Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Unclassified MEDIUM 5.4
CVE-2025-25229

Omnissa Workspace ONE UEM contains a Server-Side Request Forgery (SSRF) Vulnerability. A malicious actor with user privileges may be able to access r…

Mitigation only
Fix from $1,600 2025-08-11
Digital Experience Platform HIGH 8.6
CVE-2025-4581

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.…

Fix: after 2025.q1.4
Fix from $1,950 2025-08-09
Digital Experience Platform MEDIUM 5.0
CVE-2025-4655

SSRF vulnerability in FreeMarker templates in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through …

Fix: 2024.Q1.16 / 2025.Q1.6+
Fix from $1,600 2025-08-09
Azure Openai CRITICAL 10.0
CVE-2025-53767

Azure OpenAI Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-08-07
Vedo Suite MEDIUM 6.5
CVE-2025-51058

Bottinelli Informatical Vedo Suite 2024.17 is vulnerable to Server-side Request Forgery (SSRF) in the /api_vedo/video/preview endpoint, which allows …

No fix yet
Fix from $1,600 2025-08-06
Exonaut MEDIUM 6.5
CVE-2024-55399

4C Strategies Exonaut before v21.6.2.1-1 was discovered to contain a Server-Side Request Forgery (SSRF).

Fix: 21.6.2.1-1+
Fix from $1,600 2025-08-06
Mccms MEDIUM 6.5
CVE-2025-50234

MCCMS v2.7.0 has an SSRF vulnerability located in the index() method of the sys\apps\controllers\api\Gf.php file, where the pic parameter is processe…

No fix yet
Fix from $1,600 2025-08-06
Unclassified MEDIUM 6.3
CVE-2025-8529

A vulnerability classified as critical was found in cloudfavorites favorites-web up to 1.3.0. Affected by this vulnerability is the function getColle…

Mitigation only
Fix from $1,600 2025-08-04
Xboot HIGH 8.8
CVE-2025-8527

A vulnerability was found in Exrick xboot up to 3.3.4. It has been rated as critical. This issue affects some unknown processing of the file xboot-fa…

Fix: after 3.3.4
Fix from $1,950 2025-08-04
Unclassified MEDIUM 5.0
CVE-2025-8341

Grafana is an open-source platform for monitoring and observability. The Infinity datasource plugin, maintained by Grafana Labs, allows visualizing d…

Mitigation only
Fix from $1,600 2025-08-04
Cursor HIGH 7.5
CVE-2025-54132

Cursor is a code editor built for programming with AI. In versions below 1.3, Mermaid (which is used to render diagrams) allows embedding images whic…

Fix: 1.3+
Fix from $1,950 2025-08-01
Unclassified MEDIUM 6.9
CVE-2025-54590

webfinger.js is a TypeScript-based WebFinger client that runs in both browsers and Node.js environments. In versions 2.8.0 and below, the lookup func…

Patch available
Fix from $1,600 2025-08-01
Glpi MEDIUM 5.0
CVE-2025-52567

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versi…

Fix: 10.0.19+
Fix from $1,600 2025-07-30
Bentoml CRITICAL 9.9
CVE-2025-54381EPSS 12%

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.0 until 1.4.19, the file u…

Fix: 1.4.19+
Fix from $2,300 2025-07-29
Pacs Server HIGH 7.5
CVE-2025-24485EPSS 6%

A server-side request forgery vulnerability exists in the cecho.php functionality of MedDream PACS Premium 7.3.5.860. A specially crafted HTTP reques…

No fix yet
Fix from $1,950 2025-07-28
Ssrf Check MEDIUM 5.3
CVE-2025-8267

Versions of the package ssrfcheck before 1.2.0 are vulnerable to Server-Side Request Forgery (SSRF) due to an incomplete denylist of IP address range…

Fix: 1.2.0+
Fix from $1,600 2025-07-28
Chancms HIGH 8.8
CVE-2025-8228

A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been rated as critical. Affected by this issue is the function getPages of the …

Fix: 3.1.3+
Fix from $1,950 2025-07-27
Tableau Server HIGH 8.2
CVE-2025-52453

Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Data Source modules) allows Resource Location S…

Fix: 2023.3.19 / 2024.2.12+
Fix from $1,950 2025-07-25
Tableau Server HIGH 8.2
CVE-2025-52454

Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Amazon S3 Connector modules) allows Resource Locatio…

Fix: 2023.3.19 / 2024.2.12+
Fix from $1,950 2025-07-25
Tableau Server MEDIUM 5.3
CVE-2025-52455

Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (EPS Server modules) allows Resource Location Spoofin…

Fix: 2023.3.19 / 2024.2.12+
Fix from $1,600 2025-07-25
Golive MEDIUM 6.5
CVE-2025-45939

Apwide Golive 10.2.0 Jira plugin allows Server-Side Request Forgery (SSRF) via the test webhook function.

Mitigation only
Fix from $1,600 2025-07-25
Chancms MEDIUM 6.3
CVE-2025-8133

A vulnerability classified as critical has been found in yanyutao0402 ChanCMS up to 3.1.2. This affects the function getArticle of the file app/modul…

Fix: 3.1.3+
Fix from $1,600 2025-07-25
Unclassified HIGH 8.2
CVE-2025-8020

All versions of the package private-ip are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide an IP or hostname that reso…

Mitigation only
Fix from $1,950 2025-07-23
Unclassified MEDIUM 5.5
CVE-2025-5818

The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, an…

Mitigation only
Fix from $1,600 2025-07-23
Unclassified CRITICAL 10.0
CVE-2025-54122

Manager-io/Manager is accounting software. A critical unauthenticated full read Server-Side Request Forgery (SSRF) vulnerability has been identified …

Mitigation only
Fix from $2,300 2025-07-21
Unclassified CRITICAL 9.1
CVE-2025-52362

Server-Side Request Forgery (SSRF) vulnerability exists in the URL processing functionality of PHProxy version 1.1.1 and prior. The input validation …

Mitigation only
Fix from $2,300 2025-07-21
Urve Web Manager HIGH 8.6
CVE-2025-36845

An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php allows for Server-Side Request Forgery (SSRF). The …

No fix yet
Fix from $1,950 2025-07-21
Unclassified HIGH 8.6
CVE-2025-46385

CWE-918 Server-Side Request Forgery (SSRF)

No fix yet
Fix from $1,950 2025-07-20
Unclassified MEDIUM 6.5
CVE-2025-52163

A Server-Side Request Forgery (SSRF) in the component TunnelServlet of agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 allows attackers to f…

No fix yet
Fix from $1,600 2025-07-18
Xxl Job HIGH 8.8
CVE-2025-7787

A vulnerability, which was classified as critical, was found in Xuxueli xxl-job up to 3.1.1. Affected is the function httpJobHandler of the file src\…

Fix: after 3.1.1
Fix from $1,950 2025-07-18