Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Phpspreadsheet HIGH 8.8
CVE-2024-45291

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file that links im…

Fix: 1.29.2 / 2.1.1+
Fix from $1,950 2024-10-07
Ada MEDIUM 5.3
CVE-2024-9410

Ada.cx's Sentry configuration allowed for blind server-side request forgeries (SSRF) through the use of a data scraping endpoint.

Fix: 2024-10-01+
Fix from $1,600 2024-10-04
Mattermost Server MEDIUM 5.4
CVE-2024-45843

Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker …

Fix: 9.5.9+
Fix from $1,600 2024-09-26
My Office Sdk CRITICAL 9.8
CVE-2024-47222

New Cloud MyOffice SDK Collaborative Editing Server 2.2.2 through 2.8 allows SSRF via manipulation of requests from external document storage via the…

Fix: after 2.8.0
Fix from $2,300 2024-09-23
Unclassified MEDIUM 6.6
CVE-2024-40441

An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a d…

Mitigation only
Fix from $1,600 2024-09-23
Lobe Chat HIGH 8.8
CVE-2024-47066EPSS 12%

Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forgery protection implemented in `…

Fix: 1.19.3+
Fix from $1,950 2024-09-23
Unclassified HIGH 7.5
CVE-2024-43989EPSS 13%

Server-Side Request Forgery (SSRF) vulnerability in Firsh Justified Image Grid justified-image-grid.This issue affects Justified Image Grid: from n/a…

Mitigation only
Fix from $1,950 2024-09-23
Directus MEDIUM 5.0
CVE-2024-46990

Directus is a real-time API and App dashboard for managing SQL database content. When relying on blocking access to localhost using the default `0.0.…

Fix: 10.13.3 / 11.1.0+
Fix from $1,600 2024-09-18
Mautic MEDIUM 6.5
CVE-2022-25777

Prior to the patched version, an authenticated user of Mautic could read system files and access the internal addresses of the application due to a S…

Fix: 4.4.12 / 5.0.4+
Fix from $1,600 2024-09-18
Groupme CRITICAL 9.8
CVE-2024-38183

An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network.

Patch available
Fix from $2,300 2024-09-17
File Handling HIGH 8.2
CVE-2024-47049

The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrl and make…

Fix: 1.5.0 / 2.3.0+
Fix from $1,950 2024-09-17
Litellm HIGH 7.5
CVE-2024-6587EPSS 37%

A Server-Side Request Forgery (SSRF) vulnerability exists in berriai/litellm version 1.38.10. This vulnerability allows users to specify the `api_bas…

Patch available
Fix from $1,950 2024-09-13
GitLab MEDIUM 6.5
CVE-2024-8635

A server-side request forgery issue has been discovered in GitLab EE affecting all versions starting from 16.8 prior to 17.1.7, from 17.2 prior to 17…

Fix: 17.1.7 / 17.2.5+
Fix from $1,600 2024-09-12
Edirectory CRITICAL 9.8
CVE-2021-38132

Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000.

Fix: 9.2.6.0000+
Fix from $2,300 2024-09-12
Eladmin CRITICAL 9.8
CVE-2024-44677

eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabaseContro…

Fix: after 2.7
Fix from $2,300 2024-09-10
Spectrum HIGH 8.8
CVE-2023-37229

Loftware Spectrum before 5.1 allows SSRF.

Fix: 5.1+
Fix from $1,950 2024-09-10
Spectrum HIGH 8.8
CVE-2023-37230

Loftware Spectrum (testDeviceConnection) before 5.1 allows SSRF.

Fix: 5.1+
Fix from $1,950 2024-09-10
Seacms CRITICAL 9.8
CVE-2024-44721

SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.

No fix yet
Fix from $2,300 2024-09-09
Unclassified HIGH 8.8
CVE-2024-40718

A server side request forgery vulnerability allows a low-privileged user to perform local privilege escalation through exploiting an SSRF vulnerabili…

Mitigation only
Fix from $1,950 2024-09-07
Mindsdb CRITICAL 9.1
CVE-2024-24759

MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-sid…

Fix: 23.12.4.2+
Fix from $2,300 2024-09-05
Ofbiz CRITICAL 9.8
CVE-2024-45507EPSS 93%

Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apac…

Fix: 18.12.16+
Fix from $2,300 2024-09-04
Ckan MEDIUM 6.5
CVE-2024-43371

CKAN is an open-source data management system for powering data hubs and data portals. There are a number of CKAN plugins, including XLoader, DataPus…

Fix: 2.10.5+
Fix from $1,600 2024-08-21
Unclassified HIGH 7.2
CVE-2022-1751

The Skitter Slideshow plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.2 via the /image.ph…

Mitigation only
Fix from $1,950 2024-08-17
Terminalfour MEDIUM 6.5
CVE-2024-22217

A Server-Side Request Forgery (SSRF) vulnerability in Terminalfour before 8.3.19 allows authenticated users to use specific features to access intern…

Fix: 8.3.19+
Fix from $1,600 2024-08-15
Unclassified MEDIUM 6.3
CVE-2024-22219

XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows authenticated users to submi…

Mitigation only
Fix from $1,600 2024-08-15
Ltcms CRITICAL 9.8
CVE-2024-7743

A vulnerability was found in wanglongcn ltcms 1.0.20. It has been declared as critical. Affected by this vulnerability is the function downloadUrl of…

No fix yet
Fix from $2,300 2024-08-13
Ltcms CRITICAL 9.8
CVE-2024-7742

A vulnerability was found in wanglongcn ltcms 1.0.20. It has been classified as critical. Affected is the function multiDownload of the file /api/fil…

No fix yet
Fix from $2,300 2024-08-13
Ltcms CRITICAL 9.8
CVE-2024-7740

A vulnerability has been found in wanglongcn ltcms 1.0.20 and classified as critical. This vulnerability affects the function download of the file /a…

No fix yet
Fix from $2,300 2024-08-13
Azure Health Bot HIGH 8.8
CVE-2024-38109

An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a …

Patch available
Fix from $1,950 2024-08-13
Crm Abap Insights Management MEDIUM 5.0
CVE-2024-41737

SAP CRM ABAP (Insights Management) allows an authenticated attacker to enumerate HTTP endpoints in the internal network by specially crafting HTTP re…

Mitigation only
Fix from $1,600 2024-08-13