Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2025-7759
A vulnerability was identified in thinkgem JeeSite up to 5.12.0. This vulnerability affects unknown code of the file modules/core/src/main/java/com/j…
Jeesite
5.12.1+
MEDIUM 5.3
CVE-2025-20288
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct…
Unified Intelligence Center
Mitigation only
CRITICAL 9.8
CVE-2024-9408
In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints.
Glassfish
Mitigation only
MEDIUM 5.3
CVE-2025-1220
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation th…
PHP
8.1.33 / 8.2.29+
HIGH 8.2
CVE-2025-53641
Postiz is an AI social media scheduling tool. From 1.45.1 to 1.62.3, the Postiz frontend application allows an attacker to inject arbitrary HTTP head…
Patch available
MEDIUM 6.3
CVE-2025-50125
A
CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthenticated remote
code execution when the server is acces…
Mitigation only
MEDIUM 6.5
CVE-2025-6851
The Broken Link Notifier plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3.0 via the ajax_b…
Broken Link Notifier
1.3.1+
CRITICAL 9.1
CVE-2025-53371
DiscordNotifications is an extension for MediaWiki that sends notifications of actions in your Wiki to a Discord channel. DiscordNotifications allows…
Patch available
HIGH 7.5
CVE-2024-43394
Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via
mod_rewrite or …
HTTP Server
2.4.64+
HIGH 7.5
CVE-2024-43204
SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker. Requires an…
HTTP Server
2.4.64+
MEDIUM 6.2
CVE-2025-49545
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitr…
Coldfusion
Mitigation only
HIGH 7.3
CVE-2025-53473
Server-side request forgery (SSRF) vulnerability exists n multiple versions of Nimesa Backup and Recovery, If this vulnerability is exploited, uninte…
Mitigation only
HIGH 7.5
CVE-2025-7103
A vulnerability was found in BoyunCMS up to 1.4.20. It has been rated as critical. This issue affects some unknown processing of the file /applicatio…
Boyuncms
after 1.4.20
HIGH 7.2
CVE-2025-49418
Server-Side Request Forgery (SSRF) vulnerability in TeconceTheme Allmart allmart-core allows Server Side Request Forgery.This issue affects Allmart: …
Mitigation only
MEDIUM 5.4
CVE-2025-28963
Server-Side Request Forgery (SSRF) vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Server Side Request Forgery.This issue affec…
Mitigation only
MEDIUM 6.4
CVE-2025-6729
The PayMaster for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 0.4.31 via the …
Paymaster For Woocommerce
after 0.4.31
HIGH 7.2
CVE-2025-5817
The Amazon Products to WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2.7 via …
Amazon Products To Woocommerce
after 1.2.7
MEDIUM 6.9
CVE-2025-34051
A server-side request forgery vulnerability exists in multiple firmware versions of AVTECH DVR devices that exposes the /cgi-bin/nobody/Search.cgi?ac…
No fix yet
CRITICAL 9.8
CVE-2025-45872
zrlog v3.1.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the downloadUrl parameter.
Zrlog
Mitigation only
MEDIUM 5.8
CVE-2025-52491
Akamai CloudTest before 60 2025.06.09 (12989) allows SSRF.
Mitigation only
HIGH 7.2
CVE-2025-6762
A vulnerability classified as critical has been found in diyhi bbs up to 6.8. This affects the function getUrl of the file /admin/login of the compon…
Bbs
after 6.8
HIGH 7.2
CVE-2025-2940
The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.…
Ninja Tables
5.0.19+
HIGH 8.6
CVE-2025-52477
Octo-STS is a GitHub App that acts like a Security Token Service (STS) for the GitHub API. Octo-STS versions before v0.5.3 are vulnerable to unauthen…
Patch available
MEDIUM 5.3
CVE-2024-51981
An unauthenticated attacker may perform a blind server side request forgery (SSRF), due to a CLRF injection issue that can be leveraged to perform HT…
Mitigation only
MEDIUM 5.3
CVE-2024-51980
An unauthenticated attacker may perform a limited server side request forgery (SSRF), forcing the target device to open a TCP connection to an arbitr…
Mitigation only
HIGH 7.5
CVE-2025-49852
ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to a server-side request forgery vulnerability which could allow an unauthe…
Control Id Idsecure
4.7.50.0+
CRITICAL 10.0
CVE-2025-2828EPSS 16%
A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community package (specifically, langchai…
Langchain
0.0.28+
CRITICAL 9.8
CVE-2025-6517
A vulnerability was found in Dromara MaxKey up to 4.1.7 and classified as critical. This issue affects the function Add of the file maxkey-webs\maxke…
Maxkey
after 4.1.7
MEDIUM 5.8
CVE-2025-52967
gateway_proxy_handler in MLflow before 3.1.0 lacks gateway_path validation.
Patch available
HIGH 7.8
CVE-2025-34021
A server-side request forgery (SSRF) vulnerability exists in multiple Selea Targa IP OCR-ANPR camera models, including iZero, Targa 512, Targa 504, T…
No fix yet