Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Hub MEDIUM 5.3
CVE-2023-45822

Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for CNCF projects. During a secu…

Fix: 1.16.0+
Fix from $1,600 2023-10-19
Shenyu MEDIUM 6.5
CVE-2023-25753

There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint. This vulnerability allows us to manip…

Mitigation only
Fix from $1,600 2023-10-19
Langchain HIGH 8.8
CVE-2023-46229EPSS 45%

LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal…

Fix: 0.0.317+
Fix from $1,950 2023-10-19
Vrite CRITICAL 9.8
CVE-2023-5572

Server-Side Request Forgery (SSRF) in GitHub repository vriteio/vrite prior to 0.3.0.

Fix: 0.3.0+
Fix from $2,300 2023-10-13
Commerce MEDIUM 6.8
CVE-2023-26366

Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by a Server…

Mitigation only
Fix from $1,600 2023-10-13
Skype For Business Server MEDIUM 5.3
CVE-2023-41763 KEVEPSS 90%

Skype for Business Elevation of Privilege Vulnerability

Patch available
Fix from $1,600 2023-10-10
Netweaver Application Server Java MEDIUM 6.5
CVE-2023-42477

SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a crafted request from a vulnerable web application, ca…

No fix yet
Fix from $1,600 2023-10-10
Ucrypt MEDIUM 6.5
CVE-2023-39854

The web interface of ATX Ucrypt through 3.5 allows authenticated users (or attackers using default credentials for the admin, master, or user account…

Fix: after 3.5
Fix from $1,600 2023-10-09
Senayan Library Management System HIGH 8.8
CVE-2023-3744

Server-Side Request Forgery vulnerability in SLims version 9.6.0. This vulnerability could allow an authenticated attacker to send requests to intern…

Mitigation only
Fix from $1,950 2023-10-02
Torchserve CRITICAL 9.8
CVE-2023-43654EPSS 35%

TorchServe is a tool for serving and scaling PyTorch models in production. TorchServe default configuration lacks proper input validation, enabling t…

Fix: 0.8.2+
Fix from $2,300 2023-09-28
Ajaxnewsticker CRITICAL 9.8
CVE-2023-41449

An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter.

Mitigation only
Fix from $2,300 2023-09-27
Mastodon HIGH 7.5
CVE-2023-42450

Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 4.2.0-beta1 and prior to version 4.2.0-rc2, by crafti…

Patch available
Fix from $1,950 2023-09-19
Dropbox Folder Share HIGH 7.2
CVE-2023-3025

The Dropbox Folder Share plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.9.7 via the 'link' par…

Fix: after 1.9.7
Fix from $1,950 2023-09-16
Geonode MEDIUM 6.5
CVE-2023-42439

GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. A SSRF vulnerability exists star…

Fix: 4.1.3+
Fix from $1,600 2023-09-15
Zzcms CRITICAL 9.8
CVE-2023-42398

An issue in zzCMS v.2023 allows a remote attacker to execute arbitrary code and obtain sensitive information via the ueditor component in controller.…

No fix yet
Fix from $2,300 2023-09-15
Crayon Syntax Highlighter MEDIUM 5.4
CVE-2023-4893

The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Server Side Request Forgery via the 'crayon' shortcode in versions up to, and inc…

Fix: after 2.8.4
Fix from $1,600 2023-09-12
Instantcms MEDIUM 5.4
CVE-2023-4878

Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

Fix: 2.16.1+
Fix from $1,600 2023-09-10
Studio MEDIUM 5.4
CVE-2023-41327

WireMock is a tool for mocking HTTP services. WireMock can be configured to only permit proxying (and therefore recording) to certain addresses. This…

Fix: 2.35.1 / 3.0.3+
Fix from $1,600 2023-09-06
Studio CRITICAL 10.0
CVE-2023-39967

WireMock is a tool for mocking HTTP services. When certain request URLs like “@127.0.0.1:1234" are used in WireMock Studio configuration fields, the …

Fix: after 2.32.0-17
Fix from $2,300 2023-09-06
Bitbucket Push And Pull Request HIGH 7.5
CVE-2023-41937

Jenkins Bitbucket Push and Pull Request Plugin 2.4.0 through 2.8.3 (both inclusive) trusts values provided in the webhook payload, including certain …

Fix: after 2.8.3
Fix from $1,950 2023-09-06
Superset MEDIUM 5.4
CVE-2023-36388

Improper REST API permission in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma users to test network connections, possib…

Fix: after 2.1.0
Fix from $1,600 2023-09-06
Librey HIGH 7.5
CVE-2023-41055

LibreY is a fork of LibreX, a framework-less and javascript-free privacy respecting meta search engine. LibreY is subject to a Server-Side Request Fo…

Fix: 2023-08-17+
Fix from $1,950 2023-09-04
Librey CRITICAL 9.1
CVE-2023-41054

LibreY is a fork of LibreX, a framework-less and javascript-free privacy respecting meta search engine. LibreY is subject to a Server-Side Request Fo…

Fix: 2023-08-29+
Fix from $2,300 2023-09-04
Nebulagraph Studio HIGH 7.5
CVE-2023-36088

Server Side Request Forgery (SSRF) vulnerability in NebulaGraph Studio version 3.7.0, allows remote attackers to gain sensitive information.

No fix yet
Fix from $1,950 2023-09-01
Senayan Library Management System MEDIUM 6.1
CVE-2023-40969

Senayan Library Management Systems SLIMS 9 Bulian v9.6.1 is vulnerable to Server Side Request Forgery (SSRF) via admin/modules/bibliography/pop_p2p.p…

No fix yet
Fix from $1,600 2023-09-01
Instantcms MEDIUM 5.4
CVE-2023-4651

Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1.

Fix: 2.16.1+
Fix from $1,600 2023-08-31
Geonode HIGH 7.5
CVE-2023-40017

GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. In versions 3.2.0 through 4.1.2,…

Fix: after 4.1.2
Fix from $1,950 2023-08-24
Airflow HIGH 8.1
CVE-2023-37379

Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection ed…

Fix: 2.7.0+
Fix from $1,950 2023-08-23
Edgeconnect Sd Wan Orchestrator MEDIUM 5.3
CVE-2023-37440

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to conduct a …

Fix: 9.3.1+
Fix from $1,600 2023-08-22
Pandora Fms MEDIUM 6.5
CVE-2023-24515

Server-Side Request Forgery (SSRF) vulnerability in API checker of Pandora FMS. Application does not have a check on the URL scheme used while retrie…

Fix: after 767
Fix from $1,600 2023-08-22