Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Maanager MEDIUM 5.3
CVE-2024-1965

Server-Side Request Forgery vulnerability in Haivision's Aviwest Manager and Aviwest Steamhub. This vulnerability could allow an attacker to enumerat…

Mitigation only
Fix from $1,600 2024-02-28
Seraphinite Accelerator MEDIUM 6.4
CVE-2024-1568

The Seraphinite Accelerator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.20.52 via the O…

Fix: after 2.20.52
Fix from $1,600 2024-02-28
Anythingllm HIGH 7.5
CVE-2024-0759

Should an instance of AnythingLLM be hosted on an internal network and the attacked be explicitly granted a permission level of manager or admin, the…

Fix: 1.0.0+
Fix from $1,950 2024-02-27
Blueking Configuration Management Database HIGH 8.1
CVE-2024-22873

Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/service/s…

Fix: after 3.9.47
Fix from $1,950 2024-02-26
Superfaktura Woocommerce HIGH 8.1
CVE-2024-1758

The SuperFaktura WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.40.3 via the w…

Fix: 1.40.4+
Fix from $1,950 2024-02-26
Anythingllm MEDIUM 6.5
CVE-2024-0440

Attacker, with permission to submit a link or submits a link via POST to be collected that is using the file:// protocol can then introspect host fi…

Patch available
Fix from $1,600 2024-02-26
Anythingllm HIGH 7.5
CVE-2024-0455

The inclusion of the web scraper for AnythingLLM means that any user with the proper authorization level (manager, admin, and when in single user) co…

Patch available
Fix from $1,950 2024-02-26
Langchain HIGH 8.1
CVE-2024-0243

With the following crawler configuration: ```python from bs4 import BeautifulSoup as Soup url = "https://example.com" loader = RecursiveUrlLoader( …

Fix: 0.1.0+
Fix from $1,950 2024-02-26
Pexels\ HIGH 8.8
CVE-2024-25915

Server-Side Request Forgery (SSRF) vulnerability in Raaj Trambadia Pexels: Free Stock Photos.This issue affects Pexels: Free Stock Photos: from n/a t…

Fix: after 1.2.2
Fix from $1,950 2024-02-23
Ai HIGH 7.2
CVE-2024-23654

discourse-ai is the AI plugin for the open-source discussion platform Discourse. Prior to commit 94ba0dadc2cf38e8f81c3936974c167219878edd, interactio…

Fix: 2024-02-21+
Fix from $1,950 2024-02-21
Decidim MEDIUM 5.7
CVE-2023-47635

Decidim is a participatory democracy framework. Starting in version 0.23.0 and prior to versions 0.27.5 and 0.28.0, the CSRF authenticity token check…

Fix: 0.27.5+
Fix from $1,600 2024-02-20
Caddy Security MEDIUM 5.3
CVE-2024-21498

All versions of the package github.com/greenpau/caddy-security are vulnerable to Server-side Request Forgery (SSRF) via X-Forwarded-Host header manip…

No fix yet
Fix from $1,600 2024-02-17
Grafana MEDIUM 5.3
CVE-2023-5122

Grafana is an open-source platform for monitoring and observability. The CSV datasource plugin is a Grafana Labs maintained plugin for Grafana that a…

Fix: 0.6.13+
Fix from $1,600 2024-02-14
Jh Rvb1 Firmware HIGH 8.1
CVE-2024-23788

Server-side request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a netw…

Mitigation only
Fix from $1,950 2024-02-14
Gambio CRITICAL 9.8
CVE-2024-23761

Server Side Template Injection in Gambio 4.9.2.0 allows attackers to run arbitrary code via crafted smarty email template.

No fix yet
Fix from $2,300 2024-02-12
Popup Builder HIGH 7.2
CVE-2023-6294

The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could allow users with the adminis…

Fix: 4.2.6+
Fix from $1,950 2024-02-12
Sentry MEDIUM 5.3
CVE-2024-24829

Sentry is an error tracking and performance monitoring platform. Sentry’s integration platform provides a way for external services to interact with …

Fix: 24.1.2+
Fix from $1,600 2024-02-09
Ip CRITICAL 9.8
CVE-2023-42282

The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable v…

Fix: 1.1.9+
Fix from $2,300 2024-02-08
Xxl Job HIGH 8.8
CVE-2024-24113

xxl-job =< 2.4.1 has a Server-Side Request Forgery (SSRF) vulnerability, which causes low-privileged users to control executor to RCE.

Fix: after 2.4.1
Fix from $1,950 2024-02-08
Libuv HIGH 7.3
CVE-2024-24806

libuv is a multi-platform support library with a focus on asynchronous I/O. The `uv_getaddrinfo` function in `src/unix/getaddrinfo.c` (and its window…

Fix: 1.48.0+
Fix from $1,950 2024-02-07
Suitecrm MEDIUM 5.0
CVE-2023-6388

Suite CRM version 7.14.2 allows making arbitrary HTTP requests through the vulnerable server. This is possible because the application is vulnerable…

No fix yet
Fix from $1,600 2024-02-07
My Cloud Pr2100 Firmware MEDIUM 5.5
CVE-2023-22817

Server-side request forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL using another DNS address to …

Fix: 5.27.161+
Fix from $1,600 2024-02-05
Connect Secure HIGH 8.2
CVE-2024-21893 KEVEPSS 100%

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivant…

Mitigation only
Fix from $1,950 2024-01-31
Platform HIGH 8.6
CVE-2023-50165

Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.

Fix: after 23.1.0
Fix from $1,950 2024-01-31
Label Studio MEDIUM 5.3
CVE-2023-47116

Label Studio is a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to 1.11.0 and was tested on ve…

Fix: 1.11.0+
Fix from $1,600 2024-01-31
Servicecomb HIGH 7.5
CVE-2023-44313

Server-Side Request Forgery (SSRF) vulnerability in Apache ServiceComb Service-Center. Attackers can obtain sensitive server information through spec…

Fix: 2.2.0+
Fix from $1,950 2024-01-31
Truelayer.net HIGH 7.5
CVE-2024-23838

TrueLayer.NET is the .Net client for TrueLayer. The vulnerability could potentially allow a malicious actor to gain control over the destination URL…

Fix: 1.6.0+
Fix from $1,950 2024-01-30
Appwrite HIGH 7.5
CVE-2024-1063

Appwrite <= v1.4.13 is affected by a Server-Side Request Forgery (SSRF) via the '/v1/avatars/favicon' endpoint due to an incomplete fix of CVE-2023-2…

Fix: after 1.4.13
Fix from $1,950 2024-01-30
Seo Panel MEDIUM 5.3
CVE-2024-22648

A Blind SSRF vulnerability exists in the "Crawl Meta Data" functionality of SEO Panel version 4.10.0. This makes it possible for remote attackers to …

No fix yet
Fix from $1,600 2024-01-30
Rebuild CRITICAL 9.8
CVE-2024-1021EPSS 35%

A vulnerability, which was classified as critical, has been found in Rebuild up to 3.5.5. Affected by this issue is the function readRawText of the c…

Fix: after 3.5.5
Fix from $2,300 2024-01-29