Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.4
CVE-2025-52713
Server-Side Request Forgery (SSRF) vulnerability in BoldGrid Post and Page Builder by BoldGrid post-and-page-builder allows Server Side Request Forge…
Mitigation only
HIGH 7.2
CVE-2025-23172
The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints. However, the "Add W…
Mitigation only
HIGH 7.5
CVE-2025-30678
A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modTMSM component could allow an attacker to manipulate c…
Apex Central
Mitigation only
HIGH 7.5
CVE-2025-30679
A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modOSCE component could allow an attacker to manipulate c…
Apex Central
Mitigation only
HIGH 7.1
CVE-2025-30680
A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (SaaS) could allow an attacker to manipulate certain parameters leadin…
Apex Central
2025-03-01+
MEDIUM 6.3
CVE-2025-6142
A vulnerability was found in Intera InHire up to 20250530. It has been declared as critical. Affected by this vulnerability is an unknown functionali…
Mitigation only
CRITICAL 9.1
CVE-2025-6087
A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package. The vulnerability stems from an unimplemente…
Create Cloudflare
1.3.0 / 2.49.3+
MEDIUM 5.8
CVE-2025-49190
The application is vulnerable to Server-Side Request Forgery (SSRF). An endpoint can be used to send server internal requests to other ports.
Field Analytics
Mitigation only
MEDIUM 5.4
CVE-2025-44043
Keyoti SearchUnit prior to 9.0.0. is vulnerable to Server-Side Request Forgery (SSRF) in /Keyoti_SearchEngine_Web_Common/SearchService.svc/GetResults…
Mitigation only
CRITICAL 9.1
CVE-2025-30220EPSS 57%
GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent…
Geotools
2.25.7 / 2.26.3+
HIGH 8.2
CVE-2024-29198
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. It possible to achieve Service Side …
Geoserver
2.24.4 / 2.25.2+
HIGH 8.2
CVE-2024-34711
GeoServer is an open source server that allows users to share and edit geospatial data. An improper URI validation vulnerability exists that enables …
Geoserver
2.25.0+
HIGH 7.5
CVE-2025-27817EPSS 65%
A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients accept configuration data for …
Kafka
3.9.1+
MEDIUM 5.3
CVE-2025-42988
Under certain conditions, SAP Business Objects Business Intelligence Platform allows an unauthenticated attacker to enumerate HTTP endpoints in the i…
Businessobjects Business Intelligence Platform
Patch available
MEDIUM 5.4
CVE-2025-30997
Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Car Repair Services car-repair-services allows Server Side Request Forgery.This iss…
Mitigation only
HIGH 7.1
CVE-2025-46341
FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, when the server is using HTTP auth via reverse proxy, it's possible to impers…
Freshrss
1.26.2+
CRITICAL 9.8
CVE-2025-5510
A vulnerability classified as critical was found in quequnlong shiyi-blog up to 1.2.1. This vulnerability affects unknown code of the file /app/sys/a…
Shiyi Blog
after 1.2.1
MEDIUM 6.5
CVE-2024-7073
A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in SOAP admin services. This fla…
Identity Server
Mitigation only
CRITICAL 9.8
CVE-2025-37090
A server-side request forgery vulnerability exists in HPE StoreOnce Software.
Storeonce System
4.3.11+
HIGH 8.8
CVE-2025-5327
A vulnerability was found in chshcms mccms 2.7. It has been classified as critical. This affects the function index of the file sys/apps/controllers/…
Mccms
No fix yet
CRITICAL 9.1
CVE-2025-4967
Esri Portal for ArcGIS 11.4 and prior allows a remote, unauthenticated attacker to bypass the Portal’s SSRF protections.
Portal For Arcgis
after 11.4
HIGH 7.3
CVE-2025-45474
maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings.
Maccms
No fix yet
HIGH 7.5
CVE-2024-52588
Strapi is an open-source content management system. Prior to version 4.25.2, inputting a local domain into the Webhooks URL field leads to the applic…
Strapi
4.25.2+
HIGH 7.4
CVE-2025-5276
Versions of the package mcp-markdownify-server before 1.0.0 are vulnerable to Server-Side Request Forgery (SSRF) via the Markdownify.get() function. …
Patch available
MEDIUM 5.4
CVE-2025-45475
maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management.
Maccms
No fix yet
HIGH 8.2
CVE-2025-48383
Django-Select2 is a Django integration for Select2. Prior to version 8.4.1, instances of HeavySelect2Mixin subclasses like the ModelSelect2MultipleWi…
Patch available
HIGH 8.8
CVE-2025-5186
A vulnerability was found in thinkgem JeeSite up to 5.11.1. It has been rated as critical. Affected by this issue is the function ResourceLoader.getR…
Jeesite
after 5.11.1
MEDIUM 6.3
CVE-2025-5140
A vulnerability classified as critical has been found in Seeyon Zhiyuan OA Web Application System up to 8.1 SP2. This affects the function this.oursN…
Mitigation only
HIGH 7.6
CVE-2024-13957
SSRF Server Side Request Forgery vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise:…
Mitigation only
HIGH 7.5
CVE-2025-36560
Server-side request forgery vulnerability exists in a-blog cms multiple versions. If this vulnerability is exploited, a remote unauthenticated attack…
A Blog Cms
after 3.1.43