Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Openziti HIGH 8.6
CVE-2025-27501

OpenZiti is a free and open source project focused on bringing zero trust to any application. An endpoint on the admin panel can be accessed without …

Fix: 3.7.1+
Fix from $1,950 2025-03-03
Unclassified MEDIUM 6.9
CVE-2025-25303

The MouseTooltipTranslator Chrome extension allows mouseover translation of any language at once. The MouseTooltipTranslator browser extension is vul…

Mitigation only
Fix from $1,600 2025-03-03
Rembg HIGH 7.5
CVE-2025-25301

Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the /api/remove endpoint takes a URL query parameter that allows an image t…

Fix: after 2.0.57
Fix from $1,950 2025-03-03
Zz HIGH 8.8
CVE-2025-1848

A vulnerability classified as critical has been found in zj1983 zz up to 2024-8. Affected is an unknown function of the file /import_data_check. The …

Fix: after 2024-8
Fix from $1,950 2025-03-03
Zz HIGH 8.8
CVE-2025-1849

A vulnerability classified as critical was found in zj1983 zz up to 2024-8. Affected by this vulnerability is an unknown functionality of the file /i…

Fix: 2024-8+
Fix from $1,950 2025-03-03
Zz HIGH 8.8
CVE-2025-1833

A vulnerability, which was classified as critical, has been found in zj1983 zz up to 2024-8. Affected by this issue is the function sendNotice of the…

Fix: 2024-8+
Fix from $1,950 2025-03-02
Skycaiji MEDIUM 6.3
CVE-2025-1799

A vulnerability, which was classified as critical, was found in Zorlan SkyCaiji 2.9. This affects the function previewAction of the file vendor/skyca…

Mitigation only
Fix from $1,600 2025-03-01
Better Messages MEDIUM 6.5
CVE-2024-13697

The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Server-Side Reque…

Fix: 2.7.5+
Fix from $1,600 2025-03-01
Url Media Uploader MEDIUM 6.4
CVE-2025-1662

The URL Media Uploader plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.0 via the 'url_med…

Fix: after 1.0.1
Fix from $1,600 2025-02-28
Memos CRITICAL 9.8
CVE-2025-22952

elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploite…

Patch available
Fix from $2,300 2025-02-27
Sucms HIGH 7.5
CVE-2025-25760

A Server-Side Request Forgery (SSRF) in the component admin_webgather.php of SUCMS v1.0 allows attackers to access internal data and services via a c…

Mitigation only
Fix from $1,950 2025-02-27
Total Upkeep MEDIUM 6.5
CVE-2024-13907

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Server-Side Request Forgery in al…

Fix: 1.16.9+
Fix from $1,600 2025-02-27
Onestore Sites CRITICAL 9.1
CVE-2024-13905

The OneStore Sites plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 0.1.1 via the class-export…

Fix: after 0.1.1
Fix from $2,300 2025-02-27
Emlog MEDIUM 6.8
CVE-2025-25827

A Server-Side Request Forgery (SSRF) in the component sort.php of Emlog Pro v2.5.4 allows attackers to scan local and internal ports via supplying a …

Mitigation only
Fix from $1,600 2025-02-26
Jizhicms CRITICAL 9.1
CVE-2025-25785

JizhiCMS v2.5.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component \c\PluginsController.php. This vulnerability allows …

Mitigation only
Fix from $2,300 2025-02-26
Dryice Mycloud CRITICAL 9.1
CVE-2024-30150

HCL MyCloud is affected by Improper Access Control - an unauthenticated privilege escalation vulnerability which may lead to information disclosure a…

Mitigation only
Fix from $2,300 2025-02-25
Enfold MEDIUM 5.4
CVE-2024-13695

The Enfold theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.9 via the 'attachment_id' param…

Fix: 7.0.0+
Fix from $1,600 2025-02-25
Unclassified MEDIUM 6.4
CVE-2025-1043

The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Server-Side Request Forgery in all version…

Mitigation only
Fix from $1,600 2025-02-20
Unclassified HIGH 8.6
CVE-2024-37359

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensu…

Mitigation only
Fix from $1,950 2025-02-19
Sliver MEDIUM 5.3
CVE-2025-27090

Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security test…

Fix: 1.5.43+
Fix from $1,600 2025-02-19
Profilegrid MEDIUM 5.4
CVE-2024-13741

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up …

Fix: 5.9.4.3+
Fix from $1,600 2025-02-18
Unclassified HIGH 7.2
CVE-2025-20075

Server-side request forgery (SSRF) vulnerability exists in FileMegane versions above 3.0.0.0 prior to 3.4.0.0. Executing arbitrary backend Web API re…

Mitigation only
Fix from $1,950 2025-02-18
Unclassified MEDIUM 5.5
CVE-2024-13879

The Stream plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.2 due to insufficient validati…

Mitigation only
Fix from $1,600 2025-02-17
Responsive Addons MEDIUM 5.4
CVE-2024-13834

The Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme plugin for WordPress is vulnerable to Server-…

Fix: 3.1.5+
Fix from $1,600 2025-02-15
Label Studio HIGH 7.7
CVE-2025-25297

Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's S3 storage integration feature contains a Server-Side Requ…

Fix: 1.16.0+
Fix from $1,950 2025-02-14
GitLab HIGH 8.8
CVE-2024-9870

An external service interaction vulnerability in GitLab EE affecting all versions from 15.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to…

Fix: 17.6.5 / 17.7.4+
Fix from $1,950 2025-02-12
Tableau Server HIGH 7.7
CVE-2025-26494

Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server allows Authentication Bypass.This issue affects Tableau Server: from 20…

Fix: after 2023.3.5
Fix from $1,950 2025-02-11
Utility Configuration Collector Edge HIGH 7.8
CVE-2025-22399

Dell UCC Edge, version 2.3.0, contains a Blind SSRF on Add Customer SFTP Server vulnerability. An unauthenticated attacker with local access could po…

Patch available
Fix from $1,950 2025-02-11
Solarwinds Platform CRITICAL 9.8
CVE-2024-52606

SolarWinds Platform is affected by server-side request forgery vulnerability. Proper input sanitation was not applied allowing for the possibility of…

Fix: 2025.1+
Fix from $2,300 2025-02-11
Unclassified MEDIUM 6.5
CVE-2025-1211

Versions of the package hackney before 1.21.0 are vulnerable to Server-side Request Forgery (SSRF) due to improper parsing of URLs by URI built-in mo…

Patch available
Fix from $1,600 2025-02-11