Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Mybb HIGH 7.6
CVE-2025-29460

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Add Mycode function. NOTE: the Supplier disputes this becaus…

Mitigation only
Fix from $1,950 2025-04-17
A Blogcms HIGH 7.6
CVE-2025-29461

An issue in a-blogcms 3.1.15 allows a remote attacker to obtain sensitive information via the /bid/1/admin/entry-edit/ path.

No fix yet
Fix from $1,950 2025-04-17
Personal Management System MEDIUM 6.5
CVE-2025-29453

An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the my-contacts…

No fix yet
Fix from $1,600 2025-04-17
Twonav MEDIUM 6.5
CVE-2025-29449

An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the link identification function.

No fix yet
Fix from $1,600 2025-04-17
Twonav MEDIUM 6.5
CVE-2025-29450

An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the site settings component.

No fix yet
Fix from $1,600 2025-04-17
Seo Panel HIGH 7.6
CVE-2025-29451

An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Mail Setting component.

No fix yet
Fix from $1,950 2025-04-17
Seo Panel HIGH 7.6
CVE-2025-29452

An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Proxy Manager component.

No fix yet
Fix from $1,950 2025-04-17
Personal Management System MEDIUM 6.5
CVE-2025-29454

An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Upload func…

No fix yet
Fix from $1,600 2025-04-17
Personal Management System MEDIUM 6.5
CVE-2025-29455

An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Travel Idea…

No fix yet
Fix from $1,600 2025-04-17
Hertzbeat MEDIUM 6.5
CVE-2024-56736

Server-Side Request Forgery (SSRF) vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat (incubating): before 1.7.0. Users are rec…

Fix: 1.7.0+
Fix from $1,600 2025-04-16
Seven Bears Library Cms MEDIUM 5.3
CVE-2025-3691

A vulnerability was found in mirweiye Seven Bears Library CMS 2023. It has been classified as problematic. Affected is an unknown function of the com…

Fix: 2023+
Fix from $1,600 2025-04-16
Crushftp MEDIUM 5.0
CVE-2025-32102EPSS 8%

CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=telnetSocket request to the /W…

Fix: after 11.3.1
Fix from $1,600 2025-04-15
Unclassified MEDIUM 5.4
CVE-2025-30964

Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods Photography photography allows Server Side Request Forgery.This issue affects Photogra…

Mitigation only
Fix from $1,600 2025-04-15
Autogpt Platform HIGH 7.5
CVE-2025-31490

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prio…

Fix: 0.6.1+
Fix from $1,950 2025-04-14
Smartrobot HIGH 7.5
CVE-2025-3572

SmartRobot from INTUMIT has a Server-Side Request Forgery vulnerability, allowing unauthenticated remote attackers to probe internal network and even…

Fix: 8.0.0+
Fix from $1,950 2025-04-14
Unclassified MEDIUM 6.0
CVE-2025-22374

A Server-Side Request Forgery (SSRF) vulnerability was discovered in the videx-legacy-ssl web service of Videx’s CyberAudit-Web, affecting versions p…

Mitigation only
Fix from $1,600 2025-04-10
Octopus Server HIGH 8.8
CVE-2025-0539

In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests that contain authentication mat…

Fix: 2024.3.13071 / 2024.4.7065+
Fix from $1,950 2025-04-10
Unclassified MEDIUM 6.8
CVE-2025-32675

Server-Side Request Forgery (SSRF) vulnerability in QuantumCloud SEO Help seo-help allows Server Side Request Forgery.This issue affects SEO Help: fr…

Mitigation only
Fix from $1,600 2025-04-09
Unclassified MEDIUM 5.4
CVE-2025-31009

Server-Side Request Forgery (SSRF) vulnerability in Jan Boddez IndieBlocks indieblocks allows Server Side Request Forgery.This issue affects IndieBlo…

Mitigation only
Fix from $1,600 2025-04-09
Dotnetnuke HIGH 7.5
CVE-2025-32372

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. A bypass has been identified for the pr…

Fix: 9.13.8+
Fix from $1,950 2025-04-09
Aias MEDIUM 6.3
CVE-2025-3412

A vulnerability, which was classified as critical, was found in mymagicpower AIAS 20250308. Affected is an unknown function of the file 2_training_pl…

No fix yet
Fix from $1,600 2025-04-08
Aias MEDIUM 6.3
CVE-2025-3411

A vulnerability, which was classified as critical, has been found in mymagicpower AIAS 20250308. This issue affects some unknown processing of the fi…

No fix yet
Fix from $1,600 2025-04-08
Lnbits HIGH 7.5
CVE-2025-32013

LNbits is a Lightning wallet and accounts system. A Server-Side Request Forgery (SSRF) vulnerability has been discovered in LNbits' LNURL authenticat…

Fix: 0.12.12+
Fix from $1,950 2025-04-06
Admintwo CRITICAL 9.8
CVE-2025-3254

A vulnerability was found in xujiangfei admintwo 1.0. It has been classified as critical. Affected is an unknown function of the file /resource/add. …

No fix yet
Fix from $2,300 2025-04-04
Gravityzone HIGH 7.3
CVE-2025-2243

A server-side request forgery (SSRF) vulnerability in Bitdefender GravityZone Console allows an attacker to bypass input validation logic using leadi…

Fix: 6.41.2-1+
Fix from $1,950 2025-04-04
Gravityzone Update Server MEDIUM 5.3
CVE-2025-2245

A server-side request forgery (SSRF) vulnerability exists in the Bitdefender GravityZone Update Server when operating in Relay Mode. The HTTP proxy c…

Fix: 3.5.2.689+
Fix from $1,600 2025-04-04
Unclassified HIGH 8.2
CVE-2025-3192

Versions of the package spatie/browsershot from 0.0.0 are vulnerable to Server-side Request Forgery (SSRF) in the setUrl() function due to a missing …

Mitigation only
Fix from $1,950 2025-04-04
Unclassified MEDIUM 5.4
CVE-2025-31824

Server-Side Request Forgery (SSRF) vulnerability in Wombat Plugins WP Optin Wheel wp-optin-wheel allows Server Side Request Forgery.This issue affect…

Mitigation only
Fix from $1,600 2025-04-01
Unclassified MEDIUM 5.4
CVE-2025-31796

Server-Side Request Forgery (SSRF) vulnerability in TheInnovs ElementsCSS Addons for Elementor css-for-elementor allows Server Side Request Forgery.T…

Mitigation only
Fix from $1,600 2025-04-01
Azure Health Bot HIGH 8.8
CVE-2025-21384

An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a …

Mitigation only
Fix from $1,950 2025-04-01