Vulnerability index

Browse CVEs

2,810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 8.6 CVE-2026-14869 The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an… No fix yet Fix from $1,9502026-07-28 HIGH 7.7 CVE-2026-59931 PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through … No fix yet Fix from $1,9502026-07-28 HIGH 7.2 CVE-2026-54605 OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parse… No fix yet Fix from $1,9502026-07-28 HIGH 8.2 CVE-2026-43910 Appium Java Client is the Java language binding for writing Appium tests that conform to the W3C WebDriver protocol. From 8.2.1 until 10.1.1, when di… Java Client 10.1.1+ Fix from $1,9502026-07-28 MEDIUM 5.1 CVE-2026-67173 Pivotick did not validate the URL scheme of node imagePath values derived from graph data before assigning them to SVG image resources. An attacker a… No fix yet Fix from $1,6002026-07-28 HIGH 7.2 CVE-2026-65442 Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions. No fix yet Fix from $1,9502026-07-27 HIGH 7.2 CVE-2026-61953 Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions. No fix yet Fix from $1,9502026-07-27 MEDIUM 6.5 CVE-2026-65618 Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifacto… Artifactory 7.133.6+ Fix from $1,6002026-07-27 MEDIUM 6.8 CVE-2026-65923 A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause … Artifactory 7.111.18 / 7.117.25+ Fix from $1,6002026-07-27 MEDIUM 6.5 CVE-2026-65924 JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user … Artifactory 7.111.18 / 7.117.25+ Fix from $1,6002026-07-27 MEDIUM 6.5 CVE-2026-65925 A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response. Artifactory 7.111.18 / 7.117.25+ Fix from $1,6002026-07-27 MEDIUM 6.5 CVE-2026-64649 Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server A… Next.js 15.5.21 / 16.2.11+ Fix from $1,6002026-07-27 HIGH 8.4 CVE-2026-16481 A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch-page tool of googleapis/mcp-… No fix yet Fix from $1,9502026-07-27 MEDIUM 6.1 CVE-2026-64645 Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() o… Next.js 15.5.21 / 16.2.11+ Fix from $1,6002026-07-27 MEDIUM 6.9 CVE-2026-54272 ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF thr… No fix yet Fix from $1,6002026-07-27 CRITICAL 9.1 CVE-2026-17552 Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call. When the rewr… No fix yet Fix from $2,3002026-07-27 HIGH 8.5 CVE-2026-17192 A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to intern… No fix yet Fix from $1,9502026-07-27 MEDIUM 5.4 CVE-2026-65558 Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions. No fix yet Fix from $1,6002026-07-27 HIGH 7.2 CVE-2026-59552 Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer &amp; Embedder <= 1.4.2 versions. No fix yet Fix from $1,9502026-07-27 MEDIUM 5.5 CVE-2026-17534 Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal denylist in assertSafeFetchTa… No fix yet Fix from $1,6002026-07-27 HIGH 8.6 CVE-2025-15662 The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it se… No fix yet Fix from $1,9502026-07-27 MEDIUM 6.3 CVE-2026-17458 A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.t… No fix yet Fix from $1,6002026-07-26 CRITICAL 10.0 CVE-2026-57106 Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. Purview Data Governance No fix yet Fix from $2,3002026-07-24 MEDIUM 5.5 CVE-2026-16910 A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers accept user-supplied URLs withou… No fix yet Fix from $1,6002026-07-24 HIGH 8.8 CVE-2026-16870 Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltrati… No fix yet Fix from $1,9502026-07-24 HIGH 8.8 CVE-2026-56167 Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network. Azure Ai Search No fix yet Fix from $1,9502026-07-24 HIGH 7.7 CVE-2026-63313 9Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The endpoint accepts a user-controll… No fix yet Fix from $1,9502026-07-23 HIGH 7.2 CVE-2026-21653 Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery. This issue affects CCure … No fix yet Fix from $1,9502026-07-23 HIGH 7.2 CVE-2026-65516 Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions. No fix yet Fix from $1,9502026-07-23 CRITICAL 9.8 CVE-2026-64873 Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services. No fix yet Fix from $2,3002026-07-23