Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Unclassified MEDIUM 6.4
CVE-2025-12800

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including…

Mitigation only
Fix from $1,600 2025-11-23
Azure Monitor CRITICAL 9.8
CVE-2025-62207

Azure Monitor Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-11-20
Moveit Transfer MEDIUM 5.3
CVE-2025-13147

Server-Side Request Forgery (SSRF) vulnerability in Progress MOVEit Transfer.This issue affects MOVEit Transfer: before 2024.1.8, from 2025.0.0 befor…

Fix: 2024.1.8 / 2025.0.4+
Fix from $1,600 2025-11-19
Unclassified MEDIUM 5.4
CVE-2025-12359

The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.3 via t…

Mitigation only
Fix from $1,600 2025-11-19
Agent Dvr HIGH 7.8
CVE-2025-63408

Local Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local attacker to gain access to sensitive…

Fix: after 6.6.7.0
Fix from $1,950 2025-11-18
Unclassified MEDIUM 6.8
CVE-2025-8084

The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.8 via the rest_helpers_crea…

Mitigation only
Fix from $1,600 2025-11-18
Unclassified MEDIUM 6.4
CVE-2025-12376

The Icon List Block – Add Icon-Based Lists with Custom Styles plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to…

Mitigation only
Fix from $1,600 2025-11-18
Unclassified MEDIUM 5.8
CVE-2025-11427

The WP Migrate Lite – WordPress Migration Made Easy plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, an…

Mitigation only
Fix from $1,600 2025-11-18
Unclassified MEDIUM 6.4
CVE-2025-12962

The Local Syndication plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.5a via the `url` para…

Mitigation only
Fix from $1,600 2025-11-18
Unclassified MEDIUM 6.3
CVE-2025-13174

A weakness has been identified in rachelos WeRSS we-mp-rss up to 1.4.7. Affected by this vulnerability is the function do_job of the file /rachelos/w…

Mitigation only
Fix from $1,600 2025-11-14
Grist Core MEDIUM 6.5
CVE-2025-64752

grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with access to any document on a Grist installation can use a feature for …

Fix: 1.7.7+
Fix from $1,600 2025-11-13
Typebot CRITICAL 9.9
CVE-2025-64709

Typebot is an open-source chatbot builder. In versions prior to 3.13.1, a Server-Side Request Forgery (SSRF) vulnerability in the Typebot webhook blo…

Fix: 3.13.1+
Fix from $2,300 2025-11-13
Maxkb HIGH 8.8
CVE-2025-64511

MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can access internal network services such as databases throug…

Fix: 2.3.1+
Fix from $1,950 2025-11-13
Astro MEDIUM 6.5
CVE-2025-64525

Astro is a web framework. In Astro versions 2.16.0 up to but excluding 5.15.5 which utilizeon-demand rendering, request headers `x-forwarded-proto` a…

Fix: 5.15.5+
Fix from $1,600 2025-11-13
Lila MEDIUM 6.5
CVE-2025-52186

Lichess lila before commit 11b4c0fb00f0ffd823246f839627005459c8f05c (2025-06-02) contains a Server-Side Request Forgery (SSRF) vulnerability in the g…

Fix: 2025-06-02+
Fix from $1,600 2025-11-13
Unclassified HIGH 8.6
CVE-2025-59088

If kdcproxy receives a request for a realm which does not have server addresses defined in its configuration, by default, it will query SRV records i…

Patch available
Fix from $1,950 2025-11-12
Soft Serve HIGH 7.6
CVE-2025-64522

Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where webhook URLs are not validate…

Fix: 0.11.1+
Fix from $1,950 2025-11-10
Unclassified HIGH 7.5
CVE-2025-64430

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions 4.2.0 through 7.5.3, and 8.0.0 th…

Patch available
Fix from $1,950 2025-11-07
Unclassified CRITICAL 10.0
CVE-2025-64180

Manager-io/Manager is accounting software. In Manager Desktop and Server versions 25.11.1.3085 and below, a critical vulnerability permits unauthoriz…

Mitigation only
Fix from $2,300 2025-11-07
Unclassified HIGH 8.9
CVE-2025-64178

Jellysweep is a cleanup tool for the Jellyfin media server. In versions 0.12.1 and below, /api/images/cache, used to download media posters from the …

Patch available
Fix from $1,950 2025-11-06
Thinkdashboard MEDIUM 5.3
CVE-2025-64327

ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. Versions 0.6.7 and below contain a Blind Server-Side Request…

Fix: 0.6.8+
Fix from $1,600 2025-11-06
Metinfo HIGH 7.5
CVE-2025-63551

A Server-Side Request Forgery (SSRF) vulnerability, achievable through an XML External Entity (XXE) injection, exists in MetInfo Content Management S…

Fix: 8.1+
Fix from $1,950 2025-11-06
Prompt Optimizer HIGH 7.3
CVE-2025-60541

A Server-Side Request Forgery (SSRF) in the /api/proxy/ component of linshenkx prompt-optimizer v1.3.0 to v1.4.2 allows attackers to scan internal re…

Fix: after 1.4.2
Fix from $1,950 2025-11-06
Dataease CRITICAL 9.8
CVE-2025-64163

DataEase is an open source data visualization analysis tool. In versions 2.10.14 and below, the vendor added a blacklist to filter ldap:// and ldaps:…

Fix: 2.10.15+
Fix from $2,300 2025-11-06
Unclassified MEDIUM 6.4
CVE-2025-11917

The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.11 via the…

Patch available
Fix from $1,600 2025-11-05
Unclassified MEDIUM 6.4
CVE-2025-12388

The B Carousel Block – Responsive Image and Content Carousel plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and…

Mitigation only
Fix from $1,600 2025-11-05
Unclassified CRITICAL 9.3
CVE-2023-7325

Anheng Mingyu Operation and Maintenance Audit and Risk Control System up to 2023-08-10 contains a server-side request forgery (SSRF) vulnerability in…

Mitigation only
Fix from $2,300 2025-10-30
Nagios Xi MEDIUM 6.1
CVE-2020-36862

Nagios XI versions prior to 5.6.11 contain unauthenticated vulnerabilities in the Highcharts local exporting tool. Crafted export requests could (1) …

Fix: 5.6.11+
Fix from $1,600 2025-10-30
Perfreeblog MEDIUM 6.5
CVE-2025-60319

PerfreeBlog v4.0.11 is vulnerable to Server-Side Request Forgery due to a missing authorization check in the uploadAttachByUrl API endpoint (AttachCo…

Patch available
Fix from $1,600 2025-10-30
Unclassified MEDIUM 5.8
CVE-2025-60898

An unauthenticated server-side request forgery (SSRF) vulnerability in the Thumbnail via-uri endpoint of Halo CMS 2.21 allows a remote attacker to ca…

Mitigation only
Fix from $1,600 2025-10-29