Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Nextcloud Server CRITICAL 9.8
CVE-2023-48306

Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.11, 26.0.6…

Fix: 22.2.10.16 / 23.0.12.11+
Fix from $2,300 2023-11-21
Mail CRITICAL 9.8
CVE-2023-48307

Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Starting in version 1.13.0 and prior to version 2.2.8 and 3.3.0, a…

Fix: 2.2.8 / 3.3.0+
Fix from $2,300 2023-11-21
Bookstack MEDIUM 6.5
CVE-2023-6199

Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF.

No fix yet
Fix from $1,600 2023-11-20
Xwiki HIGH 8.8
CVE-2023-48240

XWiki Platform is a generic wiki platform. The rendered diff in XWiki embeds images to be able to compare the contents and not display a difference f…

Fix: 14.10.15 / 15.5.1+
Fix from $1,950 2023-11-20
Publiccms MEDIUM 6.5
CVE-2023-48204

An issue in PublicCMS v.4.0.202302.e allows a remote attacker to obtain sensitive information via the appToken and Parameters parameter of the api/me…

No fix yet
Fix from $1,600 2023-11-16
Powerpress MEDIUM 6.5
CVE-2023-41239

Server-Side Request Forgery (SSRF) vulnerability in Blubrry PowerPress Podcasting plugin by Blubrry.This issue affects PowerPress Podcasting plugin b…

Fix: after 11.0.6
Fix from $1,600 2023-11-13
Motors Car Dealer\, Classifieds \& Listing HIGH 7.5
CVE-2023-46207

Server-Side Request Forgery (SSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing.This issue affects Motors – Car Dealer,…

Fix: after 1.4.6
Fix from $1,950 2023-11-13
Shortcodes Ultimate MEDIUM 6.5
CVE-2023-23800

Server-Side Request Forgery (SSRF) vulnerability in Vova Anokhin WP Shortcodes Plugin — Shortcodes Ultimate.This issue affects WP Shortcodes Plugin —…

Fix: after 5.12.6
Fix from $1,600 2023-11-13
Poll Maker HIGH 7.5
CVE-2023-34013

Server-Side Request Forgery (SSRF) vulnerability in Poll Maker Team Poll Maker – Best WordPress Poll Plugin.This issue affects Poll Maker – Best Word…

Fix: after 4.6.2
Fix from $1,950 2023-11-13
Phonepe HIGH 7.5
CVE-2022-45835EPSS 38%

Server-Side Request Forgery (SSRF) vulnerability in PhonePe PhonePe Payment Solutions.This issue affects PhonePe Payment Solutions: from n/a through …

Fix: after 1.0.15
Fix from $1,950 2023-11-13
Wpgraphql MEDIUM 6.5
CVE-2023-23684

Server-Side Request Forgery (SSRF) vulnerability in WPGraphQL.This issue affects WPGraphQL: from n/a through 1.14.5.

Fix: after 1.14.5
Fix from $1,600 2023-11-13
Discourse CRITICAL 9.8
CVE-2023-47121

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` an…

Fix: 3.1.3 / 3.2.0+
Fix from $2,300 2023-11-10
Sentry Software Development Kit MEDIUM 6.1
CVE-2023-46729

sentry-javascript provides Sentry SDKs for JavaScript. An unsanitized input of Next.js SDK tunnel endpoint allows sending HTTP requests to arbitrary …

Fix: 7.77.0+
Fix from $1,600 2023-11-10
Better Pdf Exporter HIGH 7.8
CVE-2023-42361

Local File Inclusion vulnerability in Midori-global Better PDF Exporter for Jira Server and Jira Data Center v.10.3.0 and before allows an attacker t…

Fix: 11.0.0+
Fix from $1,950 2023-11-07
Group Office HIGH 8.8
CVE-2023-46730

Group-Office is an enterprise CRM and groupware tool. In affected versions there is full Server-Side Request Forgery (SSRF) vulnerability in the /api…

Fix: 6.6.177 / 6.7.54+
Fix from $1,950 2023-11-07
Apiserver HIGH 8.2
CVE-2022-3172

A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to t…

Fix: 1.22.14 / 1.23.11+
Fix from $1,950 2023-11-03
Manageengine Desktop Central HIGH 8.8
CVE-2023-4769

A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfig.do component. This vulnerab…

Mitigation only
Fix from $1,950 2023-11-03
Socialfeed Photos \& Video Using Instagram Api CRITICAL 9.8
CVE-2023-43982

Bon Presta boninstagramcarousel between v5.2.1 to v7.0.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at inst…

Fix: 7.0.0+
Fix from $2,300 2023-11-03
Content Navigator MEDIUM 5.4
CVE-2023-35896

IBM Content Navigator 3.0.13 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized reque…

Patch available
Fix from $1,600 2023-11-03
Foodcoopshop HIGH 7.5
CVE-2023-46725

FoodCoopShop is open source software for food coops and local shops. Versions starting with 3.2.0 prior to 3.6.1 are vulnerable to server-side reques…

Fix: after 3.6.0
Fix from $1,950 2023-11-02
Fogproject HIGH 7.5
CVE-2023-46236

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10, a server-side-request-forgery (SSRF) vul…

Fix: 1.5.10+
Fix from $1,950 2023-10-31
Bigbluebutton MEDIUM 5.4
CVE-2023-43798

BigBlueButton is an open-source virtual classroom. BigBlueButton prior to versions 2.6.12 and 2.7.0-rc.1 is vulnerable to Server-Side Request Forgery…

Fix: 2.6.12+
Fix from $1,600 2023-10-30
Opencrx CRITICAL 9.8
CVE-2023-46502

An issue in openCRX v.5.2.2 allows a remote attacker to read internal files and execute server side request forgery attack via insecure DocumentBuild…

Patch available
Fix from $2,300 2023-10-30
Fides HIGH 7.2
CVE-2023-46124

Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in runtime environments, and the enforceme…

Fix: 2.22.1+
Fix from $1,950 2023-10-25
Geoserver CRITICAL 9.8
CVE-2023-43795EPSS 68%

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The OGC Web Processing Service (WPS)…

Fix: 2.22.5 / 2.23.2+
Fix from $2,300 2023-10-25
Geoserver MEDIUM 5.3
CVE-2023-41339

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The WMS specification defines an ``s…

Fix: 2.22.5 / 2.23.2+
Fix from $1,600 2023-10-25
Remark42 HIGH 7.5
CVE-2023-45966

umputun remark42 version 1.12.1 and before has a Blind Server-Side Request Forgery (SSRF) vulnerability.

Fix: after 1.12.1
Fix from $1,950 2023-10-23
Calibre HIGH 7.5
CVE-2023-46303

link_to_local_path in ebooks/conversion/plugins/html_input.py in calibre before 6.19.0 can, by default, add resources outside of the document root.

Fix: 6.19.0+
Fix from $1,950 2023-10-22
Fortianalyzer MEDIUM 6.5
CVE-2023-44256

A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 and Forti…

Fix: after 7.2.3
Fix from $1,600 2023-10-20
Home Assistant HIGH 7.2
CVE-2023-41899

Home assistant is an open source home automation. In affected versions the `hassio.addon_stdin` is vulnerable to a partial Server-Side Request Forger…

Fix: 2023.9.0+
Fix from $1,950 2023-10-19