Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 6.4 CVE-2025-12800 The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including… Mitigation only Fix from $1,6002025-11-23 CRITICAL 9.8 CVE-2025-62207 Azure Monitor Elevation of Privilege Vulnerability Azure Monitor No fix yet Fix from $2,3002025-11-20 MEDIUM 5.3 CVE-2025-13147 Server-Side Request Forgery (SSRF) vulnerability in Progress MOVEit Transfer.This issue affects MOVEit Transfer: before 2024.1.8, from 2025.0.0 befor… Moveit Transfer 2024.1.8 / 2025.0.4+ Fix from $1,6002025-11-19 MEDIUM 5.4 CVE-2025-12359 The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.3 via t… Mitigation only Fix from $1,6002025-11-19 HIGH 7.8 CVE-2025-63408 Local Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local attacker to gain access to sensitive… Agent Dvr after 6.6.7.0 Fix from $1,9502025-11-18 MEDIUM 6.8 CVE-2025-8084 The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.8 via the rest_helpers_crea… Mitigation only Fix from $1,6002025-11-18 MEDIUM 6.4 CVE-2025-12376 The Icon List Block – Add Icon-Based Lists with Custom Styles plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to… Mitigation only Fix from $1,6002025-11-18 MEDIUM 5.8 CVE-2025-11427 The WP Migrate Lite – WordPress Migration Made Easy plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, an… Mitigation only Fix from $1,6002025-11-18 MEDIUM 6.4 CVE-2025-12962 The Local Syndication plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.5a via the `url` para… Mitigation only Fix from $1,6002025-11-18 MEDIUM 6.3 CVE-2025-13174 A weakness has been identified in rachelos WeRSS we-mp-rss up to 1.4.7. Affected by this vulnerability is the function do_job of the file /rachelos/w… Mitigation only Fix from $1,6002025-11-14 MEDIUM 6.5 CVE-2025-64752 grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with access to any document on a Grist installation can use a feature for … Grist Core 1.7.7+ Fix from $1,6002025-11-13 CRITICAL 9.9 CVE-2025-64709 Typebot is an open-source chatbot builder. In versions prior to 3.13.1, a Server-Side Request Forgery (SSRF) vulnerability in the Typebot webhook blo… Typebot 3.13.1+ Fix from $2,3002025-11-13 HIGH 8.8 CVE-2025-64511 MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can access internal network services such as databases throug… Maxkb 2.3.1+ Fix from $1,9502025-11-13 MEDIUM 6.5 CVE-2025-64525 Astro is a web framework. In Astro versions 2.16.0 up to but excluding 5.15.5 which utilizeon-demand rendering, request headers `x-forwarded-proto` a… Astro 5.15.5+ Fix from $1,6002025-11-13 MEDIUM 6.5 CVE-2025-52186 Lichess lila before commit 11b4c0fb00f0ffd823246f839627005459c8f05c (2025-06-02) contains a Server-Side Request Forgery (SSRF) vulnerability in the g… Lila 2025-06-02+ Fix from $1,6002025-11-13 HIGH 8.6 CVE-2025-59088 If kdcproxy receives a request for a realm which does not have server addresses defined in its configuration, by default, it will query SRV records i… Patch available Fix from $1,9502025-11-12 HIGH 7.6 CVE-2025-64522 Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where webhook URLs are not validate… Soft Serve 0.11.1+ Fix from $1,9502025-11-10 HIGH 7.5 CVE-2025-64430 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions 4.2.0 through 7.5.3, and 8.0.0 th… Patch available Fix from $1,9502025-11-07 CRITICAL 10.0 CVE-2025-64180 Manager-io/Manager is accounting software. In Manager Desktop and Server versions 25.11.1.3085 and below, a critical vulnerability permits unauthoriz… Mitigation only Fix from $2,3002025-11-07 HIGH 8.9 CVE-2025-64178 Jellysweep is a cleanup tool for the Jellyfin media server. In versions 0.12.1 and below, /api/images/cache, used to download media posters from the … Patch available Fix from $1,9502025-11-06 MEDIUM 5.3 CVE-2025-64327 ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. Versions 0.6.7 and below contain a Blind Server-Side Request… Thinkdashboard 0.6.8+ Fix from $1,6002025-11-06 HIGH 7.5 CVE-2025-63551 A Server-Side Request Forgery (SSRF) vulnerability, achievable through an XML External Entity (XXE) injection, exists in MetInfo Content Management S… Metinfo 8.1+ Fix from $1,9502025-11-06 HIGH 7.3 CVE-2025-60541 A Server-Side Request Forgery (SSRF) in the /api/proxy/ component of linshenkx prompt-optimizer v1.3.0 to v1.4.2 allows attackers to scan internal re… Prompt Optimizer after 1.4.2 Fix from $1,9502025-11-06 CRITICAL 9.8 CVE-2025-64163 DataEase is an open source data visualization analysis tool. In versions 2.10.14 and below, the vendor added a blacklist to filter ldap:// and ldaps:… Dataease 2.10.15+ Fix from $2,3002025-11-06 MEDIUM 6.4 CVE-2025-11917 The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.11 via the… Patch available Fix from $1,6002025-11-05 MEDIUM 6.4 CVE-2025-12388 The B Carousel Block – Responsive Image and Content Carousel plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and… Mitigation only Fix from $1,6002025-11-05 CRITICAL 9.3 CVE-2023-7325 Anheng Mingyu Operation and Maintenance Audit and Risk Control System up to 2023-08-10 contains a server-side request forgery (SSRF) vulnerability in… Mitigation only Fix from $2,3002025-10-30 MEDIUM 6.1 CVE-2020-36862 Nagios XI versions prior to 5.6.11 contain unauthenticated vulnerabilities in the Highcharts local exporting tool. Crafted export requests could (1) … Nagios Xi 5.6.11+ Fix from $1,6002025-10-30 MEDIUM 6.5 CVE-2025-60319 PerfreeBlog v4.0.11 is vulnerable to Server-Side Request Forgery due to a missing authorization check in the uploadAttachByUrl API endpoint (AttachCo… Perfreeblog Patch available Fix from $1,6002025-10-30 MEDIUM 5.8 CVE-2025-60898 An unauthenticated server-side request forgery (SSRF) vulnerability in the Thumbnail via-uri endpoint of Halo CMS 2.21 allows a remote attacker to ca… Mitigation only Fix from $1,6002025-10-29