Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Unclassified MEDIUM 6.5
CVE-2024-10524

Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these c…

Mitigation only
Fix from $1,600 2024-11-19
Ofbiz CRITICAL 9.8
CVE-2024-47208

Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apac…

Fix: 18.12.17+
Fix from $2,300 2024-11-18
Chatwoot HIGH 8.8
CVE-2021-3742

A Server-Side Request Forgery (SSRF) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.5.0. The vulnerability allo…

Fix: 2.5.0+
Fix from $1,950 2024-11-15
Commerce HIGH 7.7
CVE-2024-49521

Adobe Commerce versions 3.2.5 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to a security feature by…

Fix: 3.2.6+
Fix from $1,950 2024-11-12
Unclassified MEDIUM 6.4
CVE-2024-10814

The Code Embed plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5 via the ce_get_file() func…

Mitigation only
Fix from $1,600 2024-11-09
Unclassified CRITICAL 9.1
CVE-2024-50811

hopetree izone lts c011b48 contains a server-side request forgery (SSRF) vulnerability in the active push function as \\apps\\tool\\apis\\bd_push.py …

Mitigation only
Fix from $2,300 2024-11-08
Unclassified MEDIUM 6.5
CVE-2024-46947

Northern.tech Mender before 3.6.6 and 3.7.x before 3.7.7 allows SSRF.

Mitigation only
Fix from $1,600 2024-11-08
Siem HIGH 7.5
CVE-2024-48951

An issue was discovered in Logpoint before 7.5.0. Server-Side Request Forgery (SSRF) on SOAR can be used to leak Logpoint's API Token leading to auth…

Fix: 7.5.0+
Fix from $1,950 2024-11-07
Identity Services Engine MEDIUM 6.5
CVE-2024-20531

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of a…

Mitigation only
Fix from $1,600 2024-11-06
Unclassified CRITICAL 9.8
CVE-2024-51358

An issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a crafted script to the Add new application.

Mitigation only
Fix from $2,300 2024-11-05
Itop HIGH 8.8
CVE-2024-51740

Combodo iTop is a simple, web based IT Service Management tool. This vulnerability can be used to create HTTP requests on behalf of the server, from …

Fix: 2.7.11 / 3.0.5+
Fix from $1,950 2024-11-05
Gradio MEDIUM 6.5
CVE-2024-48052

In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_…

Fix: after 4.42.0
Fix from $1,600 2024-11-04
Appsmith MEDIUM 6.5
CVE-2024-51408

AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadata credent…

Fix: 1.46+
Fix from $1,600 2024-11-04
Qualitor HIGH 7.5
CVE-2024-48360

Qualitor v8.24 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /request/viewValidacao.php.

No fix yet
Fix from $1,950 2024-10-31
Unclassified MEDIUM 6.1
CVE-2024-48346

xtreme1 <= v0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the /api/data/upload path. The vulnerability is triggered through th…

Mitigation only
Fix from $1,600 2024-10-30
Eladmin MEDIUM 6.5
CVE-2024-51242

A Server-Side Request Forgery (SSRF) vulnerability has been identified in eladmin 2.7 and earlier in ServerDeployController.java. The manipulation of…

Fix: after 2.7
Fix from $1,600 2024-10-30
Sparkshop MEDIUM 6.5
CVE-2024-48107

SparkShop <=1.1.7 is vulnerable to server-side request forgery (SSRF). This vulnerability allows attacks to scan ports on the Intranet or local netwo…

Fix: after 1.1.7
Fix from $1,600 2024-10-28
Newbee Mall HIGH 8.1
CVE-2024-48178

newbee-mall v1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via the goodsCoverImg parameter.

No fix yet
Fix from $1,950 2024-10-28
Unclassified MEDIUM 6.5
CVE-2024-48450

An arbitrary file upload vulnerability in Huly Platform v0.6.295 allows attackers to execute arbitrary code via uploading a crafted HTML file into ch…

Mitigation only
Fix from $1,600 2024-10-25
Butterfly CRITICAL 9.1
CVE-2024-47883

The OpenRefine fork of the MIT Simile Butterfly server is a modular web application framework. The Butterfly framework uses the `java.net.URL` class …

Fix: after 1.2.6
Fix from $2,300 2024-10-24
Collaboration HIGH 8.8
CVE-2024-45518EPSS 20%

An issue was discovered in Zimbra Collaboration (ZCS) 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41, and 8.8.15 before Patch 46. …

Fix: 10.0.9+
Fix from $1,950 2024-10-22
Bridge HIGH 8.6
CVE-2024-49312

Server-Side Request Forgery (SSRF) vulnerability in WisdmLabs Edwiser Bridge edwiser-bridge.This issue affects Edwiser Bridge: from n/a through <= 3.…

Fix: 3.0.8+
Fix from $1,950 2024-10-17
Mapplic HIGH 8.3
CVE-2012-10018

The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and including 6.1, 1.0 respective…

Fix: after 6.1
Fix from $1,950 2024-10-16
Jpress HIGH 7.5
CVE-2024-46468

A Server-Side Request Forgery (SSRF) vulnerability exists in the jpress <= v5.1.1, which can be exploited by an attacker to obtain sensitive informat…

Fix: after 5.1.1
Fix from $1,950 2024-10-11
Plane MEDIUM 5.8
CVE-2024-47830

Plane is an open-source project management tool. Plane uses the ** wildcard support to retrieve the image from any hostname as in /web/next.config.js…

Fix: 0.23.0+
Fix from $1,600 2024-10-11
Unclassified HIGH 7.5
CVE-2024-45317

A Server-Side Request Forgery (SSRF) vulnerability in SMA1000 appliance firmware versions 12.4.3-02676 and earlier allows a remote, unauthenticated a…

Mitigation only
Fix from $1,950 2024-10-11
Gradio CRITICAL 9.8
CVE-2024-47167

Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **Server-Side Request Forgery (SSRF)** in the `…

Fix: 5.0.0+
Fix from $2,300 2024-10-10
GitLab HIGH 8.1
CVE-2024-8977

An issue has been discovered in GitLab EE affecting all versions starting from 15.10 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior …

Fix: 17.2.9 / 17.3.5+
Fix from $1,950 2024-10-10
Avalanche HIGH 7.5
CVE-2024-47008EPSS 47%

Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.

Fix: 6.4.5+
Fix from $1,950 2024-10-08
Phpspreadsheet HIGH 7.5
CVE-2024-45290

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file which links m…

Fix: 1.29.2 / 2.1.1+
Fix from $1,950 2024-10-07