Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Sim HIGH 7.5
CVE-2025-9805

A vulnerability was found in SimStudioAI sim up to 51b1e97fa22c48d144aef75f8ca31a74ad2cfed2. This issue affects some unknown processing of the file a…

Fix: 0.3.40+
Fix from $1,950 2025-09-02
Langfuse MEDIUM 5.0
CVE-2025-9799

A security flaw has been discovered in Langfuse up to 3.88.0. Affected by this vulnerability is the function promptChangeEventSourcing of the file we…

Fix: after 3.88.0
Fix from $1,600 2025-09-01
Knowage MEDIUM 5.3
CVE-2025-55007

Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, Knowage is vulnerable to server-side request forgery. T…

Fix: 8.1.37+
Fix from $1,600 2025-09-01
Next.js HIGH 8.2
CVE-2025-57822

Next.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next() was used without explicitly …

Fix: 14.2.32 / 15.4.7+
Fix from $1,950 2025-08-29
Unclassified MEDIUM 6.4
CVE-2025-53250

Server-Side Request Forgery (SSRF) vulnerability in Chartbeat Chartbeat chartbeat allows Server Side Request Forgery.This issue affects Chartbeat: fr…

Mitigation only
Fix from $1,600 2025-08-28
Unclassified MEDIUM 6.3
CVE-2025-57818

Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to version 2.0.1, a server-side request forgery (SSRF) vulnerabilit…

Patch available
Fix from $1,600 2025-08-26
Unclassified MEDIUM 5.5
CVE-2025-57814

request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Versions 1.x.x and earlier contain …

No fix yet
Fix from $1,600 2025-08-25
Rebuild MEDIUM 5.1
CVE-2024-46413

Rebuild v3.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the type parameter in the com.rebuild.web.admin.rbstore.RBStoreCont…

Fix: after 3.7.7
Fix from $1,600 2025-08-25
Unclassified HIGH 8.7
CVE-2025-54370

PhpOffice/PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to versions 1.30.0, 2.1.12, 2.4.0, 3.10.0, and 5.0.0,…

Patch available
Fix from $1,950 2025-08-25
Utcms HIGH 7.2
CVE-2025-9402

A vulnerability was found in HuangDou UTCMS 9. This issue affects some unknown processing of the file app/modules/ut-frame/admin/update.php of the co…

No fix yet
Fix from $1,950 2025-08-25
Unclassified MEDIUM 6.3
CVE-2025-9395

A vulnerability was identified in wangsongyan wblog 0.0.1. This affects the function RestorePost of the file backup.go. Such manipulation of the argu…

No fix yet
Fix from $1,600 2025-08-24
Unclassified HIGH 7.2
CVE-2025-7813

The Events Calendar, Event Booking, Registrations and Event Tickets – Eventin plugin for WordPress is vulnerable to Server-Side Request Forgery in al…

Mitigation only
Fix from $1,950 2025-08-23
Unclassified MEDIUM 5.9
CVE-2025-8678

The WP Crontrol plugin for WordPress is vulnerable to blind Server-Side Request Forgery in versions 1.17.0 to 1.19.1 via the 'wp_remote_request' func…

Mitigation only
Fix from $1,600 2025-08-22
Digital Experience Platform MEDIUM 6.5
CVE-2025-43747

A server-side request forgery (SSRF) vulnerability exists in the Liferay DXP 2025.Q2.0 through 2025.Q2.3 due to insecure domain validation on analyti…

Fix: 2025.Q2.4+
Fix from $1,600 2025-08-21
Unclassified CRITICAL 9.1
CVE-2025-27217

A Server-Side Request Forgery (SSRF) in the UISP Application may allow a malicious actor with certain permissions to make requests outside of UISP Ap…

Mitigation only
Fix from $2,300 2025-08-21
Edge Application Manager MEDIUM 5.4
CVE-2025-1142

IBM Edge Application Manager 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized r…

Mitigation only
Fix from $1,600 2025-08-20
Unclassified HIGH 7.5
CVE-2025-54924

CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data when an attacker sends a spec…

No fix yet
Fix from $1,950 2025-08-20
Unclassified HIGH 7.5
CVE-2025-54925

CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data when an attacker configures t…

Mitigation only
Fix from $1,950 2025-08-20
Eventmesh MEDIUM 6.3
CVE-2024-39954

CWE-918 Server-Side Request Forgery (SSRF) in eventmesh-runtime module in WebhookUtil.java on windows\linux\mac os e.g. allows the attacker can abuse…

Fix: 1.12.0+
Fix from $1,600 2025-08-20
Unclassified HIGH 8.6
CVE-2025-5260

Server-Side Request Forgery (SSRF) vulnerability in Pik Online Yazılım Çözümleri A.Ş. Pik Online allows Server Side Request Forgery. This issue affe…

Mitigation only
Fix from $1,950 2025-08-20
Ai Seo Link Advisor HIGH 8.8
CVE-2025-8675

Server-Side Request Forgery (SSRF) vulnerability in Drupal AI SEO Link Advisor allows Server Side Request Forgery.This issue affects AI SEO Link Advi…

Fix: 1.0.6+
Fix from $1,950 2025-08-15
Unclassified MEDIUM 5.5
CVE-2025-53241

Server-Side Request Forgery (SSRF) vulnerability in kodeshpa Simplified simplified allows Server Side Request Forgery.This issue affects Simplified: …

Mitigation only
Fix from $1,600 2025-08-14
Unclassified MEDIUM 6.4
CVE-2025-28987

Server-Side Request Forgery (SSRF) vulnerability in PressForward PressForward pressforward allows Server Side Request Forgery.This issue affects Pres…

No fix yet
Fix from $1,600 2025-08-14
Unclassified CRITICAL 9.1
CVE-2025-50251

Server side request forgery (SSRF) vulnerability in makeplane plane 0.23.1 via the password recovery.

No fix yet
Fix from $2,300 2025-08-13
Sharepoint Server HIGH 7.1
CVE-2025-53760EPSS 12%

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

Fix: 16.0.18526.20518+
Fix from $1,950 2025-08-12
Camera Station MEDIUM 5.7
CVE-2025-7622

During an internal security assessment, a Server-Side Request Forgery (SSRF) vulnerability that allowed an authenticated attacker to access internal …

Fix: 5.59.49607 / 6.10.49500+
Fix from $1,600 2025-08-12
Stirling Pdf CRITICAL 9.8
CVE-2025-55161

Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, when using the /api/v1/conver…

Fix: 1.1.0+
Fix from $2,300 2025-08-11
Stirling Pdf CRITICAL 9.8
CVE-2025-55151

Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, the "convert file to pdf" fun…

Fix: 1.1.0+
Fix from $2,300 2025-08-11
Stirling Pdf CRITICAL 9.8
CVE-2025-55150

Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, when using the /api/v1/conver…

Fix: 1.1.0+
Fix from $2,300 2025-08-11
Unclassified HIGH 8.6
CVE-2025-25235

Server-Side Request Forgery (SSRF) in Omnissa Secure Email Gateway (SEG) in SEG prior to 2.32 running on Windows and SEG prior to 2503 running on UAG…

Mitigation only
Fix from $1,950 2025-08-11