Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Strapi HIGH 8.6
CVE-2024-37818

Strapi v4.24.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /strapi.io/_next/image. This vulnerability allows att…

No fix yet
Fix from $1,950 2024-06-20
Unclassified CRITICAL 9.3
CVE-2024-5021

The WordPress Picture / Portfolio / Media Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includ…

Mitigation only
Fix from $2,300 2024-06-19
Elementskit CRITICAL 9.6
CVE-2024-4404

The ElementsKit PRO plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.6.2 via the 'render_raw' fu…

Fix: 3.6.3+
Fix from $2,300 2024-06-14
Computer Vision Annotation Tool HIGH 8.5
CVE-2024-37164

Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. CVAT allows users to supply custom endp…

Fix: 2.14.3+
Fix from $1,950 2024-06-13
Commerce HIGH 8.8
CVE-2024-34111

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could…

Fix: after 1.4.0
Fix from $1,950 2024-06-13
Allura HIGH 7.5
CVE-2024-36471

Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL.  Project administrators can run these imp…

Fix: 1.17.0+
Fix from $1,950 2024-06-10
Suitecrm MEDIUM 6.5
CVE-2024-36414

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in the co…

Fix: 7.14.4 / 8.6.1+
Fix from $1,600 2024-06-10
Tablepress MEDIUM 6.4
CVE-2024-4354

The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including…

Fix: 2.3.2+
Fix from $1,600 2024-06-07
Lunary CRITICAL 9.3
CVE-2024-5328

A Server-Side Request Forgery (SSRF) vulnerability exists in the lunary-ai/lunary application, specifically within the endpoint '/auth/saml/tto/downl…

No fix yet
Fix from $2,300 2024-06-06
Privategpt HIGH 7.2
CVE-2024-5186

A Server-Side Request Forgery (SSRF) vulnerability exists in the file upload section of imartinez/privategpt version 0.5.0. This vulnerability allows…

No fix yet
Fix from $1,950 2024-06-06
Quivr HIGH 7.7
CVE-2024-4851

A Server-Side Request Forgery (SSRF) vulnerability exists in the stangirard/quivr application, version 0.0.204, which allows attackers to access inte…

No fix yet
Fix from $1,950 2024-06-06
Anythingllm HIGH 8.8
CVE-2024-3149

A Server-Side Request Forgery (SSRF) vulnerability exists in the upload link feature of mintplex-labs/anything-llm. This feature, intended for users …

Fix: 1.0.0+
Fix from $1,950 2024-06-06
Langchain HIGH 7.7
CVE-2024-3095

A Server-Side Request Forgery (SSRF) vulnerability exists in the Web Research Retriever component of langchain-ai/langchain version 0.1.5. The vulner…

Fix: 0.2.9+
Fix from $1,950 2024-06-06
Lollms Web Ui CRITICAL 9.8
CVE-2024-5482

A Server-Side Request Forgery (SSRF) vulnerability exists in the 'add_webpage' endpoint of the parisneo/lollms-webui application, affecting the lates…

No fix yet
Fix from $2,300 2024-06-06
Gradio HIGH 8.6
CVE-2024-4325EPSS 37%

A Server-Side Request Forgery (SSRF) vulnerability exists in the gradio-app/gradio version 4.21.0, specifically within the `/queue/join` endpoint and…

Fix: 4.41.0+
Fix from $1,950 2024-06-06
Anythingllm HIGH 8.8
CVE-2024-3152

mintplex-labs/anything-llm is vulnerable to multiple security issues due to improper input validation in several endpoints. An attacker can exploit t…

Fix: 1.0.0+
Fix from $1,950 2024-06-06
Gravityzone CRITICAL 9.8
CVE-2024-4177

A host whitelist parser issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request for…

Fix: 6.38.1-2+
Fix from $2,300 2024-06-06
Finesse MEDIUM 5.3
CVE-2024-20404EPSS 23%

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on a…

Fix: 11.6+
Fix from $1,600 2024-06-05
Oncall CRITICAL 9.1
CVE-2024-5526

Grafana OnCall is an easy-to-use on-call management tool that will help reduce toil in on-call management through simpler workflows and interfaces th…

Fix: 1.5.2+
Fix from $2,300 2024-06-05
Anythingllm HIGH 7.5
CVE-2024-4084

A Server-Side Request Forgery (SSRF) vulnerability exists in the latest version of mintplex-labs/anything-llm, allowing attackers to bypass the offic…

Fix: after 1.5.4
Fix from $1,950 2024-06-05
Lylme Spage CRITICAL 9.1
CVE-2024-36675

LyLme_spage v1.9.5 is vulnerable to Server-Side Request Forgery (SSRF) via the get_head function.

No fix yet
Fix from $2,300 2024-06-04
Beyondinsight CRITICAL 9.1
CVE-2024-4219

Prior to 23.2, it is possible to perform arbitrary Server-Side requests via HTTP-based connectors within BeyondInsight, resulting in a server-side re…

Fix: 23.2+
Fix from $2,300 2024-06-04
Unclassified MEDIUM 6.4
CVE-2023-7073

The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including,…

Mitigation only
Fix from $1,600 2024-05-31
Wp Staging HIGH 7.5
CVE-2024-4469

The WP STAGING WordPress Backup Plugin WordPress plugin before 3.5.0 does not prevent users with the administrator role from pinging conducting SSRF…

Fix: 3.5.0+
Fix from $1,950 2024-05-31
Unclassified HIGH 8.1
CVE-2024-36427

The file-serving function in TARGIT Decision Suite before 24.06.19002 (TARGIT Decision Suite 2024 – June) allows authenticated attackers to read or w…

Mitigation only
Fix from $1,950 2024-05-29
Unclassified HIGH 8.1
CVE-2024-29415EPSS 8%

The ip package through 2.0.1 for Node.js might allow SSRF because some IP addresses (such as 127.1, 01200034567, 012.1.2.3, 000:0:0000::01, and ::fFF…

Patch available
Fix from $1,950 2024-05-27
Central Authentication Service CRITICAL 9.1
CVE-2024-4399

The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack

No fix yet
Fix from $2,300 2024-05-23
Wpcafe MEDIUM 5.3
CVE-2024-1855

The WPCafe – Restaurant Menu, Online Ordering for WooCommerce, Pickup / Delivery and Table Reservation plugin for WordPress is vulnerable to Server-S…

Fix: 2.2.24+
Fix from $1,600 2024-05-23
Unclassified CRITICAL 9.1
CVE-2024-25738

A Server-Side Request Forgery (SSRF) vulnerability in the /Upgrade/FixConfig route in Open Library Foundation VuFind 2.0 through 9.1 before 9.1.1 all…

Mitigation only
Fix from $2,300 2024-05-22
Memberpress MEDIUM 6.4
CVE-2024-5031

The Memberpress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.11.29 via the 'mepr-u…

Fix: 1.11.30+
Fix from $1,600 2024-05-22