Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 5.4 CVE-2025-25229 Omnissa Workspace ONE UEM contains a Server-Side Request Forgery (SSRF) Vulnerability. A malicious actor with user privileges may be able to access r… Mitigation only Fix from $1,6002025-08-11 HIGH 8.6 CVE-2025-4581 Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.… Digital Experience Platform after 2025.q1.4 Fix from $1,9502025-08-09 MEDIUM 5.0 CVE-2025-4655 SSRF vulnerability in FreeMarker templates in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through … Digital Experience Platform 2024.Q1.16 / 2025.Q1.6+ Fix from $1,6002025-08-09 CRITICAL 10.0 CVE-2025-53767 Azure OpenAI Elevation of Privilege Vulnerability Azure Openai No fix yet Fix from $2,3002025-08-07 MEDIUM 6.5 CVE-2025-51058 Bottinelli Informatical Vedo Suite 2024.17 is vulnerable to Server-side Request Forgery (SSRF) in the /api_vedo/video/preview endpoint, which allows … Vedo Suite No fix yet Fix from $1,6002025-08-06 MEDIUM 6.5 CVE-2024-55399 4C Strategies Exonaut before v21.6.2.1-1 was discovered to contain a Server-Side Request Forgery (SSRF). Exonaut 21.6.2.1-1+ Fix from $1,6002025-08-06 MEDIUM 6.5 CVE-2025-50234 MCCMS v2.7.0 has an SSRF vulnerability located in the index() method of the sys\apps\controllers\api\Gf.php file, where the pic parameter is processe… Mccms No fix yet Fix from $1,6002025-08-06 MEDIUM 6.3 CVE-2025-8529 A vulnerability classified as critical was found in cloudfavorites favorites-web up to 1.3.0. Affected by this vulnerability is the function getColle… Mitigation only Fix from $1,6002025-08-04 HIGH 8.8 CVE-2025-8527 A vulnerability was found in Exrick xboot up to 3.3.4. It has been rated as critical. This issue affects some unknown processing of the file xboot-fa… Xboot after 3.3.4 Fix from $1,9502025-08-04 MEDIUM 5.0 CVE-2025-8341 Grafana is an open-source platform for monitoring and observability. The Infinity datasource plugin, maintained by Grafana Labs, allows visualizing d… Mitigation only Fix from $1,6002025-08-04 HIGH 7.5 CVE-2025-54132 Cursor is a code editor built for programming with AI. In versions below 1.3, Mermaid (which is used to render diagrams) allows embedding images whic… Cursor 1.3+ Fix from $1,9502025-08-01 MEDIUM 6.9 CVE-2025-54590 webfinger.js is a TypeScript-based WebFinger client that runs in both browsers and Node.js environments. In versions 2.8.0 and below, the lookup func… Patch available Fix from $1,6002025-08-01 MEDIUM 5.0 CVE-2025-52567 GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versi… Glpi 10.0.19+ Fix from $1,6002025-07-30 CRITICAL 9.9 CVE-2025-54381EPSS 12% BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.0 until 1.4.19, the file u… Bentoml 1.4.19+ Fix from $2,3002025-07-29 HIGH 7.5 CVE-2025-24485EPSS 6% A server-side request forgery vulnerability exists in the cecho.php functionality of MedDream PACS Premium 7.3.5.860. A specially crafted HTTP reques… Pacs Server No fix yet Fix from $1,9502025-07-28 MEDIUM 5.3 CVE-2025-8267 Versions of the package ssrfcheck before 1.2.0 are vulnerable to Server-Side Request Forgery (SSRF) due to an incomplete denylist of IP address range… Ssrf Check 1.2.0+ Fix from $1,6002025-07-28 HIGH 8.8 CVE-2025-8228 A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been rated as critical. Affected by this issue is the function getPages of the … Chancms 3.1.3+ Fix from $1,9502025-07-27 HIGH 8.2 CVE-2025-52453 Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Data Source modules) allows Resource Location S… Tableau Server 2023.3.19 / 2024.2.12+ Fix from $1,9502025-07-25 HIGH 8.2 CVE-2025-52454 Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Amazon S3 Connector modules) allows Resource Locatio… Tableau Server 2023.3.19 / 2024.2.12+ Fix from $1,9502025-07-25 MEDIUM 5.3 CVE-2025-52455 Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (EPS Server modules) allows Resource Location Spoofin… Tableau Server 2023.3.19 / 2024.2.12+ Fix from $1,6002025-07-25 MEDIUM 6.5 CVE-2025-45939 Apwide Golive 10.2.0 Jira plugin allows Server-Side Request Forgery (SSRF) via the test webhook function. Golive Mitigation only Fix from $1,6002025-07-25 MEDIUM 6.3 CVE-2025-8133 A vulnerability classified as critical has been found in yanyutao0402 ChanCMS up to 3.1.2. This affects the function getArticle of the file app/modul… Chancms 3.1.3+ Fix from $1,6002025-07-25 HIGH 8.2 CVE-2025-8020 All versions of the package private-ip are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide an IP or hostname that reso… Mitigation only Fix from $1,9502025-07-23 MEDIUM 5.5 CVE-2025-5818 The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, an… Mitigation only Fix from $1,6002025-07-23 CRITICAL 10.0 CVE-2025-54122 Manager-io/Manager is accounting software. A critical unauthenticated full read Server-Side Request Forgery (SSRF) vulnerability has been identified … Mitigation only Fix from $2,3002025-07-21 CRITICAL 9.1 CVE-2025-52362 Server-Side Request Forgery (SSRF) vulnerability exists in the URL processing functionality of PHProxy version 1.1.1 and prior. The input validation … Mitigation only Fix from $2,3002025-07-21 HIGH 8.6 CVE-2025-36845 An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php allows for Server-Side Request Forgery (SSRF). The … Urve Web Manager No fix yet Fix from $1,9502025-07-21 HIGH 8.6 CVE-2025-46385 CWE-918 Server-Side Request Forgery (SSRF) No fix yet Fix from $1,9502025-07-20 MEDIUM 6.5 CVE-2025-52163 A Server-Side Request Forgery (SSRF) in the component TunnelServlet of agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 allows attackers to f… No fix yet Fix from $1,6002025-07-18 HIGH 8.8 CVE-2025-7787 A vulnerability, which was classified as critical, was found in Xuxueli xxl-job up to 3.1.1. Affected is the function httpJobHandler of the file src\… Xxl Job after 3.1.1 Fix from $1,9502025-07-18