Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Memos MEDIUM 6.1
CVE-2024-29029

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthentica…

Fix: 0.22.0+
Fix from $1,600 2024-04-19
Memos MEDIUM 5.3
CVE-2024-29028

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthent…

Fix: 0.16.1+
Fix from $1,600 2024-04-19
Memos MEDIUM 5.3
CVE-2024-29030

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /api/resource that allows authenticat…

Fix: 0.22.0+
Fix from $1,600 2024-04-19
Unclassified CRITICAL 9.3
CVE-2024-2796

A server-side request forgery (SSRF) was discovered in the Akana API Platform in versions prior to and including 2022.1.3. Reported by Jakob Antonsso…

Mitigation only
Fix from $2,300 2024-04-18
Unclassified CRITICAL 9.0
CVE-2024-29021EPSS 20%

Judge0 is an open-source online code execution system. The default configuration of Judge0 leaves the service vulnerable to a sandbox escape via Serv…

Mitigation only
Fix from $2,300 2024-04-18
Unclassified MEDIUM 5.5
CVE-2024-31229

Server-Side Request Forgery (SSRF) vulnerability in Really Simple Plugins Really Simple SSL.This issue affects Really Simple SSL: from n/a through 7.…

Mitigation only
Fix from $1,600 2024-04-18
Umbraco Cms MEDIUM 5.3
CVE-2024-29035

Umbraco is an ASP.NET CMS. Failing webhooks logs are available when solution is not in debug mode. Those logs can contain information that is critica…

Fix: 13.1.1+
Fix from $1,600 2024-04-17
Rss Aggregator By Feedzy MEDIUM 6.4
CVE-2023-6805

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-S…

Fix: 4.4.8+
Fix from $1,600 2024-04-17
Open Webui MEDIUM 6.4
CVE-2024-30256

Open WebUI is a user-friendly WebUI for LLMs. Open-webui is vulnerable to authenticated blind server-side request forgery. This vulnerability is fixe…

Fix: 0.1.117+
Fix from $1,600 2024-04-16
Unclassified HIGH 8.1
CVE-2024-22262

Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the …

Mitigation only
Fix from $1,950 2024-04-16
Activecampaign CRITICAL 9.8
CVE-2024-32430

Server-Side Request Forgery (SSRF) vulnerability in ActiveCampaign.This issue affects ActiveCampaign: from n/a through 8.1.14.

Fix: 8.1.15+
Fix from $2,300 2024-04-15
Unclassified CRITICAL 9.1
CVE-2024-31461

Plane, an open-source project management tool, has a Server-Side Request Forgery (SSRF) vulnerability in versions prior to 0.17-dev. This issue may a…

Patch available
Fix from $2,300 2024-04-10
Unclassified MEDIUM 5.0
CVE-2024-3448

Users with low privileges can perform certain AJAX actions. In this vulnerability instance, improper access to ajax?action=plugin:focus:checkIframeA…

Mitigation only
Fix from $1,600 2024-04-10
Unclassified MEDIUM 6.5
CVE-2023-40148

Server-side request forgery (SSRF) in PingFederate allows unauthenticated http requests to attack network resources and consume server-side resources…

Mitigation only
Fix from $1,600 2024-04-10
Avada MEDIUM 6.4
CVE-2024-2343

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and i…

Fix: 7.11.7+
Fix from $1,600 2024-04-09
Everest Forms HIGH 7.2
CVE-2024-1812

The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.7 via the 'font_url' pa…

Fix: 2.0.8+
Fix from $1,950 2024-04-09
Gutenberg Blocks With Ai MEDIUM 6.4
CVE-2023-6964

The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up t…

Fix: 3.2.12+
Fix from $1,600 2024-04-09
Unclassified HIGH 7.3
CVE-2024-1233

A flaw was found in` JwtValidator.resolvePublicKey` in JBoss EAP, where the validator checks jku and sends a HTTP request. During this process, no wh…

Patch available
Fix from $1,950 2024-04-09
Netweaver MEDIUM 5.3
CVE-2024-27898

SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vulnerable web application targe…

Mitigation only
Fix from $1,600 2024-04-09
Unclassified HIGH 7.2
CVE-2024-31288

Server-Side Request Forgery (SSRF) vulnerability in RapidLoad RapidLoad Power-Up for Autoptimize.This issue affects RapidLoad Power-Up for Autoptimiz…

Mitigation only
Fix from $1,950 2024-04-07
Unclassified HIGH 7.5
CVE-2024-27620

An issue in Ladder v.0.0.1 thru v.0.0.21 allows a remote attacker to obtain sensitive information via a crafted request to the API.

No fix yet
Fix from $1,950 2024-04-06
Cloudstack HIGH 7.3
CVE-2024-29007

The CloudStack management server and secondary storage VM could be tricked into making requests to restricted or random resources by means of followi…

Fix: 4.18.1.1+
Fix from $1,950 2024-04-04
Identity Services Engine MEDIUM 5.5
CVE-2024-20332

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduc…

Mitigation only
Fix from $1,600 2024-04-03
Gleez Cms CRITICAL 9.4
CVE-2021-27312

Server Side Request Forgery (SSRF) vulnerability in Gleez Cms 1.2.0, allows remote attackers to execute arbitrary code and obtain sensitive informati…

No fix yet
Fix from $2,300 2024-04-03
Unclassified CRITICAL 9.1
CVE-2024-25864

Server Side Request Forgery (SSRF) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbitrary code and obtain…

Mitigation only
Fix from $2,300 2024-04-03
Gutenberg Blocks With Ai MEDIUM 6.5
CVE-2024-24888

Server-Side Request Forgery (SSRF) vulnerability in StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks.This issue affects Gutenberg Blocks b…

Fix: 3.2.26+
Fix from $1,600 2024-04-02
71cms HIGH 8.6
CVE-2024-25187

Server Side Request Forgery (SSRF) vulnerability in 71cms v1.0.0, allows remote unauthenticated attackers to obtain sensitive information via getweat…

No fix yet
Fix from $1,950 2024-04-02
Unclassified MEDIUM 5.4
CVE-2024-30453

Server-Side Request Forgery (SSRF) vulnerability in Brave Brave Popup Builder.This issue affects Brave Popup Builder: from n/a through 0.6.5.

Mitigation only
Fix from $1,600 2024-03-29
Bigfix Platform HIGH 7.2
CVE-2023-45705

An administrative user of WebReports may perform a Server Side Request Forgery (SSRF) exploit through SMTP configuration options.

Fix: 10.0.11 / 11.0.2+
Fix from $1,950 2024-03-28
Unclassified HIGH 7.2
CVE-2024-27775

SysAid before version 23.2.14 b18 - CWE-918: Server-Side Request Forgery (SSRF) may allow exposing the local OS user's NTLMv2 hash

Mitigation only
Fix from $1,950 2024-03-28