Vulnerability index

Browse CVEs

2,830 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Adapter Node CRITICAL 9.1
CVE-2025-67647

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.49.5, SvelteKit is vulnerable to a serve…

Fix: 2.49.5 / 5.5.1+
Fix from $2,300 2026-01-15
Umbraco Cms MEDIUM 5.3
CVE-2021-47776

Umbraco CMS v8.14.1 contains a server-side request forgery vulnerability that allows attackers to manipulate baseUrl parameters in multiple dashboard…

No fix yet
Fix from $1,600 2026-01-15
Unclassified MEDIUM 6.2
CVE-2026-0600

Server-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository 3 versions 3.0.0 and later allows authenticated administrators to confi…

Mitigation only
Fix from $1,600 2026-01-14
Unclassified HIGH 8.6
CVE-2026-0532

External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disc…

Mitigation only
Fix from $1,950 2026-01-14
Unclassified HIGH 7.2
CVE-2025-14613

The GetContentFromURL plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0. This is due to the…

Mitigation only
Fix from $1,950 2026-01-14
Sharepoint Server MEDIUM 5.4
CVE-2026-20958

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

Fix: 16.0.19127.20442+
Fix from $1,600 2026-01-13
Hub MEDIUM 6.5
CVE-2025-65784

Insecure permissions in Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows authenticated attackers with low-level privileges to access other …

No fix yet
Fix from $1,600 2026-01-13
Metabase HIGH 8.6
CVE-2026-22805

Metabase is an open-source data analytics platform. Prior to 55.13, 56.3, and 57.1, self-hosted Metabase instances that allow users to create subscri…

Fix: 0.55.13 / 0.56.3+
Fix from $1,950 2026-01-12
Fulcio MEDIUM 5.3
CVE-2026-22772

Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.5, Fulcio's metaRegex() f…

Fix: 1.8.5+
Fix from $1,600 2026-01-12
Mastodon HIGH 7.5
CVE-2026-22245

Mastodon is a free, open-source social network server based on ActivityPub. By nature, Mastodon performs a lot of outbound requests to user-provided …

Fix: 4.2.29 / 4.3.17+
Fix from $1,950 2026-01-08
Miniflux MEDIUM 6.5
CVE-2026-21885

Miniflux 2 is an open source feed reader. Prior to version 2.2.16, Miniflux's media proxy endpoint (`GET /proxy/{encodedDigest}/{encodedURL}`) can be…

Fix: 2.2.16+
Fix from $1,600 2026-01-08
Unclassified MEDIUM 6.4
CVE-2025-22726

Server-Side Request Forgery (SSRF) vulnerability in _nK nK Themes Helper nk-themes-helper allows Server Side Request Forgery.This issue affects nK Th…

Mitigation only
Fix from $1,600 2026-01-08
Mailpit MEDIUM 5.3
CVE-2026-21859

Mailpit is an email testing tool and API for developers. Versions 1.28.0 and below have a Server-Side Request Forgery (SSRF) vulnerability in the /pr…

Fix: 1.28.1+
Fix from $1,600 2026-01-08
Unclassified MEDIUM 5.3
CVE-2019-25290

Smartliving SmartLAN/G/SI <=6.x contains an unauthenticated server-side request forgery vulnerability in the GetImage functionality through the 'host…

No fix yet
Fix from $1,600 2026-01-08
Librechat HIGH 8.1
CVE-2025-69222

LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 is prone to a server-side request forgery (SSRF) vulnerability due to missin…

Patch available
Fix from $1,950 2026-01-07
Knowage MEDIUM 6.5
CVE-2025-58441

Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, there is a blind server-side request forgery vulnerabil…

Fix: 8.1.37+
Fix from $1,600 2026-01-07
Unclassified MEDIUM 6.4
CVE-2025-14438

The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.1.0.30 via t…

Mitigation only
Fix from $1,600 2026-01-06
Craft Cms MEDIUM 6.8
CVE-2025-68437

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, the Craft CMS GraphQL `save…

Fix: 4.16.17 / 5.8.21+
Fix from $1,600 2026-01-05
Spinnaker MEDIUM 6.6
CVE-2025-61916

Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3.0 are vulnerable to server-si…

Fix: 2025.1.6 / 2025.2.3+
Fix from $1,600 2026-01-05
Evershop MEDIUM 6.5
CVE-2025-67427

A Blind Server-Side Request Forgery (SSRF) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to force the server to initiate…

Fix: after 2.1.0
Fix from $1,600 2026-01-05
Emlog HIGH 7.7
CVE-2026-21433

Emlog is an open source website building system. Versions up to and including 2.5.19 are vulnerable to server-side Out-of-Band (OOB) requests / SSRF …

Fix: after 2.5.19
Fix from $1,950 2026-01-02
Unclassified MEDIUM 6.4
CVE-2025-14627

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and …

Mitigation only
Fix from $1,600 2026-01-01
Cowrie HIGH 7.5
CVE-2025-34469

Cowrie versions prior to 2.9.0 contain a server-side request forgery (SSRF) vulnerability in the emulated shell implementation of wget and curl. In t…

Fix: 2.9.0+
Fix from $1,950 2025-12-31
Unclassified MEDIUM 5.4
CVE-2025-62088

Server-Side Request Forgery (SSRF) vulnerability in extendons WordPress & WooCommerce Scraper Plugin, Import Data from Any Site wp_scraper allows Ser…

Mitigation only
Fix from $1,600 2025-12-31
Feehicms HIGH 7.3
CVE-2025-15264

A vulnerability was determined in FeehiCMS up to 2.1.1. Impacted is an unknown function of the file frontend/web/timthumb.php of the component TimThu…

Fix: after 2.1.1
Fix from $1,950 2025-12-30
Vvvebjs CRITICAL 9.1
CVE-2024-25181

A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSRF) and arbitrary file reading…

Fix: after 1.7.4
Fix from $2,300 2025-12-29
Unclassified MEDIUM 6.3
CVE-2025-15098

A vulnerability was determined in YunaiV yudao-cloud up to 2025.11. This affects the function BpmHttpCallbackTrigger/BpmSyncHttpRequestTrigger of the…

Mitigation only
Fix from $1,600 2025-12-26
Vidiu Pro Firmware MEDIUM 6.5
CVE-2019-25251

Teradek VidiU Pro 3.0.3 contains a server-side request forgery vulnerability in the management interface that allows attackers to manipulate GET para…

No fix yet
Fix from $1,600 2025-12-24
Unclassified MEDIUM 5.4
CVE-2025-67623

Server-Side Request Forgery (SSRF) vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Server Side Request Forgery.This issue affects …

Mitigation only
Fix from $1,600 2025-12-24
Httparty HIGH 8.2
CVE-2025-68696

httparty is an API tool. In versions 0.23.2 and prior, httparty is vulnerable to SSRF. This issue can pose a risk of leaking API keys, and it can als…

Fix: 0.24.0+
Fix from $1,950 2025-12-23