Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Unclassified MEDIUM 5.4
CVE-2023-31456

There is an SSRF vulnerability in the Fluid Topics platform that affects versions prior to 4.3, where the server can be forced to make arbitrary requ…

Mitigation only
Fix from $1,600 2024-07-16
Unclassified MEDIUM 5.1
CVE-2024-36458

The vulnerability allows a malicious low-privileged PAM user to perform server upgrade related actions.

No fix yet
Fix from $1,600 2024-07-15
Publiccms HIGH 8.8
CVE-2024-40543

PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/ueditor?action=catchimage.

Fix: after 4.0.202302.e
Fix from $1,950 2024-07-12
Publiccms HIGH 8.8
CVE-2024-40544

PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/#maintenance_sysTask/edit.

Fix: after 4.0.202302.e
Fix from $1,950 2024-07-12
Sharepoint Server HIGH 7.5
CVE-2024-32987

Microsoft SharePoint Server Information Disclosure Vulnerability

Patch available
Fix from $1,950 2024-07-09
Saptmui MEDIUM 5.0
CVE-2024-37171

SAP Transportation Management (Collaboration Portal) allows an attacker with non-administrative privileges to send a crafted request from a vulnerabl…

Mitigation only
Fix from $1,600 2024-07-09
Business Workflow MEDIUM 5.0
CVE-2024-34689

WebFlow Services of SAP Business Workflow allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by speciall…

Mitigation only
Fix from $1,600 2024-07-09
Customer Relationship Management S4fnd HIGH 7.7
CVE-2024-39598

SAP CRM (WebClient UI Framework) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially craftin…

Mitigation only
Fix from $1,950 2024-07-09
Directus MEDIUM 5.0
CVE-2024-39699

Directus is a real-time API and App dashboard for managing SQL database content. There was already a reported SSRF vulnerability via file import. It …

Fix: 10.9.3+
Fix from $1,600 2024-07-08
Localai MEDIUM 5.8
CVE-2024-6095

A vulnerability in the /models/apply endpoint of mudler/localai versions 2.15.0 allows for Server-Side Request Forgery (SSRF) and partial Local File …

Fix: 2.17.0+
Fix from $1,600 2024-07-06
Foxiz CRITICAL 9.3
CVE-2024-37260

Server-Side Request Forgery (SSRF) vulnerability in Theme-Ruby Foxiz.This issue affects Foxiz: from n/a through 2.3.5.

Fix: 2.3.6+
Fix from $2,300 2024-07-06
Pi Hole HIGH 8.8
CVE-2024-34361

Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. A vulnerability in versions prior …

Fix: 5.18.3+
Fix from $1,950 2024-07-05
Unclassified HIGH 7.2
CVE-2024-39687

Fedify is a TypeScript library for building federated server apps powered by ActivityPub and other standards. At present, when Fedify needs to retrie…

Patch available
Fix from $1,950 2024-07-05
Personal Management System CRITICAL 9.8
CVE-2024-29319

Volmarg Personal Management System 1.4.64 is vulnerable to SSRF (Server Side Request Forgery) via uploading a SVG file. The server can make unintende…

No fix yet
Fix from $2,300 2024-07-05
Shopxo HIGH 8.8
CVE-2024-6524

A vulnerability was found in ShopXO up to 6.1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …

Fix: after 6.1.0
Fix from $1,950 2024-07-05
Discourse MEDIUM 5.3
CVE-2024-37157

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 on the `beta` and `tests-passe…

Fix: 3.2.3 / 3.3.0+
Fix from $1,600 2024-07-03
HTTP Server HIGH 7.5
CVE-2024-38472EPSS 69%

SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users …

Fix: 2.4.60+
Fix from $1,950 2024-07-01
Mesbook HIGH 8.2
CVE-2024-6424

External server-side request vulnerability in MESbook 20221021.03 version, which could allow a remote, unauthenticated attacker to exploit the endpoi…

Mitigation only
Fix from $1,950 2024-07-01
Infosphere Information Server MEDIUM 5.4
CVE-2023-50952

IBM InfoSphere Information Server 11.7 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthor…

Mitigation only
Fix from $1,600 2024-06-30
Unclassified HIGH 7.4
CVE-2024-38514

NextChat is a cross-platform ChatGPT/Gemini UI. There is a Server-Side Request Forgery (SSRF) vulnerability due to a lack of validation of the `endpo…

Patch available
Fix from $1,950 2024-06-28
Admirorframes HIGH 7.5
CVE-2024-5736

Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla! extension in afGdStream.php script allows to access local files or server p…

Fix: 5.0+
Fix from $1,950 2024-06-28
Quivr HIGH 8.6
CVE-2024-5885

stangirard/quivr version 0.0.236 contains a Server-Side Request Forgery (SSRF) vulnerability. The application does not provide sufficient controls wh…

No fix yet
Fix from $1,950 2024-06-27
Chuanhuchatgpt CRITICAL 9.8
CVE-2024-5822

A Server-Side Request Forgery (SSRF) vulnerability exists in the upload processing interface of gaizhenbiao/ChuanhuChatGPT versions <= ChuanhuChatGPT…

No fix yet
Fix from $2,300 2024-06-27
Blossomthemes Email Newsletter CRITICAL 9.8
CVE-2024-37098

Server-Side Request Forgery (SSRF) vulnerability in Blossom Themes BlossomThemes Email Newsletter.This issue affects BlossomThemes Email Newsletter: …

Fix: 2.2.7+
Fix from $2,300 2024-06-26
Unclassified MEDIUM 5.3
CVE-2024-34580

Apache XML Security for C++ through 2.0.4 implements the XML Signature Syntax and Processing (XMLDsig) specification without protection against an SS…

Mitigation only
Fix from $1,600 2024-06-26
Unclassified HIGH 7.3
CVE-2024-34581

The W3C XML Signature Syntax and Processing (XMLDsig) specification, starting with 1.0, was originally published with a "RetrievalMethod is a URI ...…

Mitigation only
Fix from $1,950 2024-06-26
Whatsup Gold MEDIUM 6.5
CVE-2024-5014

In WhatsUp Gold versions released before 2023.1.3, a Server Side Request Forgery vulnerability exists in the GetASPReport feature. This allows any au…

Fix: 23.1.3+
Fix from $1,600 2024-06-25
Whatsup Gold HIGH 8.8
CVE-2024-5015

In WhatsUp Gold versions released before 2023.1.3, an authenticated SSRF vulnerability in Wug.UI.Areas.Wug.Controllers.SessionControler.Update allows…

Fix: 23.1.3+
Fix from $1,950 2024-06-25
Adminerevo MEDIUM 5.3
CVE-2023-45195

Adminer and AdminerEvo are vulnerable to SSRF via database connection fields. This could allow an unauthenticated remote attacker to enumerate or acc…

Fix: 4.8.4+
Fix from $1,600 2024-06-24
Enterprise Server HIGH 7.2
CVE-2024-5746

A Server-Side Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with the Site Administrator role to g…

Fix: 3.9.16 / 3.10.13+
Fix from $1,950 2024-06-20