Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Dynamics 365 Sales HIGH 8.8
CVE-2025-21177

Server-side request forgery (ssrf) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2025-02-06
Aspera Shares MEDIUM 5.4
CVE-2024-56470

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send una…

Fix: 1.10.0+
Fix from $1,600 2025-02-05
Aspera Shares MEDIUM 5.4
CVE-2024-56471

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send una…

Fix: 1.10.0+
Fix from $1,600 2025-02-05
Zimbra Collaboration Suite MEDIUM 5.3
CVE-2025-25065

SSRF vulnerability in the RSS feed parser in Zimbra Collaboration 9.0.0 before Patch 43, 10.0.x before 10.0.12, and 10.1.x before 10.1.4 allows unaut…

Fix: 9.0.0 / 10.0.12+
Fix from $1,600 2025-02-03
Unclassified MEDIUM 5.4
CVE-2025-22701

Server-Side Request Forgery (SSRF) vulnerability in shinetheme Traveler Layout Essential For Elementor traveler-layout-essential-for-elementor.This i…

Mitigation only
Fix from $1,600 2025-02-03
Unclassified MEDIUM 5.4
CVE-2024-44055

Server-Side Request Forgery (SSRF) vulnerability in brandexponents Oshine Modules oshine-modules.This issue affects Oshine Modules: from n/a through …

Mitigation only
Fix from $1,600 2025-01-31
Unclassified MEDIUM 5.3
CVE-2025-24354

imgproxy is server for resizing, processing, and converting images. Imgproxy does not block the 0.0.0.0 address, even with IMGPROXY_ALLOW_LOOPBACK_SO…

Patch available
Fix from $1,600 2025-01-27
Multiple Page Generator HIGH 8.1
CVE-2024-10705

The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.…

Fix: 4.0.6+
Fix from $1,950 2025-01-26
Contact Form Builder MEDIUM 6.5
CVE-2024-13450

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is v…

Fix: 2.17.5+
Fix from $1,600 2025-01-25
Activity Plus Reloaded For Buddypress MEDIUM 5.4
CVE-2024-11913

The Activity Plus Reloaded for BuddyPress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and includin…

Fix: 1.1.2+
Fix from $1,600 2025-01-24
Aipower MEDIUM 5.4
CVE-2024-13360

The AI Power: Complete AI Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.8.96 via the…

Fix: 1.8.97+
Fix from $1,600 2025-01-22
Ranger CRITICAL 9.1
CVE-2024-45479

SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger…

Fix: 2.5.0+
Fix from $2,300 2025-01-21
Unclassified HIGH 8.6
CVE-2023-50733

A Server-Side Request Forgery (SSRF) vulnerability has been identified in the Web Services feature of newer Lexmark devices.

Mitigation only
Fix from $1,950 2025-01-21
Unclassified MEDIUM 5.4
CVE-2025-23221

Fedify is a TypeScript library for building federated server apps powered by ActivityPub and other standards. This vulnerability allows a user to man…

Patch available
Fix from $1,600 2025-01-20
A\+hrd MEDIUM 5.3
CVE-2025-0584

The a+HRD from aEnrich Technology has a Server-side Request Forgery, allowing unauthenticated remote attackers to exploit this vulnerability to probe…

Fix: after 7.5
Fix from $1,600 2025-01-20
Matrix Media Repo MEDIUM 5.3
CVE-2024-52602

Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. Matrix Media Repo (MMR) is vulnerable to server-side r…

Fix: 1.3.8+
Fix from $1,600 2025-01-16
Unclassified MEDIUM 6.4
CVE-2025-22346

Server-Side Request Forgery (SSRF) vulnerability in Faizaan Gagan Course Migration for LearnDash allows Server Side Request Forgery.This issue affect…

No fix yet
Fix from $1,600 2025-01-15
Mysiteforme HIGH 8.6
CVE-2024-57767

MSFM before v2025.01.01 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /file/download.

Fix: 2025-01-01+
Fix from $1,950 2025-01-15
Unclassified HIGH 7.7
CVE-2025-0474

Invoice Ninja is vulnerable to authenticated Server-Side Request Forgery (SSRF) allowing for arbitrary file read and network resource requests as the…

Patch available
Fix from $1,950 2025-01-14
Backup HIGH 7.2
CVE-2025-23082

Veeam Backup for Microsoft Azure is vulnerable to Server-Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized…

Fix: 7.1.0.59+
Fix from $1,950 2025-01-14
Dryice Myxalytics CRITICAL 9.4
CVE-2024-42168

HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability. An attacker can deploy a web server that returns malicious content, an…

Mitigation only
Fix from $2,300 2025-01-11
Purview MEDIUM 6.5
CVE-2025-21385EPSS 24%

A Server-Side Request Forgery (SSRF) vulnerability in Microsoft Purview allows an authorized attacker to disclose information over a network.

No fix yet
Fix from $1,600 2025-01-09
Greenshift Animation And Page Builder Blocks MEDIUM 5.4
CVE-2024-6155

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Authenticated (Subscriber+) Server-Side Request Forgery and …

Fix: 9.0.1+
Fix from $1,600 2025-01-09
Unclassified HIGH 7.5
CVE-2024-53705

A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establish a TCP connection to an IP a…

Mitigation only
Fix from $1,950 2025-01-09
Bookstore CRITICAL 9.8
CVE-2024-13195

A vulnerability was found in donglight bookstore电商书城系统说明 1.0.0. It has been classified as critical. This affects the function getHtml of the …

No fix yet
Fix from $2,300 2025-01-09
Unclassified CRITICAL 9.1
CVE-2024-54819EPSS 18%

I, Librarian before and including 5.11.1 is vulnerable to Server-Side Request Forgery (SSRF) due to improper input validation in classes/security/val…

Patch available
Fix from $2,300 2025-01-07
Unclassified MEDIUM 6.4
CVE-2024-56279

Server-Side Request Forgery (SSRF) vulnerability in mra13 Compact WP Audio Player compact-wp-audio-player allows Server Side Request Forgery.This iss…

Mitigation only
Fix from $1,600 2025-01-07
Mysiteforme HIGH 8.8
CVE-2024-13139

A vulnerability was found in wangl1989 mysiteforme 1.0. It has been rated as critical. This issue affects the function doContent of the file src/main…

No fix yet
Fix from $1,950 2025-01-05
Unclassified HIGH 7.4
CVE-2024-56800

Firecrawl is a web scraper that allows users to extract the content of a webpage for a large language model. Versions prior to 1.1.1 contain a server…

Patch available
Fix from $1,950 2024-12-30
Fastchat CRITICAL 9.3
CVE-2024-10044

A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Controller API Server in lm-sys/fas…

No fix yet
Fix from $2,300 2024-12-30