Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Unclassified MEDIUM 6.4
CVE-2024-4789

Cost Calculator Builder Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to 3.1.72, via the send_demo_webhook…

Mitigation only
Fix from $1,600 2024-05-17
Unclassified HIGH 8.2
CVE-2023-46784

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Server-Side Request Forgery (SSRF) vulnerability in Room 34 Creative …

Mitigation only
Fix from $1,950 2024-05-17
Imanager HIGH 7.5
CVE-2024-3970

Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure by…

Fix: 3.2.6+
Fix from $1,950 2024-05-15
Imanager HIGH 7.5
CVE-2024-3485

Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure.

Fix: 3.2.6+
Fix from $1,950 2024-05-15
Unclassified MEDIUM 5.3
CVE-2024-4894

ITPison OMICARD EDM fails to properly filter specific URL parameter, allowing unauthenticated remote attackers to modify the parameters and conduct …

Mitigation only
Fix from $1,600 2024-05-15
Whatsup Gold MEDIUM 5.3
CVE-2024-4561

In WhatsUp Gold versions released before 2023.1.2 , a blind SSRF vulnerability exists in Whatsup Gold's FaviconController that allows an attacker t…

Fix: 23.1.2+
Fix from $1,600 2024-05-14
Whatsup Gold MEDIUM 5.4
CVE-2024-4562

In WhatsUp Gold versions released before 2023.1.2 , an SSRF vulnerability exists in Whatsup Gold's Issue exists in the HTTP Monitoring functional…

Fix: 23.1.2+
Fix from $1,600 2024-05-14
Unclassified MEDIUM 5.0
CVE-2024-0862

The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains a Server-Side Request Forgery vulnerability that allows an authentica…

Mitigation only
Fix from $1,600 2024-05-14
Linqi MEDIUM 5.9
CVE-2024-33864

An issue was discovered in linqi before 1.4.0.1 on Windows. There is SSRF via Document template generation; i.e., via remote images in process creati…

Fix: 1.4.0.1+
Fix from $1,600 2024-05-14
Next.js HIGH 7.5
CVE-2024-34351EPSS 5%

Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery (SSRF) vulnerability was iden…

Fix: 14.1.1+
Fix from $1,950 2024-05-14
Unclassified HIGH 7.2
CVE-2024-33250

An issue in Open-Source Technology Committee SRS real-time video server RS/4.0.268(Leo) and SRS/4.0.195(Leo) allows a remote attacker to execute arbi…

Mitigation only
Fix from $1,950 2024-05-14
Lobe Chat CRITICAL 9.0
CVE-2024-32964EPSS 53%

Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat …

Fix: 0.150.6+
Fix from $2,300 2024-05-14
Siem CRITICAL 9.6
CVE-2024-33857

An issue was discovered in Logpoint before 7.4.0. Due to a lack of input validation on URLs in threat intelligence, an attacker with low-level access…

Fix: 7.4.0+
Fix from $2,300 2024-05-07
Crmeb Java MEDIUM 5.3
CVE-2024-33117

crmeb_java v1.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the mergeList method in class com.zbkj.front.pub.ImageMergeContr…

Mitigation only
Fix from $1,600 2024-05-06
Wings MEDIUM 6.4
CVE-2024-34068

Pterodactyl wings is the server control plane for Pterodactyl Panel. An authenticated user who has access to a game server is able to bypass the prev…

Fix: 1.11.2+
Fix from $1,600 2024-05-03
Woocommerce Pdf Invoices\& Packing Slips HIGH 7.2
CVE-2024-3047

The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, …

Fix: 3.8.1+
Fix from $1,950 2024-05-02
Unclassified CRITICAL 9.8
CVE-2023-46295

An issue was discovered in Teledyne FLIR M300 2.00-19. Unauthenticated remote code execution can occur in the web server. An attacker can exploit thi…

Mitigation only
Fix from $2,300 2024-05-01
Mybb MEDIUM 5.0
CVE-2024-23336

MyBB is a free and open source forum software. The default list of disallowed remote hosts does not contain the `127.0.0.0/8` block, which may result…

Fix: 1.8.38+
Fix from $1,600 2024-05-01
Unclassified MEDIUM 6.3
CVE-2024-33832

OneNav v0.9.35-20240318 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /index.php?c=api&method=get_link_info.

Mitigation only
Fix from $1,600 2024-04-30
Unclassified HIGH 8.3
CVE-2024-2663

The ZD YouTube FLV Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2.6 via the $_GET…

Mitigation only
Fix from $1,950 2024-04-30
Unclassified MEDIUM 6.4
CVE-2024-0216

The Google Doc Embedder plugin for WordPress is vulnerable to Server Side Request Forgery via the 'gview' shortcode in versions up to, and including,…

Mitigation only
Fix from $1,600 2024-04-30
Unclassified MEDIUM 5.0
CVE-2024-33590

Server-Side Request Forgery (SSRF) vulnerability in codeSavory Knowledge Base documentation & wiki plugin – BasePress.This issue affects Knowledge Ba…

Mitigation only
Fix from $1,600 2024-04-29
Unclassified MEDIUM 5.4
CVE-2024-33634

Server-Side Request Forgery (SSRF) vulnerability in Piotnet Piotnet Addons For Elementor Pro.This issue affects Piotnet Addons For Elementor Pro: fro…

Mitigation only
Fix from $1,600 2024-04-29
Unclassified MEDIUM 5.4
CVE-2024-33592

Server-Side Request Forgery (SSRF) vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73.

Mitigation only
Fix from $1,600 2024-04-25
Unclassified MEDIUM 6.4
CVE-2024-32803

Server-Side Request Forgery (SSRF) vulnerability in 2day.Sk, Webikon SuperFaktura WooCommerce.This issue affects SuperFaktura WooCommerce: from n/a t…

Mitigation only
Fix from $1,600 2024-04-24
Podlove Podcast Publisher MEDIUM 5.4
CVE-2024-32812

Server-Side Request Forgery (SSRF) vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through …

Fix: 4.0.12+
Fix from $1,600 2024-04-24
The Pack Elementor Addons MEDIUM 5.4
CVE-2024-32718

Server-Side Request Forgery (SSRF) vulnerability in Webangon The Pack Elementor.This issue affects The Pack Elementor addons: from n/a through 2.0.8.…

Fix: 2.0.8.3+
Fix from $1,600 2024-04-24
Import Wp MEDIUM 6.1
CVE-2023-7253

The Import WP WordPress plugin before 2.13.1 does not prevent users with the administrator role from pinging conducting SSRF attacks, which may be a…

Fix: 2.13.1+
Fix from $1,600 2024-04-24
Relate HIGH 8.8
CVE-2024-32407

An issue in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Page Sandbox feature.

Fix: 2024.1+
Fix from $1,950 2024-04-22
Hugegraph Hubble MEDIUM 5.3
CVE-2024-27347

Server-Side Request Forgery (SSRF) vulnerability in Apache HugeGraph-Hubble.This issue affects Apache HugeGraph-Hubble: from 1.0.0 before 1.3.0. Use…

Fix: 1.3.0+
Fix from $1,600 2024-04-22