Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Unclassified MEDIUM 5.5
CVE-2023-50374

Server-Side Request Forgery (SSRF) vulnerability in NiteoThemes CMP – Coming Soon & Maintenance.This issue affects CMP – Coming Soon & Maintenance: f…

Mitigation only
Fix from $1,600 2024-03-28
Ai Engine MEDIUM 6.8
CVE-2024-29090

Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a thr…

Fix: 2.1.5+
Fix from $1,600 2024-03-28
Gutenberg Blocks With Ai MEDIUM 6.5
CVE-2024-23500

Server-Side Request Forgery (SSRF) vulnerability in StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks.This issue affects Gutenberg Blocks b…

Fix: 3.2.20+
Fix from $1,600 2024-03-28
Spectra MEDIUM 6.5
CVE-2023-36679

Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a through 2.6.6.

Fix: 2.6.7+
Fix from $1,600 2024-03-28
Avada HIGH 7.7
CVE-2023-39313

Server-Side Request Forgery (SSRF) vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.

Fix: 7.11.2+
Fix from $1,950 2024-03-28
Unclassified HIGH 7.1
CVE-2023-34370

Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates, Brainstorm …

Mitigation only
Fix from $1,950 2024-03-28
Pz Linkcard MEDIUM 5.1
CVE-2024-0677

The Pz-LinkCard WordPress plugin through 2.5.1 does not prevent users from pinging arbitrary hosts via some of its shortcodes, which could allow high…

Fix: 2.5.3+
Fix from $1,600 2024-03-28
Gradio MEDIUM 6.5
CVE-2024-2206

An SSRF vulnerability exists in the gradio-app/gradio due to insufficient validation of user-supplied URLs in the `/proxy` route. Attackers can explo…

Fix: 4.18.0+
Fix from $1,600 2024-03-27
Twenty MEDIUM 5.4
CVE-2024-28435

The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload.

No fix yet
Fix from $1,600 2024-03-25
Mobile Security Framework HIGH 7.5
CVE-2024-29190

Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analy…

Fix: 3.9.7+
Fix from $1,950 2024-03-22
Easyadmin HIGH 8.8
CVE-2024-2828

A vulnerability, which was classified as critical, was found in lakernote EasyAdmin up to 20240315. Affected is the function thumbnail of the file sr…

Fix: after 2024-03-15
Fix from $1,950 2024-03-22
Easyadmin HIGH 8.8
CVE-2024-2827

A vulnerability, which was classified as critical, has been found in lakernote EasyAdmin up to 20240315. This issue affects some unknown processing o…

Fix: after 2024-03-15
Fix from $1,950 2024-03-22
Rsshub MEDIUM 6.5
CVE-2024-27927

RSSHub is an open source RSS feed generator. Prior to version 1.0.0-master.a429472, RSSHub allows remote attackers to use the server as a proxy to se…

Fix: 1.0.0-master.a429472+
Fix from $1,600 2024-03-21
Likeshop MEDIUM 5.9
CVE-2024-24028

Server Side Request Forgery (SSRF) vulnerability in Likeshop before 2.5.7 allows attackers to view sensitive information via the avatar parameter in …

Fix: 2.5.7+
Fix from $1,600 2024-03-21
Rebuild CRITICAL 9.1
CVE-2024-25294

An SSRF issue in REBUILD v.3.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the FileDownloader.java, proxy…

Mitigation only
Fix from $2,300 2024-03-20
Glpi CRITICAL 9.6
CVE-2024-27098EPSS 36%

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authe…

Fix: 10.0.13+
Fix from $2,300 2024-03-18
Cxf CRITICAL 9.3
CVE-2024-28752

A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style att…

Fix: 3.5.8 / 3.6.3+
Fix from $2,300 2024-03-15
Papercut Mf MEDIUM 6.5
CVE-2024-1884EPSS 38%

This is a Server-Side Request Forgery (SSRF) vulnerability in the PaperCut NG/MF server-side module that allows an attacker to induce the server-sid…

Fix: 20.1.10 / 21.2.14+
Fix from $1,600 2024-03-14
Dedecms MEDIUM 6.1
CVE-2024-28668

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/mychannel_add.php

No fix yet
Fix from $1,600 2024-03-13
Sd Wan 1000 Firmware MEDIUM 5.3
CVE-2024-2049

Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose …

Fix: 11.4.4.46+
Fix from $1,600 2024-03-12
Nextchat CRITICAL 9.8
CVE-2023-49785EPSS 83%

NextChat, also known as ChatGPT-Next-Web, is a cross-platform chat user interface for use with ChatGPT. Versions 2.11.2 and prior are vulnerable to s…

Fix: after 2.11.2
Fix from $2,300 2024-03-12
Chatgpt Wechat Personal CRITICAL 9.8
CVE-2024-27565

A Server-Side Request Forgery (SSRF) in weixin.php of ChatGPT-wechat-personal commit a0857f6 allows attackers to force the application to make arbitr…

No fix yet
Fix from $2,300 2024-03-05
Wondercms HIGH 8.1
CVE-2024-27561

A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers to force the application to …

No fix yet
Fix from $1,950 2024-03-05
Wondercms MEDIUM 5.3
CVE-2024-27563

A Server-Side Request Forgery (SSRF) in the getFileFromRepo function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary …

No fix yet
Fix from $1,600 2024-03-05
Chatgpt MEDIUM 6.5
CVE-2024-27564EPSS 41%

pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references section has an archived copy of …

No fix yet
Fix from $1,600 2024-03-05
Langchain CRITICAL 9.8
CVE-2024-2057

A vulnerability was found in LangChain langchain_community 0.0.26. It has been classified as critical. Affected is the function load_local in the lib…

Patch available
Fix from $2,300 2024-03-01
Sirv MEDIUM 5.4
CVE-2024-27949

Server-Side Request Forgery (SSRF) vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: from n/a through <= 7.2.0.

Fix: 7.2.1+
Fix from $1,600 2024-03-01
Recipes MEDIUM 6.5
CVE-2024-0403

Recipes version 1.5.10 allows arbitrary HTTP requests to be made through the server. This is possible because the application is vulnerable to SSRF.

No fix yet
Fix from $1,600 2024-03-01
Friends MEDIUM 5.5
CVE-2024-1978

The Friends plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.5 via the discover_available_…

Fix: 2.8.6+
Fix from $1,600 2024-02-29
Worldserver HIGH 8.8
CVE-2022-34269

An issue was discovered in RWS WorldServer before 11.7.3. An authenticated, remote attacker can perform a ws-legacy/load_dtd?system_id= blind SSRF at…

Fix: 11.7.3+
Fix from $1,950 2024-02-29