Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Astro HIGH 7.2
CVE-2025-59837

Astro is a web framework that includes an image proxy. In versions 5.13.4 and later before 5.13.10, the image proxy domain validation can be bypassed…

Fix: 5.13.10+
Fix from $1,950 2025-10-28
Concert MEDIUM 5.4
CVE-2025-36085

IBM Concert 1.0.0 through 2.0.0 Software is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauth…

Fix: 2.1.0+
Fix from $1,600 2025-10-28
Unclassified HIGH 7.5
CVE-2025-10861

The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPress is vulnerable to Server-S…

Mitigation only
Fix from $1,950 2025-10-24
Unclassified MEDIUM 6.8
CVE-2025-12136

The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and i…

No fix yet
Fix from $1,600 2025-10-24
Unclassified MEDIUM 5.5
CVE-2025-10874

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.2 does not limit URLs which ma…

Mitigation only
Fix from $1,600 2025-10-24
Azure Compute Resource Provider CRITICAL 9.8
CVE-2025-59503

Server-side request forgery (ssrf) in Azure Compute Gallery allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-10-23
Unclassified MEDIUM 5.0
CVE-2025-11128

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Server-Side Re…

Mitigation only
Fix from $1,600 2025-10-23
Unclassified MEDIUM 5.3
CVE-2025-10705

The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2…

Mitigation only
Fix from $1,600 2025-10-23
Fastgpt MEDIUM 5.3
CVE-2025-62612

FastGPT is an AI Agent building platform. Prior to version 4.11.1, in the workflow file reading node, the network link is not security-verified, posi…

Fix: 4.11.1+
Fix from $1,600 2025-10-22
Unclassified MEDIUM 5.4
CVE-2025-49374

Server-Side Request Forgery (SSRF) vulnerability in captcha.eu Captcha.eu captcha-eu allows Server Side Request Forgery.This issue affects Captcha.eu…

Mitigation only
Fix from $1,600 2025-10-22
Unclassified MEDIUM 5.0
CVE-2025-62763

Zimbra Collaboration (ZCS) before 10.1.12 allows SSRF because of the configuration of the chat proxy.

Mitigation only
Fix from $1,600 2025-10-21
Unclassified MEDIUM 5.0
CVE-2025-11536

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 8…

Mitigation only
Fix from $1,600 2025-10-20
Unclassified HIGH 7.6
CVE-2025-61488

An issue in Senayan Library Management System (SLiMS) 9 Bulian v.9.6.1 allows a remote attacker to execute arbitrary code via the scrap_image.php com…

Mitigation only
Fix from $1,950 2025-10-20
Unclassified MEDIUM 6.4
CVE-2025-11361

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in al…

Mitigation only
Fix from $1,600 2025-10-18
Thingsboard CRITICAL 9.1
CVE-2025-34282

ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload Gallery feature. An attacker …

Fix: 4.2.1+
Fix from $2,300 2025-10-17
Unclassified CRITICAL 9.6
CVE-2025-60279

A server-side request forgery (SSRF) vulnerability in Illia Cloud illia-Builder before v4.8.5 allows authenticated users to send arbitrary requests t…

Mitigation only
Fix from $2,300 2025-10-17
Unclassified HIGH 7.3
CVE-2025-11864

A vulnerability was identified in NucleoidAI Nucleoid up to 0.7.10. The impacted element is the function extension.apply of the file /src/cluster.ts …

Mitigation only
Fix from $1,950 2025-10-16
Unclassified HIGH 8.7
CVE-2025-62427

The Angular SSR is a server-rise rendering tool for Angular applications. The vulnerability is a Server-Side Request Forgery (SSRF) flaw within the U…

Patch available
Fix from $1,950 2025-10-16
Unclassified MEDIUM 6.5
CVE-2025-60540

karakeep v0.26.0 to v0.7.0 was discovered to contain a Server-Side Request Forgery (SSRF).

Mitigation only
Fix from $1,600 2025-10-14
Unclassified MEDIUM 6.8
CVE-2025-11674

SOOP-CLM developed by PiExtract has a Server-Side Request Forgery vulnerability, allowing privileged remote attackers to read server files or probe i…

Mitigation only
Fix from $1,600 2025-10-13
Furbo Mini Firmware HIGH 7.4
CVE-2025-11648

A vulnerability has been found in Tomofun Furbo 360 and Furbo Mini. Impacted is an unknown function of the file TF_FQDN.json of the component GATT In…

Fix: after 074
Fix from $1,950 2025-10-12
Furbo 360 Dog Camera Firmware HIGH 8.1
CVE-2025-11636

A security vulnerability has been detected in Tomofun Furbo 360 up to FB0035_FW_036. This issue affects some unknown processing of the component Acco…

Fix: after 036
Fix from $1,950 2025-10-12
Configurator HIGH 7.5
CVE-2025-61884 KEVEPSS 98%

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3…

Fix: after 12.2.14
Fix from $1,950 2025-10-12
Unica Centralized Offer Management CRITICAL 9.8
CVE-2025-31993

HCL Unica Centralized Offer Management is vulnerable to a potential Server-Side Request Forgery (SSRF). An attacker can exploit improper input valida…

Fix: 25.1.0.1+
Fix from $2,300 2025-10-12
Unclassified MEDIUM 6.8
CVE-2025-9975

The WP Scraper plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.8.1 via the wp_scraper_extra…

Mitigation only
Fix from $1,600 2025-10-11
Unclassified HIGH 8.5
CVE-2025-59146

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. An authenticated Server-Side Request Forgery…

Patch available
Fix from $1,950 2025-10-09
Unclassified HIGH 8.7
CVE-2025-9868

Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated re…

Mitigation only
Fix from $1,950 2025-10-08
Unclassified HIGH 7.1
CVE-2025-6242

A Server-Side Request Forgery (SSRF) vulnerability exists in the MediaConnector class within the vLLM project's multimodal feature set. The load_from…

Mitigation only
Fix from $1,950 2025-10-07
Llama Factory HIGH 8.1
CVE-2025-61784

LLaMA-Factory is a tuning library for large language models. Prior to version 0.9.4, a Server-Side Request Forgery (SSRF) vulnerability in the chat A…

Fix: 0.9.4+
Fix from $1,950 2025-10-07
Unclassified MEDIUM 5.1
CVE-2025-61768

KUNO CMS is a fully deployable full-stack blog application. In versions prior to 1.3.15, an SSRF (Server-Side Request Forgery) vulnerability exists i…

Patch available
Fix from $1,600 2025-10-06