Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 6.4 CVE-2025-22726 Server-Side Request Forgery (SSRF) vulnerability in _nK nK Themes Helper nk-themes-helper allows Server Side Request Forgery.This issue affects nK Th… Mitigation only Fix from $1,6002026-01-08 MEDIUM 5.3 CVE-2026-21859 Mailpit is an email testing tool and API for developers. Versions 1.28.0 and below have a Server-Side Request Forgery (SSRF) vulnerability in the /pr… Mailpit 1.28.1+ Fix from $1,6002026-01-08 MEDIUM 5.3 CVE-2019-25290 Smartliving SmartLAN/G/SI <=6.x contains an unauthenticated server-side request forgery vulnerability in the GetImage functionality through the 'host… No fix yet Fix from $1,6002026-01-08 HIGH 8.1 CVE-2025-69222 LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 is prone to a server-side request forgery (SSRF) vulnerability due to missin… Librechat Patch available Fix from $1,9502026-01-07 MEDIUM 6.5 CVE-2025-58441 Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, there is a blind server-side request forgery vulnerabil… Knowage 8.1.37+ Fix from $1,6002026-01-07 MEDIUM 6.4 CVE-2025-14438 The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.1.0.30 via t… Mitigation only Fix from $1,6002026-01-06 MEDIUM 6.8 CVE-2025-68437 Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, the Craft CMS GraphQL `save… Craft Cms 4.16.17 / 5.8.21+ Fix from $1,6002026-01-05 MEDIUM 6.6 CVE-2025-61916 Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3.0 are vulnerable to server-si… Spinnaker 2025.1.6 / 2025.2.3+ Fix from $1,6002026-01-05 MEDIUM 6.5 CVE-2025-67427 A Blind Server-Side Request Forgery (SSRF) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to force the server to initiate… Evershop after 2.1.0 Fix from $1,6002026-01-05 HIGH 7.7 CVE-2026-21433 Emlog is an open source website building system. Versions up to and including 2.5.19 are vulnerable to server-side Out-of-Band (OOB) requests / SSRF … Emlog after 2.5.19 Fix from $1,9502026-01-02 MEDIUM 6.4 CVE-2025-14627 The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and … Mitigation only Fix from $1,6002026-01-01 HIGH 7.5 CVE-2025-34469 Cowrie versions prior to 2.9.0 contain a server-side request forgery (SSRF) vulnerability in the emulated shell implementation of wget and curl. In t… Cowrie 2.9.0+ Fix from $1,9502025-12-31 MEDIUM 5.4 CVE-2025-62088 Server-Side Request Forgery (SSRF) vulnerability in extendons WordPress & WooCommerce Scraper Plugin, Import Data from Any Site wp_scraper allows Ser… Mitigation only Fix from $1,6002025-12-31 HIGH 7.3 CVE-2025-15264 A vulnerability was determined in FeehiCMS up to 2.1.1. Impacted is an unknown function of the file frontend/web/timthumb.php of the component TimThu… Feehicms after 2.1.1 Fix from $1,9502025-12-30 CRITICAL 9.1 CVE-2024-25181 A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSRF) and arbitrary file reading… Vvvebjs after 1.7.4 Fix from $2,3002025-12-29 MEDIUM 6.3 CVE-2025-15098 A vulnerability was determined in YunaiV yudao-cloud up to 2025.11. This affects the function BpmHttpCallbackTrigger/BpmSyncHttpRequestTrigger of the… Mitigation only Fix from $1,6002025-12-26 MEDIUM 6.5 CVE-2019-25251 Teradek VidiU Pro 3.0.3 contains a server-side request forgery vulnerability in the management interface that allows attackers to manipulate GET para… Vidiu Pro Firmware No fix yet Fix from $1,6002025-12-24 MEDIUM 5.4 CVE-2025-67623 Server-Side Request Forgery (SSRF) vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Server Side Request Forgery.This issue affects … Mitigation only Fix from $1,6002025-12-24 HIGH 8.2 CVE-2025-68696 httparty is an API tool. In versions 0.23.2 and prior, httparty is vulnerable to SSRF. This issue can pose a risk of leaking API keys, and it can als… Httparty 0.24.0+ Fix from $1,9502025-12-23 MEDIUM 6.5 CVE-2025-67743 Local Deep Research is an AI-powered research assistant for deep, iterative research. In versions from 1.3.0 to before 1.3.9, the download service (d… Local Deep Research 1.3.9+ Fix from $1,6002025-12-23 MEDIUM 5.3 CVE-2021-47715 Hasura GraphQL 1.3.3 contains a server-side request forgery vulnerability that allows attackers to inject arbitrary remote schema URLs through the ad… Graphql Engine No fix yet Fix from $1,6002025-12-22 MEDIUM 6.5 CVE-2025-68477EPSS 6% Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, Langflow provides an API Request component tha… Langflow 1.7.0+ Fix from $1,6002025-12-19 HIGH 7.2 CVE-2025-13999 The HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all ve… Mitigation only Fix from $1,9502025-12-19 HIGH 8.8 CVE-2025-64663 Custom Question Answering Elevation of Privilege Vulnerability Azure Language No fix yet Fix from $1,9502025-12-18 HIGH 8.7 CVE-2025-34452EPSS 5% Streama versions 1.10.0 through 1.10.5 and prior to commit b7c8767 contain a combination of path traversal and server-side request forgery (SSRF) vul… Patch available Fix from $1,9502025-12-18 MEDIUM 6.5 CVE-2025-68150 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.2 and 9.1.1-alpha.1, th… Parse Server 8.6.2+ Fix from $1,6002025-12-16 HIGH 7.5 CVE-2025-52196 Server-Side Request Forgery (SSRF) vulnerability in Ctera Portal 8.1.x (8.1.1417.24) allows remote attackers to induce the server to make arbitrary H… Ctera Mitigation only Fix from $1,9502025-12-16 CRITICAL 9.8 CVE-2023-53899 PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in the episode upload form. Att… Podcast Generator Mitigation only Fix from $2,3002025-12-16 MEDIUM 6.4 CVE-2025-14443 A flaw was found in ose-openshift-apiserver. This vulnerability allows internal network enumeration, service discovery, limited information disclosur… Mitigation only Fix from $1,6002025-12-16 MEDIUM 5.4 CVE-2025-67989 Server-Side Request Forgery (SSRF) vulnerability in LMPixels Kerge kerge allows Server Side Request Forgery.This issue affects Kerge: from n/a throug… No fix yet Fix from $1,6002025-12-16