Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Unclassified HIGH 8.3
CVE-2024-8099

A Server-Side Request Forgery (SSRF) vulnerability exists in the latest version of vanna-ai/vanna when using DuckDB as the database. An attacker can …

Mitigation only
Fix from $1,950 2025-03-20
Open Webui HIGH 7.7
CVE-2024-7959

The `/openai/models` endpoint in open-webui/open-webui version 0.3.8 is vulnerable to Server-Side Request Forgery (SSRF). An attacker can change the …

No fix yet
Fix from $1,950 2025-03-20
Comfyui HIGH 7.5
CVE-2024-12882

comfyanonymous/comfyui version v0.2.4 suffers from a non-blind Server-Side Request Forgery (SSRF) vulnerability. This vulnerability can be exploited …

No fix yet
Fix from $1,950 2025-03-20
Lollms Web Ui HIGH 7.5
CVE-2024-12766

parisneo/lollms-webui version V13 (feather) suffers from a Server-Side Request Forgery (SSRF) vulnerability in the `POST /api/proxy` REST API. Attack…

No fix yet
Fix from $1,950 2025-03-20
Dify MEDIUM 6.5
CVE-2024-12775

langgenius/dify version 0.10.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the test functionality for the Create Custom Tool optio…

No fix yet
Fix from $1,600 2025-03-20
Ragflow HIGH 7.5
CVE-2024-12779

A Server-Side Request Forgery (SSRF) vulnerability exists in infiniflow/ragflow version 0.12.0. The vulnerability is present in the `POST /v1/llm/add…

No fix yet
Fix from $1,950 2025-03-20
Gpt Academic MEDIUM 6.5
CVE-2024-12392

A Server-Side Request Forgery (SSRF) vulnerability exists in binary-husky/gpt_academic version git 310122f. The application has a functionality to do…

No fix yet
Fix from $1,600 2025-03-20
Ragflow CRITICAL 9.8
CVE-2024-12450

In infiniflow/ragflow versions 0.12.0, the `web_crawl` function in `document_app.py` contains multiple vulnerabilities. The function does not filter …

Patch available
Fix from $2,300 2025-03-20
Llava HIGH 7.5
CVE-2024-12068

A Server-Side Request Forgery (SSRF) vulnerability was discovered in haotian-liu/llava, affecting version git c121f04. This vulnerability allows an a…

No fix yet
Fix from $1,950 2025-03-20
Fastchat HIGH 7.5
CVE-2024-12376

A Server-Side Request Forgery (SSRF) vulnerability was identified in the lm-sys/fastchat web server, specifically in the affected version git 2c68a13…

No fix yet
Fix from $1,950 2025-03-20
Large Language And Vision Assistant HIGH 7.5
CVE-2024-11449

A vulnerability in haotian-liu/llava version 1.2.0 (LLaVA-1.6) allows for Server-Side Request Forgery (SSRF) through the /run/predict endpoint. An at…

No fix yet
Fix from $1,950 2025-03-20
Fastchat HIGH 7.5
CVE-2024-11603

A Server-Side Request Forgery (SSRF) vulnerability exists in lm-sys/fastchat version 0.2.36. The vulnerability is present in the `/queue/join?` endpo…

No fix yet
Fix from $1,950 2025-03-20
Dify HIGH 7.5
CVE-2024-11822

langgenius/dify version 0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability. The vulnerability exists due to improper handling of the a…

No fix yet
Fix from $1,950 2025-03-20
Gpt Academic HIGH 7.5
CVE-2024-11030

GPT Academic version 3.83 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability through its HotReload plugin function, which calls the …

No fix yet
Fix from $1,950 2025-03-20
Gpt Academic HIGH 7.5
CVE-2024-11031

In version 3.83 of binary-husky/gpt_academic, a Server-Side Request Forgery (SSRF) vulnerability exists in the Markdown_Translate.get_files_from_ever…

No fix yet
Fix from $1,950 2025-03-20
Unclassified MEDIUM 6.5
CVE-2024-10457

Multiple Server-Side Request Forgery (SSRF) vulnerabilities were identified in the significant-gravitas/autogpt repository, specifically in the GitHu…

Patch available
Fix from $1,600 2025-03-20
Applio MEDIUM 5.3
CVE-2025-27774

Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) and file write in `model_download.py…

Fix: after 3.2.7
Fix from $1,600 2025-03-19
Applio MEDIUM 5.3
CVE-2025-27775

Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) and file write in `model_download.py…

Fix: after 3.2.7
Fix from $1,600 2025-03-19
Applio MEDIUM 5.3
CVE-2025-27776

Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) and file write in `model_download.py…

Fix: after 3.2.7
Fix from $1,600 2025-03-19
Applio HIGH 7.5
CVE-2025-27777

Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) in `model_download.py` (line 195 in …

Fix: after 3.2.7
Fix from $1,950 2025-03-19
Smartfabric Os10 MEDIUM 6.8
CVE-2025-22474

Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) a Server-Side Request Forgery (SSRF) vulnerability. A h…

Fix: 10.5.4.14 / 10.5.5.13+
Fix from $1,600 2025-03-17
Autogpt Platform HIGH 8.1
CVE-2025-22603

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Vers…

Fix: 0.4.2+
Fix from $1,950 2025-03-10
Starter Templates CRITICAL 9.1
CVE-2024-13924

The Starter Templates by FancyWP plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.0.0 …

Fix: after 2.0.0
Fix from $2,300 2025-03-08
Axios MEDIUM 5.3
CVE-2025-27152

axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to a…

Fix: 0.30.0+
Fix from $1,600 2025-03-07
Unclassified MEDIUM 5.5
CVE-2024-13857

The WPGet API – Connect to any external REST API plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includi…

Mitigation only
Fix from $1,600 2025-03-07
Platform.ly For Woocommerce CRITICAL 9.1
CVE-2024-13904

The Platform.ly for WooCommerce plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.1.6 v…

Fix: 1.1.7+
Fix from $2,300 2025-03-07
Fastgpt MEDIUM 6.5
CVE-2025-27600

FastGPT is a knowledge-based platform built on the LLMs. Since the web crawling plug-in does not perform intranet IP verification, an attacker can in…

Fix: 4.9.0+
Fix from $1,600 2025-03-06
Vasion Print CRITICAL 9.8
CVE-2025-27652

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Server-Side Request Forgery: rfIDEAS V-2023-…

Fix: 20.0.2014 / 22.0.862+
Fix from $2,300 2025-03-05
Vasion Print CRITICAL 9.8
CVE-2025-27655

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Server-Side Request Forgery: CPA v1 V-2023-0…

Fix: 20.0.2014 / 22.0.862+
Fix from $2,300 2025-03-05
Vasion Print CRITICAL 9.8
CVE-2025-27651

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Server-Side Request Forgery: Elatec V-2023-0…

Fix: 20.0.2014 / 22.0.862+
Fix from $2,300 2025-03-05