Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 5.3 CVE-2025-59346 Dragonfly is an open source P2P-based file distribution and image acceleration system. Versions prior to 2.1.0 contain a server-side request forgery … Dragonfly 2.1.0+ Fix from $1,6002025-09-17 MEDIUM 6.5 CVE-2025-57055 WonderCMS 3.5.0 is vulnerable to Server-Side Request Forgery (SSRF) in the custom module installation functionality. An authenticated administrator c… Wondercms No fix yet Fix from $1,6002025-09-17 MEDIUM 6.5 CVE-2025-9862 Server-Side Request Forgery (SSRF) vulnerability in Ghost allows an attacker to access internal resources.This issue affects Ghost: from 6.0.0 throug… Ghost after 6.0.8 Fix from $1,6002025-09-17 MEDIUM 6.9 CVE-2025-59155 hackmd-mcp is a Model Context Protocol server for integrating HackMD's note-taking platform with AI assistants. From 1.4.0 to before 1.5.0, hackmd-mc… Patch available Fix from $1,6002025-09-15 HIGH 8.8 CVE-2025-10471 A vulnerability was detected in ZKEACMS 4.3. Impacted is the function Proxy of the file src/ZKEACMS/Controllers/MediaController.cs. Performing manipu… Zkeacms No fix yet Fix from $1,9502025-09-15 CRITICAL 9.8 CVE-2025-58045 Dataease is an open source data analytics and visualization platform. In Dataease versions up to 2.10.12, the patch introduced to mitigate DB2 JDBC d… Dataease 2.10.13+ Fix from $2,3002025-09-15 MEDIUM 5.3 CVE-2025-10453 O'View MapServer developed by PilotGaea Technologies has a Server-Side Request Forgery vulnerability, allowing unauthenticated remote attackers to ex… Mitigation only Fix from $1,6002025-09-15 CRITICAL 9.8 CVE-2025-10410 A security vulnerability has been detected in SourceCodester Link Status Checker 1.0. This vulnerability affects unknown code of the file index.php. … Link Status Checker Mitigation only Fix from $2,3002025-09-14 HIGH 7.2 CVE-2025-10397 A vulnerability was identified in Magicblack MacCMS 2025.1000.4050. This affects an unknown part of the component API Handler. The manipulation of th… Maccms Mitigation only Fix from $1,9502025-09-14 HIGH 7.2 CVE-2025-10395 A vulnerability was found in Magicblack MacCMS 2025.1000.4050. Affected by this vulnerability is the function col_url of the component Scheduled Task… Maccms Mitigation only Fix from $1,9502025-09-14 MEDIUM 6.3 CVE-2025-10393 A flaw has been found in miurla morphic up to 0.4.5. This impacts the function fetchHtml of the file /api/advanced-search of the component HTTP Statu… Mitigation only Fix from $1,6002025-09-14 HIGH 8.8 CVE-2025-10391 A security vulnerability has been detected in CRMEB up to 5.6.1. The impacted element is the function testOutUrl of the file app/services/out/OutAcco… Crmeb after 5.6.1 Fix from $1,9502025-09-14 CRITICAL 9.8 CVE-2025-10329 A vulnerability was detected in cdevroe unmark up to 1.9.3. This affects an unknown part of the file /application/controllers/Marks.php. The manipula… Unmark after 1.9.3 Fix from $2,3002025-09-12 HIGH 8.8 CVE-2025-6454 An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could h… GitLab 18.1.6 / 18.2.6+ Fix from $1,9502025-09-12 HIGH 7.2 CVE-2025-59055 InstantCMS is a free and open source content management system. A blind Server-Side Request Forgery (SSRF) vulnerability in InstantCMS up to and incl… Instantcms after 2.17.3 Fix from $1,9502025-09-11 MEDIUM 6.3 CVE-2025-10211 A security vulnerability has been detected in yanyutao0402 ChanCMS 3.3.0. The affected element is the function CollectController of the file /cms/col… Chancms No fix yet Fix from $1,6002025-09-10 MEDIUM 6.4 CVE-2025-7843 The Auto Save Remote Images (Drafts) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.9 vi… Mitigation only Fix from $1,6002025-09-10 CRITICAL 9.1 CVE-2025-44594 halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/attachments/-/upload-from-url. Halo after 2.20.17 Fix from $2,3002025-09-09 MEDIUM 6.9 CVE-2025-9269 A Server-Side Request Forgery (SSRF) vulnerability has been identified in the embedded web server in various Lexmark devices. This vulnerability can … Mitigation only Fix from $1,6002025-09-09 HIGH 7.3 CVE-2025-5005 A vulnerability was detected in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.5.4. This affects an unknown function of the file crm… Lingdang Crm after 8.6.5.4 Fix from $1,9502025-09-09 MEDIUM 6.5 CVE-2025-54249 Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Secu… Experience Manager after 2025.8.0 Fix from $1,6002025-09-09 HIGH 7.2 CVE-2025-49430 Server-Side Request Forgery (SSRF) vulnerability in FWDesign Ultimate Video Player fwduvp allows Server Side Request Forgery.This issue affects Ultim… Mitigation only Fix from $1,9502025-09-09 MEDIUM 6.4 CVE-2025-47437 Server-Side Request Forgery (SSRF) vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n… Mitigation only Fix from $1,6002025-09-09 MEDIUM 6.8 CVE-2025-55139 SSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neuro… Connect Secure 22.7 / 22.8+ Fix from $1,6002025-09-09 HIGH 8.8 CVE-2025-9065 A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of input sanitization. Authentic… Thinmanager after 14.0.0 Fix from $1,9502025-09-09 MEDIUM 6.5 CVE-2025-43763 A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7,… Digital Experience Platform 7.4.3.132 / 2024.q1.21+ Fix from $1,6002025-09-09 MEDIUM 6.5 CVE-2025-10096 A vulnerability was determined in SimStudioAI sim up to 1.0.0. This affects an unknown function of the file apps/sim/app/api/files/parse/route.ts. Ex… Sim 0.3.40+ Fix from $1,6002025-09-08 HIGH 8.6 CVE-2025-8085EPSS 17% The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated … Ditty 3.1.58+ Fix from $1,9502025-09-08 MEDIUM 6.5 CVE-2025-58179 Astro is a web framework for content-driven websites. Versions 11.0.3 through 12.6.5 are vulnerable to SSRF when using Astro's Cloudflare adapter. Wh… \@astrojs\/cloudflare 12.6.6+ Fix from $1,6002025-09-05 MEDIUM 5.4 CVE-2025-58641 Server-Side Request Forgery (SSRF) vulnerability in kamleshyadav Exit Intent Popup exitintentpopup allows Server Side Request Forgery.This issue affe… Mitigation only Fix from $1,6002025-09-03