Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Jeesite HIGH 8.8
CVE-2025-7759

A vulnerability was identified in thinkgem JeeSite up to 5.12.0. This vulnerability affects unknown code of the file modules/core/src/main/java/com/j…

Fix: 5.12.1+
Fix from $1,950 2025-07-17
Unified Intelligence Center MEDIUM 5.3
CVE-2025-20288

A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct…

Mitigation only
Fix from $1,600 2025-07-16
Glassfish CRITICAL 9.8
CVE-2024-9408

In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints.

Mitigation only
Fix from $2,300 2025-07-16
PHP MEDIUM 5.3
CVE-2025-1220

In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation th…

Fix: 8.1.33 / 8.2.29+
Fix from $1,600 2025-07-13
Unclassified HIGH 8.2
CVE-2025-53641

Postiz is an AI social media scheduling tool. From 1.45.1 to 1.62.3, the Postiz frontend application allows an attacker to inject arbitrary HTTP head…

Patch available
Fix from $1,950 2025-07-11
Unclassified MEDIUM 6.3
CVE-2025-50125

A CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthenticated remote code execution when the server is acces…

Mitigation only
Fix from $1,600 2025-07-11
Broken Link Notifier MEDIUM 6.5
CVE-2025-6851

The Broken Link Notifier plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3.0 via the ajax_b…

Fix: 1.3.1+
Fix from $1,600 2025-07-11
Unclassified CRITICAL 9.1
CVE-2025-53371

DiscordNotifications is an extension for MediaWiki that sends notifications of actions in your Wiki to a Discord channel. DiscordNotifications allows…

Patch available
Fix from $2,300 2025-07-10
HTTP Server HIGH 7.5
CVE-2024-43394

Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via  mod_rewrite or …

Fix: 2.4.64+
Fix from $1,950 2025-07-10
HTTP Server HIGH 7.5
CVE-2024-43204

SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker.  Requires an…

Fix: 2.4.64+
Fix from $1,950 2025-07-10
Coldfusion MEDIUM 6.2
CVE-2025-49545

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitr…

Mitigation only
Fix from $1,600 2025-07-08
Unclassified HIGH 7.3
CVE-2025-53473

Server-side request forgery (SSRF) vulnerability exists n multiple versions of Nimesa Backup and Recovery, If this vulnerability is exploited, uninte…

Mitigation only
Fix from $1,950 2025-07-07
Boyuncms HIGH 7.5
CVE-2025-7103

A vulnerability was found in BoyunCMS up to 1.4.20. It has been rated as critical. This issue affects some unknown processing of the file /applicatio…

Fix: after 1.4.20
Fix from $1,950 2025-07-07
Unclassified HIGH 7.2
CVE-2025-49418

Server-Side Request Forgery (SSRF) vulnerability in TeconceTheme Allmart allmart-core allows Server Side Request Forgery.This issue affects Allmart: …

Mitigation only
Fix from $1,950 2025-07-04
Unclassified MEDIUM 5.4
CVE-2025-28963

Server-Side Request Forgery (SSRF) vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Server Side Request Forgery.This issue affec…

Mitigation only
Fix from $1,600 2025-07-04
Paymaster For Woocommerce MEDIUM 6.4
CVE-2025-6729

The PayMaster for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 0.4.31 via the …

Fix: after 0.4.31
Fix from $1,600 2025-07-04
Amazon Products To Woocommerce HIGH 7.2
CVE-2025-5817

The Amazon Products to WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2.7 via …

Fix: after 1.2.7
Fix from $1,950 2025-07-02
Unclassified MEDIUM 6.9
CVE-2025-34051

A server-side request forgery vulnerability exists in multiple firmware versions of AVTECH DVR devices that exposes the /cgi-bin/nobody/Search.cgi?ac…

No fix yet
Fix from $1,600 2025-07-01
Zrlog CRITICAL 9.8
CVE-2025-45872

zrlog v3.1.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the downloadUrl parameter.

Mitigation only
Fix from $2,300 2025-07-01
Unclassified MEDIUM 5.8
CVE-2025-52491

Akamai CloudTest before 60 2025.06.09 (12989) allows SSRF.

Mitigation only
Fix from $1,600 2025-06-30
Bbs HIGH 7.2
CVE-2025-6762

A vulnerability classified as critical has been found in diyhi bbs up to 6.8. This affects the function getUrl of the file /admin/login of the compon…

Fix: after 6.8
Fix from $1,950 2025-06-27
Ninja Tables HIGH 7.2
CVE-2025-2940

The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.…

Fix: 5.0.19+
Fix from $1,950 2025-06-27
Unclassified HIGH 8.6
CVE-2025-52477

Octo-STS is a GitHub App that acts like a Security Token Service (STS) for the GitHub API. Octo-STS versions before v0.5.3 are vulnerable to unauthen…

Patch available
Fix from $1,950 2025-06-26
Unclassified MEDIUM 5.3
CVE-2024-51981

An unauthenticated attacker may perform a blind server side request forgery (SSRF), due to a CLRF injection issue that can be leveraged to perform HT…

Mitigation only
Fix from $1,600 2025-06-25
Unclassified MEDIUM 5.3
CVE-2024-51980

An unauthenticated attacker may perform a limited server side request forgery (SSRF), forcing the target device to open a TCP connection to an arbitr…

Mitigation only
Fix from $1,600 2025-06-25
Control Id Idsecure HIGH 7.5
CVE-2025-49852

ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to a server-side request forgery vulnerability which could allow an unauthe…

Fix: 4.7.50.0+
Fix from $1,950 2025-06-24
Langchain CRITICAL 10.0
CVE-2025-2828EPSS 16%

A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community package (specifically, langchai…

Fix: 0.0.28+
Fix from $2,300 2025-06-23
Maxkey CRITICAL 9.8
CVE-2025-6517

A vulnerability was found in Dromara MaxKey up to 4.1.7 and classified as critical. This issue affects the function Add of the file maxkey-webs\maxke…

Fix: after 4.1.7
Fix from $2,300 2025-06-23
Unclassified MEDIUM 5.8
CVE-2025-52967

gateway_proxy_handler in MLflow before 3.1.0 lacks gateway_path validation.

Patch available
Fix from $1,600 2025-06-23
Unclassified HIGH 7.8
CVE-2025-34021

A server-side request forgery (SSRF) vulnerability exists in multiple Selea Targa IP OCR-ANPR camera models, including iZero, Targa 512, Targa 504, T…

No fix yet
Fix from $1,950 2025-06-20