Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
60indexpage CRITICAL 9.8
CVE-2024-0945

A vulnerability classified as critical has been found in 60IndexPage up to 1.8.5. This affects an unknown part of the file /include/file.php of the c…

Fix: 1.8.5+
Fix from $2,300 2024-01-26
60indexpage CRITICAL 9.8
CVE-2024-0946

A vulnerability classified as critical was found in 60IndexPage up to 1.8.5. This vulnerability affects unknown code of the file /apply/index.php of …

Fix: 1.8.5+
Fix from $2,300 2024-01-26
Contact Form 7 Extension For Mailchimp MEDIUM 6.5
CVE-2024-22134

Server-Side Request Forgery (SSRF) vulnerability in Renzo Johnson Contact Form 7 Extension For Mailchimp.This issue affects Contact Form 7 Extension …

Fix: after 0.5.70
Fix from $1,600 2024-01-24
Apex Central HIGH 7.1
CVE-2023-52331

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central could allow an attacker to interact with internal o…

Mitigation only
Fix from $1,950 2024-01-23
Apex Central MEDIUM 5.4
CVE-2023-38624

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacke…

Mitigation only
Fix from $1,600 2024-01-23
Apex Central MEDIUM 5.4
CVE-2023-38625

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacke…

Mitigation only
Fix from $1,600 2024-01-23
Apex Central MEDIUM 5.4
CVE-2023-38626

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacke…

Mitigation only
Fix from $1,600 2024-01-23
Apex Central MEDIUM 5.4
CVE-2023-38627

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacke…

Mitigation only
Fix from $1,600 2024-01-23
Tutanota MEDIUM 5.3
CVE-2024-23330

Tuta is an encrypted email service. In versions prior to 119.10, an attacker can attach an image in a html mail which is loaded from external resourc…

Fix: 119.10+
Fix from $1,600 2024-01-23
Whoogle Search CRITICAL 9.8
CVE-2024-22203

Whoogle Search is a self-hosted metasearch engine. In versions prior to 0.8.4, the `element` method in `app/routes.py` does not validate the user-con…

Fix: 0.8.4+
Fix from $2,300 2024-01-23
Whoogle Search CRITICAL 9.8
CVE-2024-22205

Whoogle Search is a self-hosted metasearch engine. In versions 0.8.3 and prior, the `window` endpoint does not sanitize user-supplied input from the …

Fix: 0.8.4+
Fix from $2,300 2024-01-23
Admin Css Mu CRITICAL 9.8
CVE-2022-40700

Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Managemen…

Fix: after 6.0.1
Fix from $2,300 2024-01-19
Maximo Application Suite MEDIUM 5.4
CVE-2023-32337

IBM Maximo Spatial Asset Management 8.10 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauth…

Fix: 8.10.6+
Fix from $1,600 2024-01-19
Zhihuiyun CRITICAL 9.8
CVE-2024-0649

A vulnerability was found in ZhiHuiYun up to 4.4.13 and classified as critical. This issue affects the function download_network_image of the file /a…

Fix: after 4.4.13
Fix from $2,300 2024-01-17
Shopware HIGH 8.1
CVE-2024-22408

Shopware is an open headless commerce platform. The implemented Flow Builder functionality in the Shopware application does not adequately validate t…

Fix: 6.5.7.4+
Fix from $1,950 2024-01-16
Austin MEDIUM 6.5
CVE-2024-0601

A vulnerability was found in ZhongFuCheng3y Austin 1.0. It has been rated as critical. Affected by this issue is the function getRemoteUrl2File of th…

No fix yet
Fix from $1,600 2024-01-16
Jsm File Get Contents\(\) Shortcode HIGH 8.8
CVE-2023-6991

The JSM file_get_contents() Shortcode WordPress plugin before 2.7.1 does not validate one of its shortcode's parameters before making a request to it…

Fix: 2.7.1+
Fix from $1,950 2024-01-15
Yiqiniu CRITICAL 9.8
CVE-2024-0510

A vulnerability, which was classified as critical, has been found in HaoKeKeJi YiQiNiu up to 3.1. Affected by this issue is the function http_post of…

Fix: after 3.1
Fix from $2,300 2024-01-13
Forest HIGH 7.5
CVE-2023-51804

An issue in rymcu forest v.0.02 allows a remote attacker to obtain sensitive information via manipulation of the HTTP body URL in the com.rymcu.fores…

Patch available
Fix from $1,950 2024-01-13
Bar Assistant HIGH 8.8
CVE-2023-49471

Blind Server-Side Request Forgery (SSRF) vulnerability in karlomikus Bar Assistant before version 3.2.0 does not validate a parameter before making a…

Fix: 3.2.0+
Fix from $1,950 2024-01-10
Inis HIGH 8.8
CVE-2024-0308

A vulnerability was found in Inis up to 2.0.1. It has been rated as critical. This issue affects some unknown processing of the file app/api/controll…

Fix: after 2.0.1
Fix from $1,950 2024-01-08
Youke 365 CRITICAL 9.8
CVE-2024-0303

A vulnerability, which was classified as critical, was found in Youke365 up to 1.5.3. Affected is an unknown function of the file /app/api/controller…

Fix: after 1.5.3
Fix from $2,300 2024-01-08
Youke 365 CRITICAL 9.8
CVE-2024-0304

A vulnerability has been found in Youke365 up to 1.5.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Fix: after 1.5.3
Fix from $2,300 2024-01-08
Axis HIGH 7.2
CVE-2023-51441

** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Axis allowed users with access to the admin service to perform poss…

Fix: after 1.3
Fix from $1,950 2024-01-06
D Tale HIGH 7.5
CVE-2024-21642

D-Tale is a visualizer for Pandas data structures. Users hosting versions D-Tale prior to 3.9.0 publicly can be vulnerable to server-side request for…

Fix: 3.9.0+
Fix from $1,950 2024-01-05
Happy Addons For Elementor MEDIUM 6.5
CVE-2023-51676

Server-Side Request Forgery (SSRF) vulnerability in Leevio Happy Addons for Elementor.This issue affects Happy Addons for Elementor: from n/a through…

Fix: after 3.9.1.1
Fix from $1,600 2023-12-29
Miniflare HIGH 8.1
CVE-2023-7078

Sending specially crafted HTTP requests to Miniflare's server could result in arbitrary HTTP and WebSocket requests being sent from the server. If Mi…

Fix: 3.20231030.2+
Fix from $1,950 2023-12-29
Audiobookshelf HIGH 7.5
CVE-2023-51665

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenticated blind server-side reque…

Fix: 2.7.0+
Fix from $1,950 2023-12-27
Audiobookshelf HIGH 7.5
CVE-2023-51697

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenticated blind server-side reque…

Fix: 2.7.0+
Fix from $1,950 2023-12-27
Ofbiz CRITICAL 9.8
CVE-2023-51467EPSS 96%

The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code

Fix: 18.12.11+
Fix from $2,300 2023-12-26