Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Dragonfly MEDIUM 5.3
CVE-2025-59346

Dragonfly is an open source P2P-based file distribution and image acceleration system. Versions prior to 2.1.0 contain a server-side request forgery …

Fix: 2.1.0+
Fix from $1,600 2025-09-17
Wondercms MEDIUM 6.5
CVE-2025-57055

WonderCMS 3.5.0 is vulnerable to Server-Side Request Forgery (SSRF) in the custom module installation functionality. An authenticated administrator c…

No fix yet
Fix from $1,600 2025-09-17
Ghost MEDIUM 6.5
CVE-2025-9862

Server-Side Request Forgery (SSRF) vulnerability in Ghost allows an attacker to access internal resources.This issue affects Ghost: from 6.0.0 throug…

Fix: after 6.0.8
Fix from $1,600 2025-09-17
Unclassified MEDIUM 6.9
CVE-2025-59155

hackmd-mcp is a Model Context Protocol server for integrating HackMD's note-taking platform with AI assistants. From 1.4.0 to before 1.5.0, hackmd-mc…

Patch available
Fix from $1,600 2025-09-15
Zkeacms HIGH 8.8
CVE-2025-10471

A vulnerability was detected in ZKEACMS 4.3. Impacted is the function Proxy of the file src/ZKEACMS/Controllers/MediaController.cs. Performing manipu…

No fix yet
Fix from $1,950 2025-09-15
Dataease CRITICAL 9.8
CVE-2025-58045

Dataease is an open source data analytics and visualization platform. In Dataease versions up to 2.10.12, the patch introduced to mitigate DB2 JDBC d…

Fix: 2.10.13+
Fix from $2,300 2025-09-15
Unclassified MEDIUM 5.3
CVE-2025-10453

O'View MapServer developed by PilotGaea Technologies has a Server-Side Request Forgery vulnerability, allowing unauthenticated remote attackers to ex…

Mitigation only
Fix from $1,600 2025-09-15
Link Status Checker CRITICAL 9.8
CVE-2025-10410

A security vulnerability has been detected in SourceCodester Link Status Checker 1.0. This vulnerability affects unknown code of the file index.php. …

Mitigation only
Fix from $2,300 2025-09-14
Maccms HIGH 7.2
CVE-2025-10397

A vulnerability was identified in Magicblack MacCMS 2025.1000.4050. This affects an unknown part of the component API Handler. The manipulation of th…

Mitigation only
Fix from $1,950 2025-09-14
Maccms HIGH 7.2
CVE-2025-10395

A vulnerability was found in Magicblack MacCMS 2025.1000.4050. Affected by this vulnerability is the function col_url of the component Scheduled Task…

Mitigation only
Fix from $1,950 2025-09-14
Unclassified MEDIUM 6.3
CVE-2025-10393

A flaw has been found in miurla morphic up to 0.4.5. This impacts the function fetchHtml of the file /api/advanced-search of the component HTTP Statu…

Mitigation only
Fix from $1,600 2025-09-14
Crmeb HIGH 8.8
CVE-2025-10391

A security vulnerability has been detected in CRMEB up to 5.6.1. The impacted element is the function testOutUrl of the file app/services/out/OutAcco…

Fix: after 5.6.1
Fix from $1,950 2025-09-14
Unmark CRITICAL 9.8
CVE-2025-10329

A vulnerability was detected in cdevroe unmark up to 1.9.3. This affects an unknown part of the file /application/controllers/Marks.php. The manipula…

Fix: after 1.9.3
Fix from $2,300 2025-09-12
GitLab HIGH 8.8
CVE-2025-6454

An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could h…

Fix: 18.1.6 / 18.2.6+
Fix from $1,950 2025-09-12
Instantcms HIGH 7.2
CVE-2025-59055

InstantCMS is a free and open source content management system. A blind Server-Side Request Forgery (SSRF) vulnerability in InstantCMS up to and incl…

Fix: after 2.17.3
Fix from $1,950 2025-09-11
Chancms MEDIUM 6.3
CVE-2025-10211

A security vulnerability has been detected in yanyutao0402 ChanCMS 3.3.0. The affected element is the function CollectController of the file /cms/col…

No fix yet
Fix from $1,600 2025-09-10
Unclassified MEDIUM 6.4
CVE-2025-7843

The Auto Save Remote Images (Drafts) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.9 vi…

Mitigation only
Fix from $1,600 2025-09-10
Halo CRITICAL 9.1
CVE-2025-44594

halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/attachments/-/upload-from-url.

Fix: after 2.20.17
Fix from $2,300 2025-09-09
Unclassified MEDIUM 6.9
CVE-2025-9269

A Server-Side Request Forgery (SSRF) vulnerability has been identified in the embedded web server in various Lexmark devices. This vulnerability can …

Mitigation only
Fix from $1,600 2025-09-09
Lingdang Crm HIGH 7.3
CVE-2025-5005

A vulnerability was detected in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.5.4. This affects an unknown function of the file crm…

Fix: after 8.6.5.4
Fix from $1,950 2025-09-09
Experience Manager MEDIUM 6.5
CVE-2025-54249

Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Secu…

Fix: after 2025.8.0
Fix from $1,600 2025-09-09
Unclassified HIGH 7.2
CVE-2025-49430

Server-Side Request Forgery (SSRF) vulnerability in FWDesign Ultimate Video Player fwduvp allows Server Side Request Forgery.This issue affects Ultim…

Mitigation only
Fix from $1,950 2025-09-09
Unclassified MEDIUM 6.4
CVE-2025-47437

Server-Side Request Forgery (SSRF) vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n…

Mitigation only
Fix from $1,600 2025-09-09
Connect Secure MEDIUM 6.8
CVE-2025-55139

SSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neuro…

Fix: 22.7 / 22.8+
Fix from $1,600 2025-09-09
Thinmanager HIGH 8.8
CVE-2025-9065

A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of input sanitization. Authentic…

Fix: after 14.0.0
Fix from $1,950 2025-09-09
Digital Experience Platform MEDIUM 6.5
CVE-2025-43763

A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7,…

Fix: 7.4.3.132 / 2024.q1.21+
Fix from $1,600 2025-09-09
Sim MEDIUM 6.5
CVE-2025-10096

A vulnerability was determined in SimStudioAI sim up to 1.0.0. This affects an unknown function of the file apps/sim/app/api/files/parse/route.ts. Ex…

Fix: 0.3.40+
Fix from $1,600 2025-09-08
Ditty HIGH 8.6
CVE-2025-8085EPSS 17%

The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated …

Fix: 3.1.58+
Fix from $1,950 2025-09-08
\@astrojs\/cloudflare MEDIUM 6.5
CVE-2025-58179

Astro is a web framework for content-driven websites. Versions 11.0.3 through 12.6.5 are vulnerable to SSRF when using Astro's Cloudflare adapter. Wh…

Fix: 12.6.6+
Fix from $1,600 2025-09-05
Unclassified MEDIUM 5.4
CVE-2025-58641

Server-Side Request Forgery (SSRF) vulnerability in kamleshyadav Exit Intent Popup exitintentpopup allows Server Side Request Forgery.This issue affe…

Mitigation only
Fix from $1,600 2025-09-03