Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 5.3 CVE-2025-10695 Two unauthenticated diagnostic endpoints allow arbitrary backend-initiated network connections to an attacker‑supplied destination. Both endpoints ar… Opensupports No fix yet Fix from $1,6002025-10-03 MEDIUM 6.5 CVE-2025-57305 VitaraCharts 5.3.5 is vulnerable to Server-Side Request Forgery in fileLoader.jsp. Vitaracharts No fix yet Fix from $1,6002025-10-02 HIGH 7.3 CVE-2025-61735 Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. You are fine as long as… Kylin 5.0.3+ Fix from $1,9502025-10-02 HIGH 8.8 CVE-2025-20371 In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2408.119 and 9.2.2406.… Splunk 9.2.8 / 9.2.2406.122+ Fix from $1,9502025-10-01 MEDIUM 5.3 CVE-2025-56520 Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi. A … Dify No fix yet Fix from $1,6002025-09-30 MEDIUM 5.3 CVE-2025-34232 Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments… Virtual Appliance Application 25.1.102 / 25.1.1413+ Fix from $1,6002025-09-29 MEDIUM 6.8 CVE-2025-34233 Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments… Virtual Appliance Application 25.1.102 / 25.1.1413+ Fix from $1,6002025-09-29 HIGH 8.6 CVE-2025-34225 Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments… Virtual Appliance Application 25.1.102 / 25.1.1413+ Fix from $1,9502025-09-29 HIGH 8.6 CVE-2025-34228 Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments… Virtual Appliance Application 25.1.102 / 25.1.1413+ Fix from $1,9502025-09-29 MEDIUM 5.8 CVE-2025-34229 Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments… Virtual Appliance Application 25.1.102 / 25.1.1413+ Fix from $1,6002025-09-29 MEDIUM 5.8 CVE-2025-34230 Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments… Virtual Appliance Application 25.1.102 / 25.1.1413+ Fix from $1,6002025-09-29 HIGH 8.6 CVE-2025-34231 Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments… Virtual Appliance Application 25.1.102 / 25.1.1413+ Fix from $1,9502025-09-29 CRITICAL 9.8 CVE-2025-11046 A security flaw has been discovered in Tencent WeKnora 0.1.0. This impacts the function testEmbeddingModel of the file /api/v1/initialization/embeddi… Weknora Mitigation only Fix from $2,3002025-09-26 MEDIUM 5.4 CVE-2025-60181 Server-Side Request Forgery (SSRF) vulnerability in silence Silencesoft RSS Reader external-rss-reader allows Server Side Request Forgery.This issue … Mitigation only Fix from $1,6002025-09-26 MEDIUM 5.4 CVE-2025-60161 Server-Side Request Forgery (SSRF) vulnerability in bdthemes ZoloBlocks zoloblocks allows Server Side Request Forgery.This issue affects ZoloBlocks: … Mitigation only Fix from $1,6002025-09-26 MEDIUM 5.4 CVE-2025-10137 The Snow Monkey theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 29.1.5 via the request() funct… Mitigation only Fix from $1,6002025-09-26 CRITICAL 9.5 CVE-2020-36851 Rob--W cors-anywhere instances configured as an open proxy allow unauthenticated external users to induce the server to make HTTP requests to arbitra… Mitigation only Fix from $2,3002025-09-25 HIGH 7.5 CVE-2025-59527 Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, a Server-Side Request Forgery (SSRF) vulne… Flowise No fix yet Fix from $1,9502025-09-22 MEDIUM 6.9 CVE-2025-9960 A restriction bypass vulnerability in is-localhost-ip could allow attackers to perform Server-Side Request Forgery (SSRF). This issue affects is-loca… No fix yet Fix from $1,6002025-09-22 MEDIUM 6.4 CVE-2025-58962 Server-Side Request Forgery (SSRF) vulnerability in publitio Publitio publitio allows Server Side Request Forgery.This issue affects Publitio: from n… Mitigation only Fix from $1,6002025-09-22 MEDIUM 6.4 CVE-2025-58011 Server-Side Request Forgery (SSRF) vulnerability in Alex Content Mask content-mask allows Server Side Request Forgery.This issue affects Content Mask… Mitigation only Fix from $1,6002025-09-22 MEDIUM 5.4 CVE-2025-58005 Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft DriCub dricub-driving-school allows Server Side Request Forgery.This issue affects … No fix yet Fix from $1,6002025-09-22 MEDIUM 5.4 CVE-2025-36037 IBM webMethods Integration 10.15 and 11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send una… Webmethods Integration Mitigation only Fix from $1,6002025-09-22 MEDIUM 6.3 CVE-2025-10787 A vulnerability was found in MuYuCMS up to 2.7. Impacted is an unknown function of the file /index/index.html of the component Add Fiend Link Handler… Mitigation only Fix from $1,6002025-09-22 HIGH 7.2 CVE-2025-10765 A security flaw has been discovered in SeriaWei ZKEACMS up to 4.3. This vulnerability affects the function CheckPage/Suggestions in the library cms-v… Zkeacms after 4.3 Fix from $1,9502025-09-21 HIGH 8.8 CVE-2025-10764 A vulnerability was identified in SeriaWei ZKEACMS up to 4.3. This affects the function Edit of the file src/ZKEACMS.EventAction/Controllers/PendingT… Zkeacms after 4.3 Fix from $1,9502025-09-21 MEDIUM 6.3 CVE-2025-10760 A flaw has been found in Harness 3.3.0. This impacts the function LookupRepo of the file app/api/controller/gitspace/lookup_repo.go. Executing manipu… No fix yet Fix from $1,6002025-09-21 HIGH 7.5 CVE-2025-26515 StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 without Single Sign-on enabled are susceptible to a Server-Sid… Storagegrid 11.8.0.15 / 11.9.0.8+ Fix from $1,9502025-09-19 CRITICAL 9.1 CVE-2025-57644 Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative user can exe… Automation Platform Mitigation only Fix from $2,3002025-09-19 HIGH 7.7 CVE-2025-59344 AliasVault is a privacy-first password manager with built-in email aliasing. A server-side request forgery (SSRF) vulnerability exists in the favicon… Patch available Fix from $1,9502025-09-19