Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 8.8 CVE-2025-7759 A vulnerability was identified in thinkgem JeeSite up to 5.12.0. This vulnerability affects unknown code of the file modules/core/src/main/java/com/j… Jeesite 5.12.1+ Fix from $1,9502025-07-17 MEDIUM 5.3 CVE-2025-20288 A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct… Unified Intelligence Center Mitigation only Fix from $1,6002025-07-16 CRITICAL 9.8 CVE-2024-9408 In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints. Glassfish Mitigation only Fix from $2,3002025-07-16 MEDIUM 5.3 CVE-2025-1220 In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation th… PHP 8.1.33 / 8.2.29+ Fix from $1,6002025-07-13 HIGH 8.2 CVE-2025-53641 Postiz is an AI social media scheduling tool. From 1.45.1 to 1.62.3, the Postiz frontend application allows an attacker to inject arbitrary HTTP head… Patch available Fix from $1,9502025-07-11 MEDIUM 6.3 CVE-2025-50125 A CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthenticated remote code execution when the server is acces… Mitigation only Fix from $1,6002025-07-11 MEDIUM 6.5 CVE-2025-6851 The Broken Link Notifier plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3.0 via the ajax_b… Broken Link Notifier 1.3.1+ Fix from $1,6002025-07-11 CRITICAL 9.1 CVE-2025-53371 DiscordNotifications is an extension for MediaWiki that sends notifications of actions in your Wiki to a Discord channel. DiscordNotifications allows… Patch available Fix from $2,3002025-07-10 HIGH 7.5 CVE-2024-43394 Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via  mod_rewrite or … HTTP Server 2.4.64+ Fix from $1,9502025-07-10 HIGH 7.5 CVE-2024-43204 SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker.  Requires an… HTTP Server 2.4.64+ Fix from $1,9502025-07-10 MEDIUM 6.2 CVE-2025-49545 ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitr… Coldfusion Mitigation only Fix from $1,6002025-07-08 HIGH 7.3 CVE-2025-53473 Server-side request forgery (SSRF) vulnerability exists n multiple versions of Nimesa Backup and Recovery, If this vulnerability is exploited, uninte… Mitigation only Fix from $1,9502025-07-07 HIGH 7.5 CVE-2025-7103 A vulnerability was found in BoyunCMS up to 1.4.20. It has been rated as critical. This issue affects some unknown processing of the file /applicatio… Boyuncms after 1.4.20 Fix from $1,9502025-07-07 HIGH 7.2 CVE-2025-49418 Server-Side Request Forgery (SSRF) vulnerability in TeconceTheme Allmart allmart-core allows Server Side Request Forgery.This issue affects Allmart: … Mitigation only Fix from $1,9502025-07-04 MEDIUM 5.4 CVE-2025-28963 Server-Side Request Forgery (SSRF) vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Server Side Request Forgery.This issue affec… Mitigation only Fix from $1,6002025-07-04 MEDIUM 6.4 CVE-2025-6729 The PayMaster for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 0.4.31 via the … Paymaster For Woocommerce after 0.4.31 Fix from $1,6002025-07-04 HIGH 7.2 CVE-2025-5817 The Amazon Products to WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2.7 via … Amazon Products To Woocommerce after 1.2.7 Fix from $1,9502025-07-02 MEDIUM 6.9 CVE-2025-34051 A server-side request forgery vulnerability exists in multiple firmware versions of AVTECH DVR devices that exposes the /cgi-bin/nobody/Search.cgi?ac… No fix yet Fix from $1,6002025-07-01 CRITICAL 9.8 CVE-2025-45872 zrlog v3.1.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the downloadUrl parameter. Zrlog Mitigation only Fix from $2,3002025-07-01 MEDIUM 5.8 CVE-2025-52491 Akamai CloudTest before 60 2025.06.09 (12989) allows SSRF. Mitigation only Fix from $1,6002025-06-30 HIGH 7.2 CVE-2025-6762 A vulnerability classified as critical has been found in diyhi bbs up to 6.8. This affects the function getUrl of the file /admin/login of the compon… Bbs after 6.8 Fix from $1,9502025-06-27 HIGH 7.2 CVE-2025-2940 The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.… Ninja Tables 5.0.19+ Fix from $1,9502025-06-27 HIGH 8.6 CVE-2025-52477 Octo-STS is a GitHub App that acts like a Security Token Service (STS) for the GitHub API. Octo-STS versions before v0.5.3 are vulnerable to unauthen… Patch available Fix from $1,9502025-06-26 MEDIUM 5.3 CVE-2024-51981 An unauthenticated attacker may perform a blind server side request forgery (SSRF), due to a CLRF injection issue that can be leveraged to perform HT… Mitigation only Fix from $1,6002025-06-25 MEDIUM 5.3 CVE-2024-51980 An unauthenticated attacker may perform a limited server side request forgery (SSRF), forcing the target device to open a TCP connection to an arbitr… Mitigation only Fix from $1,6002025-06-25 HIGH 7.5 CVE-2025-49852 ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to a server-side request forgery vulnerability which could allow an unauthe… Control Id Idsecure 4.7.50.0+ Fix from $1,9502025-06-24 CRITICAL 10.0 CVE-2025-2828EPSS 16% A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community package (specifically, langchai… Langchain 0.0.28+ Fix from $2,3002025-06-23 CRITICAL 9.8 CVE-2025-6517 A vulnerability was found in Dromara MaxKey up to 4.1.7 and classified as critical. This issue affects the function Add of the file maxkey-webs\maxke… Maxkey after 4.1.7 Fix from $2,3002025-06-23 MEDIUM 5.8 CVE-2025-52967 gateway_proxy_handler in MLflow before 3.1.0 lacks gateway_path validation. Patch available Fix from $1,6002025-06-23 HIGH 7.8 CVE-2025-34021 A server-side request forgery (SSRF) vulnerability exists in multiple Selea Targa IP OCR-ANPR camera models, including iZero, Targa 512, Targa 504, T… No fix yet Fix from $1,9502025-06-20