Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Opensupports MEDIUM 5.3
CVE-2025-10695

Two unauthenticated diagnostic endpoints allow arbitrary backend-initiated network connections to an attacker‑supplied destination. Both endpoints ar…

No fix yet
Fix from $1,600 2025-10-03
Vitaracharts MEDIUM 6.5
CVE-2025-57305

VitaraCharts 5.3.5 is vulnerable to Server-Side Request Forgery in fileLoader.jsp.

No fix yet
Fix from $1,600 2025-10-02
Kylin HIGH 7.3
CVE-2025-61735

Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. You are fine as long as…

Fix: 5.0.3+
Fix from $1,950 2025-10-02
Splunk HIGH 8.8
CVE-2025-20371

In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2408.119 and 9.2.2406.…

Fix: 9.2.8 / 9.2.2406.122+
Fix from $1,950 2025-10-01
Dify MEDIUM 5.3
CVE-2025-56520

Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi. A …

No fix yet
Fix from $1,600 2025-09-30
Virtual Appliance Application MEDIUM 5.3
CVE-2025-34232

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments…

Fix: 25.1.102 / 25.1.1413+
Fix from $1,600 2025-09-29
Virtual Appliance Application MEDIUM 6.8
CVE-2025-34233

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments…

Fix: 25.1.102 / 25.1.1413+
Fix from $1,600 2025-09-29
Virtual Appliance Application HIGH 8.6
CVE-2025-34225

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments…

Fix: 25.1.102 / 25.1.1413+
Fix from $1,950 2025-09-29
Virtual Appliance Application HIGH 8.6
CVE-2025-34228

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments…

Fix: 25.1.102 / 25.1.1413+
Fix from $1,950 2025-09-29
Virtual Appliance Application MEDIUM 5.8
CVE-2025-34229

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments…

Fix: 25.1.102 / 25.1.1413+
Fix from $1,600 2025-09-29
Virtual Appliance Application MEDIUM 5.8
CVE-2025-34230

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments…

Fix: 25.1.102 / 25.1.1413+
Fix from $1,600 2025-09-29
Virtual Appliance Application HIGH 8.6
CVE-2025-34231

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments…

Fix: 25.1.102 / 25.1.1413+
Fix from $1,950 2025-09-29
Weknora CRITICAL 9.8
CVE-2025-11046

A security flaw has been discovered in Tencent WeKnora 0.1.0. This impacts the function testEmbeddingModel of the file /api/v1/initialization/embeddi…

Mitigation only
Fix from $2,300 2025-09-26
Unclassified MEDIUM 5.4
CVE-2025-60181

Server-Side Request Forgery (SSRF) vulnerability in silence Silencesoft RSS Reader external-rss-reader allows Server Side Request Forgery.This issue …

Mitigation only
Fix from $1,600 2025-09-26
Unclassified MEDIUM 5.4
CVE-2025-60161

Server-Side Request Forgery (SSRF) vulnerability in bdthemes ZoloBlocks zoloblocks allows Server Side Request Forgery.This issue affects ZoloBlocks: …

Mitigation only
Fix from $1,600 2025-09-26
Unclassified MEDIUM 5.4
CVE-2025-10137

The Snow Monkey theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 29.1.5 via the request() funct…

Mitigation only
Fix from $1,600 2025-09-26
Unclassified CRITICAL 9.5
CVE-2020-36851

Rob--W cors-anywhere instances configured as an open proxy allow unauthenticated external users to induce the server to make HTTP requests to arbitra…

Mitigation only
Fix from $2,300 2025-09-25
Flowise HIGH 7.5
CVE-2025-59527

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, a Server-Side Request Forgery (SSRF) vulne…

No fix yet
Fix from $1,950 2025-09-22
Unclassified MEDIUM 6.9
CVE-2025-9960

A restriction bypass vulnerability in is-localhost-ip could allow attackers to perform Server-Side Request Forgery (SSRF). This issue affects is-loca…

No fix yet
Fix from $1,600 2025-09-22
Unclassified MEDIUM 6.4
CVE-2025-58962

Server-Side Request Forgery (SSRF) vulnerability in publitio Publitio publitio allows Server Side Request Forgery.This issue affects Publitio: from n…

Mitigation only
Fix from $1,600 2025-09-22
Unclassified MEDIUM 6.4
CVE-2025-58011

Server-Side Request Forgery (SSRF) vulnerability in Alex Content Mask content-mask allows Server Side Request Forgery.This issue affects Content Mask…

Mitigation only
Fix from $1,600 2025-09-22
Unclassified MEDIUM 5.4
CVE-2025-58005

Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft DriCub dricub-driving-school allows Server Side Request Forgery.This issue affects …

No fix yet
Fix from $1,600 2025-09-22
Webmethods Integration MEDIUM 5.4
CVE-2025-36037

IBM webMethods Integration 10.15 and 11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send una…

Mitigation only
Fix from $1,600 2025-09-22
Unclassified MEDIUM 6.3
CVE-2025-10787

A vulnerability was found in MuYuCMS up to 2.7. Impacted is an unknown function of the file /index/index.html of the component Add Fiend Link Handler…

Mitigation only
Fix from $1,600 2025-09-22
Zkeacms HIGH 7.2
CVE-2025-10765

A security flaw has been discovered in SeriaWei ZKEACMS up to 4.3. This vulnerability affects the function CheckPage/Suggestions in the library cms-v…

Fix: after 4.3
Fix from $1,950 2025-09-21
Zkeacms HIGH 8.8
CVE-2025-10764

A vulnerability was identified in SeriaWei ZKEACMS up to 4.3. This affects the function Edit of the file src/ZKEACMS.EventAction/Controllers/PendingT…

Fix: after 4.3
Fix from $1,950 2025-09-21
Unclassified MEDIUM 6.3
CVE-2025-10760

A flaw has been found in Harness 3.3.0. This impacts the function LookupRepo of the file app/api/controller/gitspace/lookup_repo.go. Executing manipu…

No fix yet
Fix from $1,600 2025-09-21
Storagegrid HIGH 7.5
CVE-2025-26515

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 without Single Sign-on enabled are susceptible to a Server-Sid…

Fix: 11.8.0.15 / 11.9.0.8+
Fix from $1,950 2025-09-19
Automation Platform CRITICAL 9.1
CVE-2025-57644

Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative user can exe…

Mitigation only
Fix from $2,300 2025-09-19
Unclassified HIGH 7.7
CVE-2025-59344

AliasVault is a privacy-first password manager with built-in email aliasing. A server-side request forgery (SSRF) vulnerability exists in the favicon…

Patch available
Fix from $1,950 2025-09-19