Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Prestashop HIGH 8.1
CVE-2024-41651

An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE: this is disp…

Fix: after 8.1.7
Fix from $1,950 2024-08-12
Openhab Web Interface CRITICAL 10.0
CVE-2024-42467

openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. In versions 3.4.0.M4 through 4…

Fix: 4.2.1+
Fix from $2,300 2024-08-12
Havoc CRITICAL 9.8
CVE-2024-41570

An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send arbitrary network traffic or…

No fix yet
Fix from $2,300 2024-08-12
Axios HIGH 7.5
CVE-2024-39338

axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs.

Fix: 1.7.4+
Fix from $1,950 2024-08-12
Modern Events Calendar CRITICAL 9.6
CVE-2024-6522

The Modern Events Calendar plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.12.1 via the 'me…

Fix: 7.13.0+
Fix from $2,300 2024-08-07
Copilot Studio MEDIUM 6.5
CVE-2024-38206EPSS 12%

An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a n…

Patch available
Fix from $1,600 2024-08-06
Nuxt HIGH 7.5
CVE-2024-42352

Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. `nuxt/icon` provides an API to allow client …

Fix: 1.4.5+
Fix from $1,950 2024-08-05
Iotdb Workbench HIGH 7.3
CVE-2024-36448

** UNSUPPORTED WHEN ASSIGNED ** Server-Side Request Forgery (SSRF) vulnerability in Apache IoTDB Workbench. This issue affects Apache IoTDB Workbenc…

Mitigation only
Fix from $1,950 2024-08-05
Rocket.chat HIGH 8.6
CVE-2024-39713

A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.

Fix: 6.10.1+
Fix from $1,950 2024-08-05
Unclassified MEDIUM 5.4
CVE-2024-39637

Server-Side Request Forgery (SSRF) vulnerability in pixelcurve Edubin edubin.This issue affects Edubin: from n/a through <= 9.2.0.

Mitigation only
Fix from $1,600 2024-08-01
Ai Engine HIGH 7.1
CVE-2024-38791

Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot allows Server Side Request Forgery.This issue affects AI En…

Fix: 2.4.8+
Fix from $1,950 2024-08-01
Remote Content Shortcode MEDIUM 6.4
CVE-2024-2090

The Remote Content Shortcode plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.5 via the remo…

Fix: after 1.5
Fix from $1,600 2024-08-01
Youdiancms MEDIUM 6.3
CVE-2024-7330

A vulnerability has been found in YouDianCMS 7 and classified as critical. Affected by this vulnerability is the function curl_exec of the file /App/…

No fix yet
Fix from $1,600 2024-08-01
Gravityzone CRITICAL 9.8
CVE-2024-6980

A verbose error handling issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request fo…

Fix: 6.38.1-5+
Fix from $2,300 2024-07-31
Streamlit Geospatial CRITICAL 9.8
CVE-2024-41120

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `url` va…

Fix: 2024-07-19+
Fix from $2,300 2024-07-26
Streamlit Geospatial CRITICAL 9.8
CVE-2024-41118

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `url` va…

Fix: 2024-07-19+
Fix from $2,300 2024-07-26
Txtdot HIGH 7.5
CVE-2024-41812

txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Prior to version 1.7.0, a Server-Side …

Fix: 1.7.0+
Fix from $1,950 2024-07-26
Txtdot HIGH 7.5
CVE-2024-41813

txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Starting in version 1.4.0 and prior to…

Fix: 1.6.1+
Fix from $1,950 2024-07-26
Unclassified MEDIUM 6.9
CVE-2024-6922EPSS 30%

Automation Anywhere Automation 360 v21-v32 is vulnerable to Server-Side Request Forgery in a web API component. An attacker with unauthenticated acce…

Mitigation only
Fix from $1,600 2024-07-26
Unclassified HIGH 8.3
CVE-2024-41668

The cBioPortal for Cancer Genomics provides visualization, analysis, and download of large-scale cancer genomics data sets. When running a publicly e…

Patch available
Fix from $1,950 2024-07-23
Unclassified MEDIUM 5.4
CVE-2024-41664

Canarytokens help track activity and actions on a network. Prior to `sha-8ea5315`, Canarytokens.org was vulnerable to a blind SSRF in the Webhook ale…

Mitigation only
Fix from $1,600 2024-07-23
Coblocks MEDIUM 6.5
CVE-2024-4260

The Page Builder Gutenberg Blocks WordPress plugin before 3.1.12 does not prevent users from pinging arbitrary hosts via some of its shortcodes, whi…

Fix: 3.1.12+
Fix from $1,600 2024-07-23
Magical Addons For Elementor MEDIUM 6.4
CVE-2024-38730

Server-Side Request Forgery (SSRF) vulnerability in Noor alam Magical Addons For Elementor.This issue affects Magical Addons For Elementor: from n/a …

Fix: 1.1.42+
Fix from $1,600 2024-07-22
Json Content Importer MEDIUM 6.4
CVE-2024-38723

Server-Side Request Forgery (SSRF) vulnerability in Bernhard Kux JSON Content Importer.This issue affects JSON Content Importer: from n/a through 1.5…

Fix: 1.6.0+
Fix from $1,600 2024-07-22
Seraphinite Post .docx Source MEDIUM 6.4
CVE-2024-38728

Server-Side Request Forgery (SSRF) vulnerability in Seraphinite Solutions Seraphinite Post .DOCX Source.This issue affects Seraphinite Post .DOCX Sou…

Fix: 2.16.10+
Fix from $1,600 2024-07-22
Berqwp HIGH 7.2
CVE-2024-37942

Server-Side Request Forgery (SSRF) vulnerability in Berqier Ltd BerqWP.This issue affects BerqWP: from n/a through 1.7.5.

Fix: 1.7.6+
Fix from $1,950 2024-07-22
Cxf CRITICAL 9.1
CVE-2024-29736

A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style att…

Fix: 3.5.9 / 3.6.4+
Fix from $2,300 2024-07-19
Unclassified HIGH 8.2
CVE-2024-21527

Versions of the package github.com/gotenberg/gotenberg/v8/pkg/gotenberg before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/pkg/m…

Patch available
Fix from $1,950 2024-07-19
Bigfix Compliance MEDIUM 6.2
CVE-2024-30125

HCL BigFix Compliance server can respond with an HTTP status of 500, indicating a server-side error that may cause the server process to die.

Fix: 2.0.11+
Fix from $1,600 2024-07-18
HTTP Server HIGH 7.5
CVE-2024-40898

SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF…

Fix: 2.4.62+
Fix from $1,950 2024-07-18