Vulnerability index

Browse CVEs

2,810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 7.5 CVE-2026-64799 Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image UR… No fix yet Fix from $1,9502026-07-23 MEDIUM 6.5 CVE-2026-13192 In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature may allow an… Telerik Ui For Asp.net Ajax 2026.2.708+ Fix from $1,6002026-07-22 MEDIUM 5.4 CVE-2026-65593 n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that la… N8n 1.123.64 / 2.29.8+ Fix from $1,6002026-07-22 HIGH 8.6 CVE-2026-65317 Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows un… No fix yet Fix from $1,9502026-07-21 HIGH 8.6 CVE-2026-65318 Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to ca… Mitigation only Fix from $1,9502026-07-21 HIGH 8.2 CVE-2026-65056 mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loo… No fix yet Fix from $1,9502026-07-21 CRITICAL 9.3 CVE-2026-65057 Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary … Mitigation only Fix from $2,3002026-07-21 HIGH 8.6 CVE-2026-63764 LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within t… Lmdeploy after 0.14.0 Fix from $1,9502026-07-21 HIGH 7.1 CVE-2026-47695 CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to version 1.119.0, CC-Tweaked's HTTP API … No fix yet Fix from $1,9502026-07-21 MEDIUM 6.5 CVE-2026-46556 FlaskBB is a Forum Software written in Python using the micro framework Flask. Prior to version 2.2.1, a Server-Side Request Forgery (SSRF) vulnerabi… No fix yet Fix from $1,6002026-07-21 MEDIUM 5.5 CVE-2026-47390 PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `spider_tools` URL… No fix yet Fix from $1,6002026-07-21 MEDIUM 6.8 CVE-2026-15927 A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/mirror.py accept an exte… No fix yet Fix from $1,6002026-07-21 MEDIUM 6.4 CVE-2026-64626 AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the encoder download-by-URL flow du… No fix yet Fix from $1,6002026-07-20 HIGH 7.5 CVE-2026-51031 FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. This allows a remote attacker … No fix yet Fix from $1,9502026-07-20 MEDIUM 5.3 CVE-2026-44583 Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the PayPal webhook endpoint /ext… No fix yet Fix from $1,6002026-07-20 MEDIUM 5.0 CVE-2026-63730 HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to make reques… No fix yet Fix from $1,6002026-07-20 HIGH 7.7 CVE-2026-63731 HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to arbitrary i… No fix yet Fix from $1,9502026-07-20 HIGH 7.7 CVE-2026-63769 Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated us… No fix yet Fix from $1,9502026-07-20 HIGH 7.7 CVE-2026-63107 LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey template endpoint that allows authen… No fix yet Fix from $1,9502026-07-20 MEDIUM 5.1 CVE-2026-60033 Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to an SSRF vulne… No fix yet Fix from $1,6002026-07-20 MEDIUM 5.8 CVE-2026-45709 Mailpit is an email testing tool and API for developers. The fix for GHSA-6jxm-fv7w-rw5j (CVE-2026-23845, "Server-Side Request Forgery (SSRF) via HTM… Mailpit 1.30.0+ Fix from $1,6002026-07-20 HIGH 8.1 CVE-2026-62418 Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources check. This issue af… Syncope 4.0.7 / 4.1.2+ Fix from $1,9502026-07-20 MEDIUM 6.4 CVE-2026-63743 SurrealDB before 3.1.0 contains a capability bypass vulnerability in HTTP redirect handling that allows authenticated users to circumvent port-scoped… Surrealdb 3.1.0+ Fix from $1,6002026-07-20 MEDIUM 6.3 CVE-2026-16223 A vulnerability was determined in 1Panel-dev CordysCRM up to 1.4.1. Impacted is the function getSqlBotSrc of the file backend/crm/src/main/java/cn/co… No fix yet Fix from $1,6002026-07-19 MEDIUM 6.3 CVE-2026-16222 A vulnerability was found in 1Panel-dev CordysCRM up to 1.4.1. This issue affects some unknown processing of the file backend/crm/src/main/java/cn/co… No fix yet Fix from $1,6002026-07-19 MEDIUM 6.3 CVE-2026-16196 A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Impacted is the function isPrivateOrRestrictedIP of the file pkg/tools/integration/web… No fix yet Fix from $1,6002026-07-18 MEDIUM 6.3 CVE-2026-16194 A vulnerability was determined in zhayujie CowAgent up to 2.1.1. This affects the function WebFetch.execute of the file agent/tools/web_fetch/web_fet… No fix yet Fix from $1,6002026-07-18 HIGH 7.3 CVE-2026-16128 A security flaw has been discovered in zevorn rt-claw up to 0.2.0. This impacts the function receiver_thread of the file claw/services/swarm/swarm.c … No fix yet Fix from $1,9502026-07-18 HIGH 7.3 CVE-2026-16127 A vulnerability was identified in zevorn rt-claw up to 0.2.0. This affects the function claw_net_get/claw_net_post of the file claw/tools/tool_net.c … No fix yet Fix from $1,9502026-07-18 MEDIUM 6.3 CVE-2026-16124 A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.15.0-beta.32. This affects the function CheckSSRF/isPrivateIP of the fi… No fix yet Fix from $1,6002026-07-18