Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Unclassified MEDIUM 6.4
CVE-2025-22726

Server-Side Request Forgery (SSRF) vulnerability in _nK nK Themes Helper nk-themes-helper allows Server Side Request Forgery.This issue affects nK Th…

Mitigation only
Fix from $1,600 2026-01-08
Mailpit MEDIUM 5.3
CVE-2026-21859

Mailpit is an email testing tool and API for developers. Versions 1.28.0 and below have a Server-Side Request Forgery (SSRF) vulnerability in the /pr…

Fix: 1.28.1+
Fix from $1,600 2026-01-08
Unclassified MEDIUM 5.3
CVE-2019-25290

Smartliving SmartLAN/G/SI <=6.x contains an unauthenticated server-side request forgery vulnerability in the GetImage functionality through the 'host…

No fix yet
Fix from $1,600 2026-01-08
Librechat HIGH 8.1
CVE-2025-69222

LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 is prone to a server-side request forgery (SSRF) vulnerability due to missin…

Patch available
Fix from $1,950 2026-01-07
Knowage MEDIUM 6.5
CVE-2025-58441

Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, there is a blind server-side request forgery vulnerabil…

Fix: 8.1.37+
Fix from $1,600 2026-01-07
Unclassified MEDIUM 6.4
CVE-2025-14438

The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.1.0.30 via t…

Mitigation only
Fix from $1,600 2026-01-06
Craft Cms MEDIUM 6.8
CVE-2025-68437

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, the Craft CMS GraphQL `save…

Fix: 4.16.17 / 5.8.21+
Fix from $1,600 2026-01-05
Spinnaker MEDIUM 6.6
CVE-2025-61916

Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3.0 are vulnerable to server-si…

Fix: 2025.1.6 / 2025.2.3+
Fix from $1,600 2026-01-05
Evershop MEDIUM 6.5
CVE-2025-67427

A Blind Server-Side Request Forgery (SSRF) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to force the server to initiate…

Fix: after 2.1.0
Fix from $1,600 2026-01-05
Emlog HIGH 7.7
CVE-2026-21433

Emlog is an open source website building system. Versions up to and including 2.5.19 are vulnerable to server-side Out-of-Band (OOB) requests / SSRF …

Fix: after 2.5.19
Fix from $1,950 2026-01-02
Unclassified MEDIUM 6.4
CVE-2025-14627

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and …

Mitigation only
Fix from $1,600 2026-01-01
Cowrie HIGH 7.5
CVE-2025-34469

Cowrie versions prior to 2.9.0 contain a server-side request forgery (SSRF) vulnerability in the emulated shell implementation of wget and curl. In t…

Fix: 2.9.0+
Fix from $1,950 2025-12-31
Unclassified MEDIUM 5.4
CVE-2025-62088

Server-Side Request Forgery (SSRF) vulnerability in extendons WordPress & WooCommerce Scraper Plugin, Import Data from Any Site wp_scraper allows Ser…

Mitigation only
Fix from $1,600 2025-12-31
Feehicms HIGH 7.3
CVE-2025-15264

A vulnerability was determined in FeehiCMS up to 2.1.1. Impacted is an unknown function of the file frontend/web/timthumb.php of the component TimThu…

Fix: after 2.1.1
Fix from $1,950 2025-12-30
Vvvebjs CRITICAL 9.1
CVE-2024-25181

A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSRF) and arbitrary file reading…

Fix: after 1.7.4
Fix from $2,300 2025-12-29
Unclassified MEDIUM 6.3
CVE-2025-15098

A vulnerability was determined in YunaiV yudao-cloud up to 2025.11. This affects the function BpmHttpCallbackTrigger/BpmSyncHttpRequestTrigger of the…

Mitigation only
Fix from $1,600 2025-12-26
Vidiu Pro Firmware MEDIUM 6.5
CVE-2019-25251

Teradek VidiU Pro 3.0.3 contains a server-side request forgery vulnerability in the management interface that allows attackers to manipulate GET para…

No fix yet
Fix from $1,600 2025-12-24
Unclassified MEDIUM 5.4
CVE-2025-67623

Server-Side Request Forgery (SSRF) vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Server Side Request Forgery.This issue affects …

Mitigation only
Fix from $1,600 2025-12-24
Httparty HIGH 8.2
CVE-2025-68696

httparty is an API tool. In versions 0.23.2 and prior, httparty is vulnerable to SSRF. This issue can pose a risk of leaking API keys, and it can als…

Fix: 0.24.0+
Fix from $1,950 2025-12-23
Local Deep Research MEDIUM 6.5
CVE-2025-67743

Local Deep Research is an AI-powered research assistant for deep, iterative research. In versions from 1.3.0 to before 1.3.9, the download service (d…

Fix: 1.3.9+
Fix from $1,600 2025-12-23
Graphql Engine MEDIUM 5.3
CVE-2021-47715

Hasura GraphQL 1.3.3 contains a server-side request forgery vulnerability that allows attackers to inject arbitrary remote schema URLs through the ad…

No fix yet
Fix from $1,600 2025-12-22
Langflow MEDIUM 6.5
CVE-2025-68477EPSS 6%

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, Langflow provides an API Request component tha…

Fix: 1.7.0+
Fix from $1,600 2025-12-19
Unclassified HIGH 7.2
CVE-2025-13999

The HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all ve…

Mitigation only
Fix from $1,950 2025-12-19
Azure Language HIGH 8.8
CVE-2025-64663

Custom Question Answering Elevation of Privilege Vulnerability

No fix yet
Fix from $1,950 2025-12-18
Unclassified HIGH 8.7
CVE-2025-34452EPSS 5%

Streama versions 1.10.0 through 1.10.5 and prior to commit b7c8767 contain a combination of path traversal and server-side request forgery (SSRF) vul…

Patch available
Fix from $1,950 2025-12-18
Parse Server MEDIUM 6.5
CVE-2025-68150

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.2 and 9.1.1-alpha.1, th…

Fix: 8.6.2+
Fix from $1,600 2025-12-16
Ctera HIGH 7.5
CVE-2025-52196

Server-Side Request Forgery (SSRF) vulnerability in Ctera Portal 8.1.x (8.1.1417.24) allows remote attackers to induce the server to make arbitrary H…

Mitigation only
Fix from $1,950 2025-12-16
Podcast Generator CRITICAL 9.8
CVE-2023-53899

PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in the episode upload form. Att…

Mitigation only
Fix from $2,300 2025-12-16
Unclassified MEDIUM 6.4
CVE-2025-14443

A flaw was found in ose-openshift-apiserver. This vulnerability allows internal network enumeration, service discovery, limited information disclosur…

Mitigation only
Fix from $1,600 2025-12-16
Unclassified MEDIUM 5.4
CVE-2025-67989

Server-Side Request Forgery (SSRF) vulnerability in LMPixels Kerge kerge allows Server Side Request Forgery.This issue affects Kerge: from n/a throug…

No fix yet
Fix from $1,600 2025-12-16