Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Ofbiz HIGH 7.5
CVE-2023-50968EPSS 63%

Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations. Th…

Fix: 18.12.11+
Fix from $1,950 2023-12-26
Mindsdb CRITICAL 9.1
CVE-2023-50731

MindsDB is a SQL Server for artificial intelligence. Prior to version 23.11.4.1, the `put` method in `mindsdb/mindsdb/api/http/namespaces/file.py` do…

Fix: 23.11.4.1+
Fix from $2,300 2023-12-22
Yii2 Authclient HIGH 8.8
CVE-2023-50714

yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to v…

Fix: 2.2.15+
Fix from $1,950 2023-12-22
Medusa MEDIUM 5.3
CVE-2023-50258

Medusa is an automatic video library manager for TV shows. Versions prior to 1.0.19 are vulnerable to unauthenticated blind server-side request forge…

Fix: 1.0.19+
Fix from $1,600 2023-12-22
Medusa MEDIUM 5.3
CVE-2023-50259

Medusa is an automatic video library manager for TV shows. Versions prior to 1.0.19 are vulnerable to unauthenticated blind server-side request forge…

Fix: 1.0.19+
Fix from $1,600 2023-12-22
Automad HIGH 8.8
CVE-2023-7037

A vulnerability was found in automad up to 1.10.9. It has been declared as critical. This vulnerability affects the function import of the file FileC…

Fix: after 1.10.9
Fix from $1,950 2023-12-21
Mlflow CRITICAL 9.8
CVE-2023-6974

A malicious user could use this issue to access internal HTTP(s) servers and in the worst case (ie: aws instance) it could be abuse to get a remote c…

Fix: 2.9.2+
Fix from $2,300 2023-12-20
Avalanche HIGH 7.5
CVE-2023-46262EPSS 83%

An unauthenticated attacked could send a specifically crafted web request causing a Server-Side Request Forgery (SSRF) in Ivanti Avalanche Remote Con…

Fix: after 6.4.1
Fix from $1,950 2023-12-19
Givewp MEDIUM 6.5
CVE-2022-40312

Server-Side Request Forgery (SSRF) vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform.This issue affects GiveWP – Donation Plu…

Fix: after 2.25.1
Fix from $1,600 2023-12-18
Kodexplorer CRITICAL 9.8
CVE-2023-6852

A vulnerability classified as critical has been found in kalcaddle KodExplorer up to 4.51.03. Affected is an unknown function of the file plugins/web…

Fix: 4.52.01+
Fix from $2,300 2023-12-16
Kodexplorer CRITICAL 9.8
CVE-2023-6853

A vulnerability classified as critical was found in kalcaddle KodExplorer up to 4.51.03. Affected by this vulnerability is the function index of the …

Fix: 4.52.01+
Fix from $2,300 2023-12-16
Kodbox CRITICAL 9.8
CVE-2023-6849

A vulnerability was found in kalcaddle kodbox up to 1.48. It has been rated as critical. Affected by this issue is the function cover of the file plu…

Fix: 1.48.04+
Fix from $2,300 2023-12-16
Bazarr MEDIUM 5.3
CVE-2023-50266

Bazarr manages and downloads subtitles. In version 1.2.4, the proxy method in bazarr/bazarr/app/ui.py does not validate the user-controlled protocol …

Patch available
Fix from $1,600 2023-12-15
Commentluv HIGH 7.5
CVE-2023-49159

Server-Side Request Forgery (SSRF) vulnerability in Elegant Digital Solutions CommentLuv.This issue affects CommentLuv: from n/a through 3.0.4.

Fix: after 3.0.4
Fix from $1,950 2023-12-15
Mail Sqr Expert MEDIUM 5.3
CVE-2023-48379

Softnext Mail SQR Expert is an email management platform, it has inadequate filtering for a specific URL parameter within a specific function. An una…

Fix: after 230330
Fix from $1,600 2023-12-15
Kubeflow MEDIUM 6.5
CVE-2023-6570

Server-Side Request Forgery (SSRF) in kubeflow/kubeflow

No fix yet
Fix from $1,600 2023-12-14
Jcdashboard CRITICAL 9.8
CVE-2023-40630

Unauthenticated LFI/SSRF in JCDashboards component for Joomla.

Fix: after 1.1.30
Fix from $2,300 2023-12-14
Audiobookshelf MEDIUM 6.5
CVE-2023-47619

Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, users with the update permission are able to read arbitrar…

Fix: after 2.4.3
Fix from $1,600 2023-12-13
Mindsdb MEDIUM 5.3
CVE-2023-49795

MindsDB connects artificial intelligence models to real time data. Versions prior to 23.11.4.1 contain a server-side request forgery vulnerability in…

Fix: 23.11.4.1+
Fix from $1,600 2023-12-11
Nuxt Api Party HIGH 7.5
CVE-2023-49799

`nuxt-api-party` is an open source module to proxy API requests. nuxt-api-party attempts to check if the user has passed an absolute URL to prevent t…

Fix: after 0.21.3
Fix from $1,950 2023-12-09
12 Step Meeting List MEDIUM 5.4
CVE-2023-46641

Server-Side Request Forgery (SSRF) vulnerability in Code for Recovery 12 Step Meeting List.This issue affects 12 Step Meeting List: from n/a through …

Fix: 3.14.25+
Fix from $1,600 2023-12-07
Payment Gateway MEDIUM 6.5
CVE-2022-45362EPSS 42%

Server-Side Request Forgery (SSRF) vulnerability in Paytm Paytm Payment Gateway.This issue affects Paytm Payment Gateway: from n/a through 2.7.0.

Fix: after 2.7.0
Fix from $1,600 2023-12-07
Starter Templates MEDIUM 5.4
CVE-2023-41804

Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates.This issue a…

Fix: 3.2.5+
Fix from $1,600 2023-12-07
Espocrm MEDIUM 6.5
CVE-2023-46736

EspoCRM is an Open Source CRM (Customer Relationship Management) software. In affected versions there is Server-Side Request Forgery (SSRF) vulnerabi…

Fix: after 8.0.2
Fix from $1,600 2023-12-05
Microcks CRITICAL 9.8
CVE-2023-48910

Microcks up to 1.17.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download. This vulnerabili…

Fix: after 1.17.1
Fix from $2,300 2023-12-04
Ray CRITICAL 9.1
CVE-2023-48023EPSS 35%

Anyscale Ray 2.6.3 and 2.8.0 allows /log_proxy SSRF. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its docu…

No fix yet
Fix from $2,300 2023-11-28
Ray CRITICAL 9.8
CVE-2023-48022EPSS 84%

Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the vendor's position is that this …

No fix yet
Fix from $2,300 2023-11-28
Owncast CRITICAL 9.8
CVE-2023-46480

An issue in OwnCast v.0.1.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the authHost parameter of the ind…

Mitigation only
Fix from $2,300 2023-11-27
Wpb Show Core CRITICAL 9.8
CVE-2023-5974

The WPB Show Core WordPress plugin through 2.2 is vulnerable to server-side request forgery (SSRF) via the `path` parameter.

Fix: after 2.2
Fix from $2,300 2023-11-27
Instant Images HIGH 8.8
CVE-2023-27451

Server-Side Request Forgery (SSRF) vulnerability in Darren Cooney Instant Images plugin <= 5.1.0.2 versions.

Fix: after 5.1.0.2
Fix from $1,950 2023-11-22