Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 5.0 CVE-2025-66407 Weblate is a web based localization tool. The Create Component functionality in Weblate allows authorized users to add new translation components by … Weblate 5.15+ Fix from $1,6002025-12-16 MEDIUM 6.5 CVE-2023-53893 Ateme TITAN File 3.9.12.4 contains an authenticated server-side request forgery vulnerability in the job callback URL parameter that allows attackers… Titan File No fix yet Fix from $1,6002025-12-15 CRITICAL 9.1 CVE-2025-66844 In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the con… Grav 1.7.49.5+ Fix from $2,3002025-12-15 MEDIUM 5.8 CVE-2025-13281 A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vu… Mitigation only Fix from $1,6002025-12-14 CRITICAL 9.8 CVE-2025-14518 A vulnerability was identified in PowerJob up to 5.1.2. This vulnerability affects the function checkConnectivity of the file src/main/java/tech/powe… Powerjob after 5.1.2 Fix from $2,3002025-12-11 HIGH 8.8 CVE-2025-14516 A vulnerability was found in Yalantis uCrop 2.2.11. Affected by this issue is the function downloadFile of the file com.yalantis.ucrop.task.BitmapLoa… Ucrop No fix yet Fix from $1,9502025-12-11 MEDIUM 5.8 CVE-2025-11467 The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-S… Mitigation only Fix from $1,6002025-12-11 HIGH 7.5 CVE-2025-65512 A Server-Side Request Forgery (SSRF) vulnerability was discovered in the webpage-to-markdown conversion feature of markdownify-mcp v0.0.2 and before.… Markdownify Mcp Server after 0.0.2 Fix from $1,9502025-12-10 MEDIUM 6.9 CVE-2020-36884 BrightSign Digital Signage Diagnostic Web Server 8.2.26 and less contains an unauthenticated server-side request forgery vulnerability in the 'url' G… No fix yet Fix from $1,6002025-12-10 HIGH 8.6 CVE-2025-67494 ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, full-read SSRF vulnerability. … Zitadel 4.7.1+ Fix from $1,9502025-12-09 HIGH 7.5 CVE-2025-65513 fetch-mcp v1.0.2 and before is vulnerable to Server-Side Request Forgery (SSRF) vulnerability, which allows attackers to bypass private IP validation… Fetch Mcp Server after 1.0.2 Fix from $1,9502025-12-09 HIGH 7.2 CVE-2021-47703 OpenBMCS 2.4 contains an unauthenticated SSRF vulnerability that allows attackers to bypass firewalls and initiate service and network enumeration on… Openbmcs No fix yet Fix from $1,9502025-12-09 HIGH 8.6 CVE-2025-26487 Server-Side Request Forgery (SSRF) vulnerability in Infinera MTC-9 version allows remote unauthenticated users to gain access to other network resou… Infinera Mtc 9 Firmware 23.0+ Fix from $1,9502025-12-08 HIGH 7.5 CVE-2025-59775 Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off  allows to po… HTTP Server 2.4.66+ Fix from $1,9502025-12-05 HIGH 7.1 CVE-2025-65958 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a Server-Side Request Forgery (SS… Open Webui 0.6.37+ Fix from $1,9502025-12-04 HIGH 7.2 CVE-2025-14008 A flaw has been found in dayrui XunRuiCMS up to 4.7.1. This vulnerability affects unknown code of the file admin79f2ec220c7e.php?c=api&m=test_site_do… Xunruicms after 4.7.1 Fix from $1,9502025-12-04 CRITICAL 9.8 CVE-2025-14004 A security flaw has been discovered in dayrui XunRuiCMS up to 4.7.1. Affected is an unknown function of the file /admind45f74adbd95.php?c=email&m=add… Xunruicms after 4.7.1 Fix from $2,3002025-12-04 CRITICAL 9.1 CVE-2025-13872 Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-based platforms allows an atta… Opinio Mitigation only Fix from $2,3002025-12-02 CRITICAL 9.8 CVE-2025-66405 Portkey.ai Gateway is a blazing fast AI Gateway with integrated guardrails. Prior to 1.14.0, the gateway determined the destination baseURL by priori… Gateway 1.14.0+ Fix from $2,3002025-12-01 CRITICAL 9.1 CVE-2025-65836 PublicCMS V5.202506.b is vulnerable to SSRF. in the chat interface of SimpleAiAdminController. Publiccms No fix yet Fix from $2,3002025-12-01 CRITICAL 9.8 CVE-2025-13814 A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the function LocalFileServiceImpl.uploadPictureByUrl of the fil… Mogublog after 5.2 Fix from $2,3002025-12-01 MEDIUM 6.5 CVE-2025-13809 A vulnerability has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected by this issue is some unknown functiona… Orion Ops after 2025-08-01 Fix from $1,6002025-12-01 MEDIUM 6.3 CVE-2025-13796 A security vulnerability has been detected in deco-cx apps up to 0.120.1. Affected by this vulnerability is the function AnalyticsScript of the file … Patch available Fix from $1,6002025-12-01 MEDIUM 5.3 CVE-2025-13789 A vulnerability was found in ZenTao up to 21.7.6-8564. This affects the function makeRequest of the file module/ai/model.php. The manipulation of the… Zentao 21.7.6+ Fix from $1,6002025-11-30 HIGH 8.1 CVE-2025-66201 LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.1-rc2, LibreChat is vulnerable to Server-side Request Forgery (SSRF), by … Librechat 0.8.1+ Fix from $1,9502025-11-29 MEDIUM 6.5 CVE-2025-13378 The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and… Mitigation only Fix from $1,6002025-11-27 HIGH 8.7 CVE-2025-34350 UnForm Server versions < 10.1.15 contain an unauthenticated arbitrary file read and SMB coercion vulnerability in the Doc Flow feature’s 'arc' endpoi… Mitigation only Fix from $1,9502025-11-25 HIGH 7.6 CVE-2025-33203 NVIDIA NeMo Agent Toolkit UI for Web contains a vulnerability in the chat API endpoint where an attacker may cause a Server-Side Request Forgery. A s… Mitigation only Fix from $1,9502025-11-25 HIGH 8.5 CVE-2025-62155 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.9.6, a recently patched S… Mitigation only Fix from $1,9502025-11-25 MEDIUM 6.3 CVE-2025-13588 A vulnerability was found in lKinderBueno Streamity Xtream IPTV Player up to 2.8. The impacted element is an unknown function of the file public/prox… Patch available Fix from $1,6002025-11-24