Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 7.2 CVE-2025-59837 Astro is a web framework that includes an image proxy. In versions 5.13.4 and later before 5.13.10, the image proxy domain validation can be bypassed… Astro 5.13.10+ Fix from $1,9502025-10-28 MEDIUM 5.4 CVE-2025-36085 IBM Concert 1.0.0 through 2.0.0 Software is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauth… Concert 2.1.0+ Fix from $1,6002025-10-28 HIGH 7.5 CVE-2025-10861 The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPress is vulnerable to Server-S… Mitigation only Fix from $1,9502025-10-24 MEDIUM 6.8 CVE-2025-12136 The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and i… No fix yet Fix from $1,6002025-10-24 MEDIUM 5.5 CVE-2025-10874 The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.2 does not limit URLs which ma… Mitigation only Fix from $1,6002025-10-24 CRITICAL 9.8 CVE-2025-59503 Server-side request forgery (ssrf) in Azure Compute Gallery allows an unauthorized attacker to elevate privileges over a network. Azure Compute Resource Provider Mitigation only Fix from $2,3002025-10-23 MEDIUM 5.0 CVE-2025-11128 The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Server-Side Re… Mitigation only Fix from $1,6002025-10-23 MEDIUM 5.3 CVE-2025-10705 The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2… Mitigation only Fix from $1,6002025-10-23 MEDIUM 5.3 CVE-2025-62612 FastGPT is an AI Agent building platform. Prior to version 4.11.1, in the workflow file reading node, the network link is not security-verified, posi… Fastgpt 4.11.1+ Fix from $1,6002025-10-22 MEDIUM 5.4 CVE-2025-49374 Server-Side Request Forgery (SSRF) vulnerability in captcha.eu Captcha.eu captcha-eu allows Server Side Request Forgery.This issue affects Captcha.eu… Mitigation only Fix from $1,6002025-10-22 MEDIUM 5.0 CVE-2025-62763 Zimbra Collaboration (ZCS) before 10.1.12 allows SSRF because of the configuration of the chat proxy. Mitigation only Fix from $1,6002025-10-21 MEDIUM 5.0 CVE-2025-11536 The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 8… Mitigation only Fix from $1,6002025-10-20 HIGH 7.6 CVE-2025-61488 An issue in Senayan Library Management System (SLiMS) 9 Bulian v.9.6.1 allows a remote attacker to execute arbitrary code via the scrap_image.php com… Mitigation only Fix from $1,9502025-10-20 MEDIUM 6.4 CVE-2025-11361 The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in al… Mitigation only Fix from $1,6002025-10-18 CRITICAL 9.1 CVE-2025-34282 ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload Gallery feature. An attacker … Thingsboard 4.2.1+ Fix from $2,3002025-10-17 CRITICAL 9.6 CVE-2025-60279 A server-side request forgery (SSRF) vulnerability in Illia Cloud illia-Builder before v4.8.5 allows authenticated users to send arbitrary requests t… Mitigation only Fix from $2,3002025-10-17 HIGH 7.3 CVE-2025-11864 A vulnerability was identified in NucleoidAI Nucleoid up to 0.7.10. The impacted element is the function extension.apply of the file /src/cluster.ts … Mitigation only Fix from $1,9502025-10-16 HIGH 8.7 CVE-2025-62427 The Angular SSR is a server-rise rendering tool for Angular applications. The vulnerability is a Server-Side Request Forgery (SSRF) flaw within the U… Patch available Fix from $1,9502025-10-16 MEDIUM 6.5 CVE-2025-60540 karakeep v0.26.0 to v0.7.0 was discovered to contain a Server-Side Request Forgery (SSRF). Mitigation only Fix from $1,6002025-10-14 MEDIUM 6.8 CVE-2025-11674 SOOP-CLM developed by PiExtract has a Server-Side Request Forgery vulnerability, allowing privileged remote attackers to read server files or probe i… Mitigation only Fix from $1,6002025-10-13 HIGH 7.4 CVE-2025-11648 A vulnerability has been found in Tomofun Furbo 360 and Furbo Mini. Impacted is an unknown function of the file TF_FQDN.json of the component GATT In… Furbo Mini Firmware after 074 Fix from $1,9502025-10-12 HIGH 8.1 CVE-2025-11636 A security vulnerability has been detected in Tomofun Furbo 360 up to FB0035_FW_036. This issue affects some unknown processing of the component Acco… Furbo 360 Dog Camera Firmware after 036 Fix from $1,9502025-10-12 HIGH 7.5 CVE-2025-61884 KEVEPSS 98% Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3… Configurator after 12.2.14 Fix from $1,9502025-10-12 CRITICAL 9.8 CVE-2025-31993 HCL Unica Centralized Offer Management is vulnerable to a potential Server-Side Request Forgery (SSRF). An attacker can exploit improper input valida… Unica Centralized Offer Management 25.1.0.1+ Fix from $2,3002025-10-12 MEDIUM 6.8 CVE-2025-9975 The WP Scraper plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.8.1 via the wp_scraper_extra… Mitigation only Fix from $1,6002025-10-11 HIGH 8.5 CVE-2025-59146 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. An authenticated Server-Side Request Forgery… Patch available Fix from $1,9502025-10-09 HIGH 8.7 CVE-2025-9868 Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated re… Mitigation only Fix from $1,9502025-10-08 HIGH 7.1 CVE-2025-6242 A Server-Side Request Forgery (SSRF) vulnerability exists in the MediaConnector class within the vLLM project's multimodal feature set. The load_from… Mitigation only Fix from $1,9502025-10-07 HIGH 8.1 CVE-2025-61784 LLaMA-Factory is a tuning library for large language models. Prior to version 0.9.4, a Server-Side Request Forgery (SSRF) vulnerability in the chat A… Llama Factory 0.9.4+ Fix from $1,9502025-10-07 MEDIUM 5.1 CVE-2025-61768 KUNO CMS is a fully deployable full-stack blog application. In versions prior to 1.3.15, an SSRF (Server-Side Request Forgery) vulnerability exists i… Patch available Fix from $1,6002025-10-06