Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Nextcloud Server MEDIUM 5.3
CVE-2025-47791

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 28.0.13, 29.0.10, and 30.0.3 and Nextcloud Enterprise Server pr…

Fix: 28.0.13 / 29.0.10+
Fix from $1,600 2025-05-16
Jetpack Boost CRITICAL 9.1
CVE-2024-6584

The 'wp_ajax_boost_proxy_ig' action allows administrators to make GET requests to arbitrary URLs.

Fix: 3.4.7+
Fix from $2,300 2025-05-15
Unclassified HIGH 7.2
CVE-2025-40595

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. By using an encoded URL, a remo…

Mitigation only
Fix from $1,950 2025-05-14
Unclassified MEDIUM 5.5
CVE-2024-13940

The Ninja Forms Webhooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.0.7 via the form w…

Mitigation only
Fix from $1,600 2025-05-14
Yifang CRITICAL 9.1
CVE-2025-45887

Yifang CMS v2.0.2 is vulnerable to Server-Side Request Forgery (SSRF) in /api/file/getRemoteContent.

No fix yet
Fix from $2,300 2025-05-09
Power Apps HIGH 7.5
CVE-2025-47733

Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network

Mitigation only
Fix from $1,950 2025-05-08
Azure Storage Resource Provider CRITICAL 9.8
CVE-2025-29972

Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network.

Mitigation only
Fix from $2,300 2025-05-08
Wp Pipes MEDIUM 6.5
CVE-2025-47664

Server-Side Request Forgery (SSRF) vulnerability in ThimPress WP Pipes allows Server Side Request Forgery. This issue affects WP Pipes: from n/a thro…

Fix: after 1.4.3
Fix from $1,600 2025-05-07
Webinarpress CRITICAL 9.8
CVE-2025-47635

Server-Side Request Forgery (SSRF) vulnerability in WPWebinarSystem WebinarPress wp-webinarsystem allows Server Side Request Forgery.This issue affec…

Fix: after 1.33.27
Fix from $2,300 2025-05-07
Activity Link Preview For Buddypress CRITICAL 9.8
CVE-2025-47548

Server-Side Request Forgery (SSRF) vulnerability in Varun Dubey Wbcom Designs - Activity Link Preview For BuddyPress activity-link-preview-for-buddyp…

Fix: after 1.4.4
Fix from $2,300 2025-05-07
Unclassified MEDIUM 6.4
CVE-2025-47484

Server-Side Request Forgery (SSRF) vulnerability in Oliver Campion Display Remote Posts Block display-remote-posts-block allows Server Side Request F…

Mitigation only
Fix from $1,600 2025-05-07
Mrdoc MEDIUM 5.5
CVE-2025-45250

MrDoc v0.95 and before is vulnerable to Server-Side Request Forgery (SSRF) in the validate_url function of the app_doc/utils.py file.

Fix: after 0.95
Fix from $1,600 2025-05-06
Concert MEDIUM 6.5
CVE-2024-55910

IBM Concert Software 1.0.0 through 1.0.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauth…

Fix: 1.1.0+
Fix from $1,600 2025-05-02
Replyone HIGH 7.5
CVE-2024-48907

Sematell ReplyOne 7.4.3.0 allows SSRF via the application server API.

No fix yet
Fix from $1,950 2025-05-01
Stirling Pdf HIGH 7.5
CVE-2025-46568

Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. Prior to version 0.45.0, Stirling-PDF is…

Fix: 0.45.0+
Fix from $1,950 2025-05-01
Gravity Forms Webhooks MEDIUM 5.5
CVE-2024-13845

The Gravity Forms WebHooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.0 via the 'pro…

Fix: 1.7.0+
Fix from $1,600 2025-05-01
Sma1000 Firmware HIGH 7.2
CVE-2025-2170

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface, which in specific conditions co…

Fix: 12.4.3-02925+
Fix from $1,950 2025-04-30
Devexpress CRITICAL 9.8
CVE-2023-35817

DevExpress before 23.1.3 allows AsyncDownloader SSRF.

Fix: 21.2.12+
Fix from $2,300 2025-04-28
Playedu HIGH 7.5
CVE-2025-4012

A vulnerability was found in playeduxyz PlayEdu 开源培训系统 up to 1.8 and classified as problematic. This issue affects some unknown processing of t…

Fix: after 1.8
Fix from $1,950 2025-04-28
Shoplentor MEDIUM 6.5
CVE-2025-3775

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnera…

Fix: 3.1.3+
Fix from $1,600 2025-04-25
Unclassified MEDIUM 6.4
CVE-2025-46511

Server-Side Request Forgery (SSRF) vulnerability in Derek Springer BeerXML Shortcode beerxml-shortcode allows Server Side Request Forgery.This issue …

Mitigation only
Fix from $1,600 2025-04-24
Posthog MEDIUM 6.5
CVE-2025-1521

PostHog slack_incoming_webhook Server-Side Request Forgery Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclo…

Fix: 0.3.7+
Fix from $1,600 2025-04-23
Posthog MEDIUM 6.5
CVE-2025-1522

PostHog database_schema Server-Side Request Forgery Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sens…

Fix: 0.3.7+
Fix from $1,600 2025-04-23
Maximo Asset Management MEDIUM 5.4
CVE-2025-2987

IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorize…

Mitigation only
Fix from $1,600 2025-04-22
Crawl4ai CRITICAL 9.1
CVE-2025-28197

Crawl4AI <=0.4.247 is vulnerable to SSRF in /crawl4ai/async_dispatcher.py.

Fix: after 0.4.247
Fix from $2,300 2025-04-18
Pbootcms MEDIUM 6.5
CVE-2025-3787

A vulnerability was found in PbootCMS 3.2.5. It has been classified as problematic. Affected is an unknown function of the component Image Handler. T…

No fix yet
Fix from $1,600 2025-04-18
Personal Management System MEDIUM 6.5
CVE-2025-29456

An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the create Note…

No fix yet
Fix from $1,600 2025-04-17
Mybb HIGH 7.6
CVE-2025-29457

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Import a Theme function. NOTE: the Supplier disputes this be…

No fix yet
Fix from $1,950 2025-04-17
Mybb HIGH 7.6
CVE-2025-29458

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Change Avatar function. NOTE: the Supplier disputes this bec…

No fix yet
Fix from $1,950 2025-04-17
Mybb HIGH 7.6
CVE-2025-29459

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Mail function. NOTE: the Supplier disputes this because of t…

No fix yet
Fix from $1,950 2025-04-17