Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Weblate MEDIUM 5.0
CVE-2025-66407

Weblate is a web based localization tool. The Create Component functionality in Weblate allows authorized users to add new translation components by …

Fix: 5.15+
Fix from $1,600 2025-12-16
Titan File MEDIUM 6.5
CVE-2023-53893

Ateme TITAN File 3.9.12.4 contains an authenticated server-side request forgery vulnerability in the job callback URL parameter that allows attackers…

No fix yet
Fix from $1,600 2025-12-15
Grav CRITICAL 9.1
CVE-2025-66844

In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the con…

Fix: 1.7.49.5+
Fix from $2,300 2025-12-15
Unclassified MEDIUM 5.8
CVE-2025-13281

A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vu…

Mitigation only
Fix from $1,600 2025-12-14
Powerjob CRITICAL 9.8
CVE-2025-14518

A vulnerability was identified in PowerJob up to 5.1.2. This vulnerability affects the function checkConnectivity of the file src/main/java/tech/powe…

Fix: after 5.1.2
Fix from $2,300 2025-12-11
Ucrop HIGH 8.8
CVE-2025-14516

A vulnerability was found in Yalantis uCrop 2.2.11. Affected by this issue is the function downloadFile of the file com.yalantis.ucrop.task.BitmapLoa…

No fix yet
Fix from $1,950 2025-12-11
Unclassified MEDIUM 5.8
CVE-2025-11467

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-S…

Mitigation only
Fix from $1,600 2025-12-11
Markdownify Mcp Server HIGH 7.5
CVE-2025-65512

A Server-Side Request Forgery (SSRF) vulnerability was discovered in the webpage-to-markdown conversion feature of markdownify-mcp v0.0.2 and before.…

Fix: after 0.0.2
Fix from $1,950 2025-12-10
Unclassified MEDIUM 6.9
CVE-2020-36884

BrightSign Digital Signage Diagnostic Web Server 8.2.26 and less contains an unauthenticated server-side request forgery vulnerability in the 'url' G…

No fix yet
Fix from $1,600 2025-12-10
Zitadel HIGH 8.6
CVE-2025-67494

ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, full-read SSRF vulnerability. …

Fix: 4.7.1+
Fix from $1,950 2025-12-09
Fetch Mcp Server HIGH 7.5
CVE-2025-65513

fetch-mcp v1.0.2 and before is vulnerable to Server-Side Request Forgery (SSRF) vulnerability, which allows attackers to bypass private IP validation…

Fix: after 1.0.2
Fix from $1,950 2025-12-09
Openbmcs HIGH 7.2
CVE-2021-47703

OpenBMCS 2.4 contains an unauthenticated SSRF vulnerability that allows attackers to bypass firewalls and initiate service and network enumeration on…

No fix yet
Fix from $1,950 2025-12-09
Infinera Mtc 9 Firmware HIGH 8.6
CVE-2025-26487

Server-Side Request Forgery (SSRF) vulnerability in Infinera MTC-9 version allows remote unauthenticated users to gain access to other network resou…

Fix: 23.0+
Fix from $1,950 2025-12-08
HTTP Server HIGH 7.5
CVE-2025-59775

Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off  allows to po…

Fix: 2.4.66+
Fix from $1,950 2025-12-05
Open Webui HIGH 7.1
CVE-2025-65958

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a Server-Side Request Forgery (SS…

Fix: 0.6.37+
Fix from $1,950 2025-12-04
Xunruicms HIGH 7.2
CVE-2025-14008

A flaw has been found in dayrui XunRuiCMS up to 4.7.1. This vulnerability affects unknown code of the file admin79f2ec220c7e.php?c=api&m=test_site_do…

Fix: after 4.7.1
Fix from $1,950 2025-12-04
Xunruicms CRITICAL 9.8
CVE-2025-14004

A security flaw has been discovered in dayrui XunRuiCMS up to 4.7.1. Affected is an unknown function of the file /admind45f74adbd95.php?c=email&m=add…

Fix: after 4.7.1
Fix from $2,300 2025-12-04
Opinio CRITICAL 9.1
CVE-2025-13872

Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-based platforms allows an atta…

Mitigation only
Fix from $2,300 2025-12-02
Gateway CRITICAL 9.8
CVE-2025-66405

Portkey.ai Gateway is a blazing fast AI Gateway with integrated guardrails. Prior to 1.14.0, the gateway determined the destination baseURL by priori…

Fix: 1.14.0+
Fix from $2,300 2025-12-01
Publiccms CRITICAL 9.1
CVE-2025-65836

PublicCMS V5.202506.b is vulnerable to SSRF. in the chat interface of SimpleAiAdminController.

No fix yet
Fix from $2,300 2025-12-01
Mogublog CRITICAL 9.8
CVE-2025-13814

A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the function LocalFileServiceImpl.uploadPictureByUrl of the fil…

Fix: after 5.2
Fix from $2,300 2025-12-01
Orion Ops MEDIUM 6.5
CVE-2025-13809

A vulnerability has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected by this issue is some unknown functiona…

Fix: after 2025-08-01
Fix from $1,600 2025-12-01
Unclassified MEDIUM 6.3
CVE-2025-13796

A security vulnerability has been detected in deco-cx apps up to 0.120.1. Affected by this vulnerability is the function AnalyticsScript of the file …

Patch available
Fix from $1,600 2025-12-01
Zentao MEDIUM 5.3
CVE-2025-13789

A vulnerability was found in ZenTao up to 21.7.6-8564. This affects the function makeRequest of the file module/ai/model.php. The manipulation of the…

Fix: 21.7.6+
Fix from $1,600 2025-11-30
Librechat HIGH 8.1
CVE-2025-66201

LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.1-rc2, LibreChat is vulnerable to Server-side Request Forgery (SSRF), by …

Fix: 0.8.1+
Fix from $1,950 2025-11-29
Unclassified MEDIUM 6.5
CVE-2025-13378

The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and…

Mitigation only
Fix from $1,600 2025-11-27
Unclassified HIGH 8.7
CVE-2025-34350

UnForm Server versions < 10.1.15 contain an unauthenticated arbitrary file read and SMB coercion vulnerability in the Doc Flow feature’s 'arc' endpoi…

Mitigation only
Fix from $1,950 2025-11-25
Unclassified HIGH 7.6
CVE-2025-33203

NVIDIA NeMo Agent Toolkit UI for Web contains a vulnerability in the chat API endpoint where an attacker may cause a Server-Side Request Forgery. A s…

Mitigation only
Fix from $1,950 2025-11-25
Unclassified HIGH 8.5
CVE-2025-62155

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.9.6, a recently patched S…

Mitigation only
Fix from $1,950 2025-11-25
Unclassified MEDIUM 6.3
CVE-2025-13588

A vulnerability was found in lKinderBueno Streamity Xtream IPTV Player up to 2.8. The impacted element is an unknown function of the file public/prox…

Patch available
Fix from $1,600 2025-11-24