Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Unclassified MEDIUM 6.4
CVE-2025-52713

Server-Side Request Forgery (SSRF) vulnerability in BoldGrid Post and Page Builder by BoldGrid post-and-page-builder allows Server Side Request Forge…

Mitigation only
Fix from $1,600 2025-06-20
Unclassified HIGH 7.2
CVE-2025-23172

The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints. However, the "Add W…

Mitigation only
Fix from $1,950 2025-06-19
Apex Central HIGH 7.5
CVE-2025-30678

A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modTMSM component could allow an attacker to manipulate c…

Mitigation only
Fix from $1,950 2025-06-17
Apex Central HIGH 7.5
CVE-2025-30679

A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modOSCE component could allow an attacker to manipulate c…

Mitigation only
Fix from $1,950 2025-06-17
Apex Central HIGH 7.1
CVE-2025-30680

A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (SaaS) could allow an attacker to manipulate certain parameters leadin…

Fix: 2025-03-01+
Fix from $1,950 2025-06-17
Unclassified MEDIUM 6.3
CVE-2025-6142

A vulnerability was found in Intera InHire up to 20250530. It has been declared as critical. Affected by this vulnerability is an unknown functionali…

Mitigation only
Fix from $1,600 2025-06-16
Create Cloudflare CRITICAL 9.1
CVE-2025-6087

A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package. The vulnerability stems from an unimplemente…

Fix: 1.3.0 / 2.49.3+
Fix from $2,300 2025-06-16
Field Analytics MEDIUM 5.8
CVE-2025-49190

The application is vulnerable to Server-Side Request Forgery (SSRF). An endpoint can be used to send server internal requests to other ports.

Mitigation only
Fix from $1,600 2025-06-12
Unclassified MEDIUM 5.4
CVE-2025-44043

Keyoti SearchUnit prior to 9.0.0. is vulnerable to Server-Side Request Forgery (SSRF) in /Keyoti_SearchEngine_Web_Common/SearchService.svc/GetResults…

Mitigation only
Fix from $1,600 2025-06-10
Geotools CRITICAL 9.1
CVE-2025-30220EPSS 57%

GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent…

Fix: 2.25.7 / 2.26.3+
Fix from $2,300 2025-06-10
Geoserver HIGH 8.2
CVE-2024-29198

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. It possible to achieve Service Side …

Fix: 2.24.4 / 2.25.2+
Fix from $1,950 2025-06-10
Geoserver HIGH 8.2
CVE-2024-34711

GeoServer is an open source server that allows users to share and edit geospatial data. An improper URI validation vulnerability exists that enables …

Fix: 2.25.0+
Fix from $1,950 2025-06-10
Kafka HIGH 7.5
CVE-2025-27817EPSS 65%

A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients accept configuration data for …

Fix: 3.9.1+
Fix from $1,950 2025-06-10
Businessobjects Business Intelligence Platform MEDIUM 5.3
CVE-2025-42988

Under certain conditions, SAP Business Objects Business Intelligence Platform allows an unauthenticated attacker to enumerate HTTP endpoints in the i…

Patch available
Fix from $1,600 2025-06-10
Unclassified MEDIUM 5.4
CVE-2025-30997

Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Car Repair Services car-repair-services allows Server Side Request Forgery.This iss…

Mitigation only
Fix from $1,600 2025-06-06
Freshrss HIGH 7.1
CVE-2025-46341

FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, when the server is using HTTP auth via reverse proxy, it's possible to impers…

Fix: 1.26.2+
Fix from $1,950 2025-06-04
Shiyi Blog CRITICAL 9.8
CVE-2025-5510

A vulnerability classified as critical was found in quequnlong shiyi-blog up to 1.2.1. This vulnerability affects unknown code of the file /app/sys/a…

Fix: after 1.2.1
Fix from $2,300 2025-06-03
Identity Server MEDIUM 6.5
CVE-2024-7073

A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in SOAP admin services. This fla…

Mitigation only
Fix from $1,600 2025-06-02
Storeonce System CRITICAL 9.8
CVE-2025-37090

A server-side request forgery vulnerability exists in HPE StoreOnce Software.

Fix: 4.3.11+
Fix from $2,300 2025-06-02
Mccms HIGH 8.8
CVE-2025-5327

A vulnerability was found in chshcms mccms 2.7. It has been classified as critical. This affects the function index of the file sys/apps/controllers/…

No fix yet
Fix from $1,950 2025-05-29
Portal For Arcgis CRITICAL 9.1
CVE-2025-4967

Esri Portal for ArcGIS 11.4 and prior allows a remote, unauthenticated attacker to bypass the Portal’s SSRF protections.

Fix: after 11.4
Fix from $2,300 2025-05-29
Maccms HIGH 7.3
CVE-2025-45474

maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings.

No fix yet
Fix from $1,950 2025-05-29
Strapi HIGH 7.5
CVE-2024-52588

Strapi is an open-source content management system. Prior to version 4.25.2, inputting a local domain into the Webhooks URL field leads to the applic…

Fix: 4.25.2+
Fix from $1,950 2025-05-29
Unclassified HIGH 7.4
CVE-2025-5276

Versions of the package mcp-markdownify-server before 1.0.0 are vulnerable to Server-Side Request Forgery (SSRF) via the Markdownify.get() function. …

Patch available
Fix from $1,950 2025-05-29
Maccms MEDIUM 5.4
CVE-2025-45475

maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management.

No fix yet
Fix from $1,600 2025-05-27
Unclassified HIGH 8.2
CVE-2025-48383

Django-Select2 is a Django integration for Select2. Prior to version 8.4.1, instances of HeavySelect2Mixin subclasses like the ModelSelect2MultipleWi…

Patch available
Fix from $1,950 2025-05-27
Jeesite HIGH 8.8
CVE-2025-5186

A vulnerability was found in thinkgem JeeSite up to 5.11.1. It has been rated as critical. Affected by this issue is the function ResourceLoader.getR…

Fix: after 5.11.1
Fix from $1,950 2025-05-26
Unclassified MEDIUM 6.3
CVE-2025-5140

A vulnerability classified as critical has been found in Seeyon Zhiyuan OA Web Application System up to 8.1 SP2. This affects the function this.oursN…

Mitigation only
Fix from $1,600 2025-05-25
Unclassified HIGH 7.6
CVE-2024-13957

SSRF Server Side Request Forgery vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise:…

Mitigation only
Fix from $1,950 2025-05-22
A Blog Cms HIGH 7.5
CVE-2025-36560

Server-side request forgery vulnerability exists in a-blog cms multiple versions. If this vulnerability is exploited, a remote unauthenticated attack…

Fix: after 3.1.43
Fix from $1,950 2025-05-19