fix yet Fix from $1,9502026-07-30 MEDIUM 6.9 CVE-2026-54885 Server-Side Request Forgery vulnerability in malach-it Boruta allows an unauthenticated remote attacker to cause the OAuth/OpenID authorization serve… No fix yet Fix from $1,6002026-07-30 MEDIUM 6.8 CVE-2026-18378 A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an a… Cost Management Metrics Operator No fix yet Fix from $1,6002026-07-30 HIGH 7.6 CVE-2026-18381 A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to… Cost Management Metrics Operator No fix yet Fix from $1,9502026-07-30 MEDIUM 6.8 CVE-2026-18382 A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an… Cost Management Metrics Operator No fix yet Fix from $1,6002026-07-30 MEDIUM 5.8 CVE-2026-18369 A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP… No fix yet Fix from $1,6002026-07-30 HIGH 8.8 CVE-2026-18353 PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and checks its **unverified** `iss` claim against an issuer allowlist using Python's `urlp… No fix yet Fix from $1,9502026-07-30 MEDIUM 5.9 CVE-2026-46678 Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.56.0 through 1.98.0, when an application opts a URL in… Pydantic Ai 1.99.0+ Fix from $1,6002026-07-29 MEDIUM 6.8 CVE-2026-54249 Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and 2.0.0b1 through 2.0.0b5, a c… Pydantic Ai 1.105.0+ Fix from $1,6002026-07-29 MEDIUM 6.0 CVE-2026-67435 linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to version 6.0.0, lib.url.fetch() … No fix yet Fix from $1,6002026-07-29 HIGH 8.3 CVE-2026-67436 Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In 6.0.0 and earlier, the redfi… No fix yet Fix from $1,9502026-07-29 HIGH 8.5 CVE-2026-67428 Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules including src/core/modules/third_par… No fix yet Fix from $1,9502026-07-29 HIGH 8.5 CVE-2026-67424 Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the HTTP modules http.get, http.request, and http.batch in… No fix yet Fix from $1,9502026-07-29 CRITICAL 9.3 CVE-2026-67426 Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/veri… No fix yet Fix from $2,3002026-07-29 HIGH 8.6 CVE-2026-16328 In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to overrid… No fix yet Fix from $1,9502026-07-29 CRITICAL 10.0 CVE-2026-54735 Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in … Prebid Server Mitigation only Fix from $2,3002026-07-29 HIGH 7.4 CVE-2026-54660 swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts getRemo… No fix yet Fix from $1,9502026-07-29 MEDIUM 6.1 CVE-2026-54663 swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts warmUpR… No fix yet Fix from $1,6002026-07-29 HIGH 7.5 CVE-2026-58189 Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects Apache Traf… Traffic Server 9.2.15 / 10.1.4+ Fix from $1,9502026-07-29 HIGH 7.5 CVE-2026-55391 datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf,… Datamodel Code Generator 0.63.0+ Fix from $1,9502026-07-28 HIGH 8.2 CVE-2026-54690 datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf,… Datamodel Code Generator 0.61.0+ Fix from $1,9502026-07-28 HIGH 8.2 CVE-2026-54691 datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61.0, src/datamodel_code_generator/http.py http.get… No fix yet Fix from $1,9502026-07-28