Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Owncast MEDIUM 6.5
CVE-2023-3188

Server-Side Request Forgery (SSRF) in GitHub repository owncast/owncast prior to 0.1.0.

Fix: 0.1.0+
Fix from $1,600 2023-06-10
Wpforo Forum HIGH 8.8
CVE-2023-2249EPSS 61%

The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, a…

Fix: after 2.1.7
Fix from $1,950 2023-06-09
Getwid CRITICAL 9.6
CVE-2023-1895

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Server Side Request Forgery via the get_remote_content REST API endpoint in versi…

Fix: after 1.8.3
Fix from $2,300 2023-06-09
Cells MEDIUM 6.5
CVE-2023-32750

Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the background. Th…

Fix: 3.0.12 / 4.1.3+
Fix from $1,600 2023-06-08
Chamilo Lms MEDIUM 5.3
CVE-2023-34959

An issue in Chamilo v1.11.* up to v1.11.18 allows attackers to execute a Server-Side Request Forgery (SSRF) and obtain information on the services ru…

Fix: after 1.11.18
Fix from $1,600 2023-06-08
Synapse MEDIUM 5.4
CVE-2023-32683

Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. A discovered oEmbed or image URL can bypass the `url_preview_ur…

Fix: 1.85.0+
Fix from $1,600 2023-06-06
Advanced Secure Gateway HIGH 8.1
CVE-2023-23955

Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Server-Side Request Forgery vulnerability.

Fix: 3.1.6.0 / 7.3.13.1+
Fix from $1,950 2023-06-01
Vip Video Analysis CRITICAL 9.8
CVE-2023-3015

A vulnerability has been found in yiwent Vip Video Analysis 1.0 and classified as critical. Affected by this vulnerability is an unknown functionalit…

Mitigation only
Fix from $2,300 2023-05-31
Jizhicms CRITICAL 9.8
CVE-2023-2927

A vulnerability was found in JIZHICMS 2.4.5. It has been classified as critical. Affected is the function index of the file TemplateController.php. T…

No fix yet
Fix from $2,300 2023-05-27
Mail MEDIUM 5.3
CVE-2023-33184

Nextcloud Mail is a mail app in Nextcloud. A blind SSRF attack allowed to send GET requests to services running in the same web server. It is recomme…

Fix: 1.15.3 / 2.2.5+
Fix from $1,600 2023-05-27
Remote Management System MEDIUM 5.8
CVE-2023-32348

Teltonika’s Remote Management System versions prior to 4.10.0 contain a virtual private network (VPN) hub feature for cross-device communication that…

Fix: 4.10.0+
Fix from $1,600 2023-05-22
Davinci HIGH 8.8
CVE-2023-31848

davinci 0.3.0-rc is vulnerable to Server-side request forgery (SSRF).

No fix yet
Fix from $1,950 2023-05-17
Pdfocus MEDIUM 6.5
CVE-2023-23169

Synapsoft pdfocus 1.17 is vulnerable to local file inclusion and server-side request forgery Directory Traversal.

No fix yet
Fix from $1,600 2023-05-12
My Cloud Os MEDIUM 5.5
CVE-2022-29840

Server-Side Request Forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL to point back to the loopback…

Fix: 5.26.202+
Fix from $1,600 2023-05-10
Windows 10 1507 MEDIUM 6.5
CVE-2023-24954

Microsoft SharePoint Server Information Disclosure Vulnerability

Fix: 10.0.10240.19926 / 10.0.14393.5921+
Fix from $1,600 2023-05-09
Imgproxy MEDIUM 5.3
CVE-2023-30019

imgproxy <=3.14.0 is vulnerable to Server-Side Request Forgery (SSRF) due to a lack of sanitization of the imageURL parameter.

Fix: after 3.14.0
Fix from $1,600 2023-05-08
Watson Machine Learning On Cloud Pak For Data MEDIUM 6.5
CVE-2023-30444

IBM Watson Machine Learning on Cloud Pak for Data 4.0 and 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated at…

Patch available
Fix from $1,600 2023-04-27
Blackbox Exporter HIGH 7.5
CVE-2023-26735

blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface. This vulnerability allows attackers to detect int…

Mitigation only
Fix from $1,950 2023-04-26
Hub CRITICAL 9.8
CVE-2022-48477

In JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing

Fix: 2023.1.15725+
Fix from $2,300 2023-04-24
Delmia Apriso HIGH 7.5
CVE-2023-2140

A Server-Side Request Forgery vulnerability in DELMIA Apriso Release 2017 through Release 2022 could allow an unauthenticated attacker to issue re…

Fix: after 2022
Fix from $1,950 2023-04-21
Superset MEDIUM 6.5
CVE-2023-25504

A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import dataset feature in order to condu…

Fix: after 2.0.1
Fix from $1,600 2023-04-17
GitLab CRITICAL 9.8
CVE-2018-17452

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Sid…

Fix: 11.1.7 / 11.2.4+
Fix from $2,300 2023-04-15
Sharepoint Foundation HIGH 8.1
CVE-2023-28288EPSS 6%

Microsoft SharePoint Server Spoofing Vulnerability

Patch available
Fix from $1,950 2023-04-11
Sveltekit HIGH 8.8
CVE-2023-29008

The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+server.js` file, containing endpoint han…

Fix: 1.15.2+
Fix from $1,950 2023-04-06
Budibase MEDIUM 6.5
CVE-2023-29010

Budibase is a low code platform for creating internal tools, workflows, and admin panels. Versions prior to 2.4.3 (07 March 2023) are vulnerable to S…

Fix: 2.4.3+
Fix from $1,600 2023-04-06
Glpi MEDIUM 5.4
CVE-2023-28633

GLPI is a free asset and IT management software package. Starting in version 0.84 and prior to versions 9.5.13 and 10.0.7, usage of RSS feeds is subj…

Fix: 9.5.13 / 10.0.7+
Fix from $1,600 2023-04-05
Openapi Generator CRITICAL 9.1
CVE-2023-27162

openapi-generator up to v6.4.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/gen/clients/{language}. This vul…

Fix: after 6.4.0
Fix from $2,300 2023-03-31
Request Baskets MEDIUM 6.5
CVE-2023-27163EPSS 7%

request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This vulnerability…

Fix: after 1.2.1
Fix from $1,600 2023-03-31
Appwrite HIGH 7.5
CVE-2023-27159EPSS 36%

Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This vulnerability allows…

Fix: after 1.2.1
Fix from $1,950 2023-03-31
Forem HIGH 7.2
CVE-2023-27160

forem up to v2022.11.11 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /articles/{id}. This vulnerability allows at…

Fix: after 2022.11.11
Fix from $1,950 2023-03-31