Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Mobile Security Framework CRITICAL 9.8
CVE-2025-31116

Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analy…

Fix: 4.3.2+
Fix from $2,300 2025-03-31
Openemr HIGH 7.5
CVE-2025-31117

OpenEMR is a free and open source electronic health records and medical practice management application. An Out-of-Band Server-Side Request Forgery (…

Fix: 7.0.3.1+
Fix from $1,950 2025-03-31
Youkefu HIGH 8.8
CVE-2025-2997

A vulnerability was found in zhangyanbo2007 youkefu 4.2.0. It has been classified as critical. Affected is an unknown function of the file /res/url. …

No fix yet
Fix from $1,950 2025-03-31
Unclassified MEDIUM 6.4
CVE-2025-31527

Server-Side Request Forgery (SSRF) vulnerability in Kishan WP Link Preview wp-link-preview allows Server Side Request Forgery.This issue affects WP L…

Mitigation only
Fix from $1,600 2025-03-31
Maccms CRITICAL 9.1
CVE-2025-28091

maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.

No fix yet
Fix from $2,300 2025-03-28
Shopxo MEDIUM 6.3
CVE-2025-28092

ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function.

No fix yet
Fix from $1,600 2025-03-28
Shopxo MEDIUM 6.3
CVE-2025-28093

ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) in Email Settings.

No fix yet
Fix from $1,600 2025-03-28
Shopxo MEDIUM 6.5
CVE-2025-28094

shopxo v6.4.0 has a ssrf/xss vulnerability in multiple places.

No fix yet
Fix from $1,600 2025-03-28
Onenav MEDIUM 5.4
CVE-2025-28096

OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers.

No fix yet
Fix from $1,600 2025-03-28
Maccms CRITICAL 9.1
CVE-2025-28089

maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.

No fix yet
Fix from $2,300 2025-03-28
Maccms CRITICAL 9.1
CVE-2025-28090

maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature.

No fix yet
Fix from $2,300 2025-03-28
Kylin MEDIUM 6.5
CVE-2024-48944

Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. Through a kylin server, an attacker may forge a request to invoke "/kylin/api/xxx/d…

Fix: 5.0.2+
Fix from $1,600 2025-03-27
Unclassified HIGH 7.6
CVE-2025-27406

Icinga Reporting is the central component for reporting related functionality in the monitoring web frontend and framework Icinga Web 2. A vulnerabil…

Mitigation only
Fix from $1,950 2025-03-26
Product Import Export For Woocommerce HIGH 7.6
CVE-2025-1912

The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Server-Side Request Forgery in all …

Fix: 2.5.1+
Fix from $1,950 2025-03-26
Unclassified MEDIUM 6.4
CVE-2024-13411

The Zapier for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.5.1 via the update…

Mitigation only
Fix from $1,600 2025-03-26
Wp Compress MEDIUM 5.8
CVE-2025-2109

The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, a…

Fix: 6.30.16+
Fix from $1,600 2025-03-25
Unclassified MEDIUM 6.9
CVE-2024-10206

A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an unauthenticated network-based attacker t…

Mitigation only
Fix from $1,600 2025-03-25
Unclassified MEDIUM 5.3
CVE-2024-10207

A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an authenticated network-based attacker to …

Mitigation only
Fix from $1,600 2025-03-25
Nossrf CRITICAL 9.1
CVE-2025-2691

Versions of the package nossrf before 1.0.4 are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide a hostname that resolv…

Fix: 1.0.4+
Fix from $2,300 2025-03-23
Import Export Wordpress Users HIGH 7.6
CVE-2025-1970

The Export and Import Users and Customers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6…

Fix: 2.6.3+
Fix from $1,950 2025-03-22
Unclassified MEDIUM 6.4
CVE-2024-13856

The Your Friendly Drag and Drop Page Builder — Make Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, …

Mitigation only
Fix from $1,600 2025-03-22
Spirateam CRITICAL 9.8
CVE-2024-48590

Inflectra SpiraTeam 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) via the NewsReaderService. This allows an attacker to escalate privile…

Mitigation only
Fix from $2,300 2025-03-20
Druid MEDIUM 5.4
CVE-2025-27888

Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scri…

Fix: 31.0.2+
Fix from $1,600 2025-03-20
Order Export \& Order Import For Woocommerce MEDIUM 6.5
CVE-2024-13923

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin…

Fix: 2.6.1+
Fix from $1,600 2025-03-20
Autogpt Platform HIGH 7.5
CVE-2025-0454

A Server-Side Request Forgery (SSRF) vulnerability was identified in the Requests utility of significant-gravitas/autogpt versions prior to v0.4.0. T…

Fix: 0.4.0+
Fix from $1,950 2025-03-20
Dify MEDIUM 6.5
CVE-2025-0184

A Server-Side Request Forgery (SSRF) vulnerability was identified in langgenius/dify version 0.10.2. The vulnerability occurs in the 'Create Knowledg…

Fix: 0.11.0+
Fix from $1,600 2025-03-20
Chuanhuchatgpt MEDIUM 6.5
CVE-2025-0188

A Server-Side Request Forgery (SSRF) vulnerability was discovered in gaizhenbiao/chuanhuchatgpt version 20240914. The vulnerability allows an attacke…

No fix yet
Fix from $1,600 2025-03-20
Llava CRITICAL 9.3
CVE-2024-9309

A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Controller API Server in haotian-li…

No fix yet
Fix from $2,300 2025-03-20
Composio HIGH 7.5
CVE-2024-8955

A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.4. This vulnerability allows an attacker to read the co…

No fix yet
Fix from $1,950 2025-03-20
Composio HIGH 7.5
CVE-2024-8952

A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.2, specifically in the /api/actions/execute/WEBTOOL_SCR…

No fix yet
Fix from $1,950 2025-03-20