Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 5.3 CVE-2025-47791 Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 28.0.13, 29.0.10, and 30.0.3 and Nextcloud Enterprise Server pr… Nextcloud Server 28.0.13 / 29.0.10+ Fix from $1,6002025-05-16 CRITICAL 9.1 CVE-2024-6584 The 'wp_ajax_boost_proxy_ig' action allows administrators to make GET requests to arbitrary URLs. Jetpack Boost 3.4.7+ Fix from $2,3002025-05-15 HIGH 7.2 CVE-2025-40595 A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. By using an encoded URL, a remo… Mitigation only Fix from $1,9502025-05-14 MEDIUM 5.5 CVE-2024-13940 The Ninja Forms Webhooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.0.7 via the form w… Mitigation only Fix from $1,6002025-05-14 CRITICAL 9.1 CVE-2025-45887 Yifang CMS v2.0.2 is vulnerable to Server-Side Request Forgery (SSRF) in /api/file/getRemoteContent. Yifang No fix yet Fix from $2,3002025-05-09 HIGH 7.5 CVE-2025-47733 Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network Power Apps Mitigation only Fix from $1,9502025-05-08 CRITICAL 9.8 CVE-2025-29972 Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network. Azure Storage Resource Provider Mitigation only Fix from $2,3002025-05-08 MEDIUM 6.5 CVE-2025-47664 Server-Side Request Forgery (SSRF) vulnerability in ThimPress WP Pipes allows Server Side Request Forgery. This issue affects WP Pipes: from n/a thro… Wp Pipes after 1.4.3 Fix from $1,6002025-05-07 CRITICAL 9.8 CVE-2025-47635 Server-Side Request Forgery (SSRF) vulnerability in WPWebinarSystem WebinarPress wp-webinarsystem allows Server Side Request Forgery.This issue affec… Webinarpress after 1.33.27 Fix from $2,3002025-05-07 CRITICAL 9.8 CVE-2025-47548 Server-Side Request Forgery (SSRF) vulnerability in Varun Dubey Wbcom Designs - Activity Link Preview For BuddyPress activity-link-preview-for-buddyp… Activity Link Preview For Buddypress after 1.4.4 Fix from $2,3002025-05-07 MEDIUM 6.4 CVE-2025-47484 Server-Side Request Forgery (SSRF) vulnerability in Oliver Campion Display Remote Posts Block display-remote-posts-block allows Server Side Request F… Mitigation only Fix from $1,6002025-05-07 MEDIUM 5.5 CVE-2025-45250 MrDoc v0.95 and before is vulnerable to Server-Side Request Forgery (SSRF) in the validate_url function of the app_doc/utils.py file. Mrdoc after 0.95 Fix from $1,6002025-05-06 MEDIUM 6.5 CVE-2024-55910 IBM Concert Software 1.0.0 through 1.0.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauth… Concert 1.1.0+ Fix from $1,6002025-05-02 HIGH 7.5 CVE-2024-48907 Sematell ReplyOne 7.4.3.0 allows SSRF via the application server API. Replyone No fix yet Fix from $1,9502025-05-01 HIGH 7.5 CVE-2025-46568 Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. Prior to version 0.45.0, Stirling-PDF is… Stirling Pdf 0.45.0+ Fix from $1,9502025-05-01 MEDIUM 5.5 CVE-2024-13845 The Gravity Forms WebHooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.0 via the 'pro… Gravity Forms Webhooks 1.7.0+ Fix from $1,6002025-05-01 HIGH 7.2 CVE-2025-2170 A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface, which in specific conditions co… Sma1000 Firmware 12.4.3-02925+ Fix from $1,9502025-04-30 CRITICAL 9.8 CVE-2023-35817 DevExpress before 23.1.3 allows AsyncDownloader SSRF. Devexpress 21.2.12+ Fix from $2,3002025-04-28 HIGH 7.5 CVE-2025-4012 A vulnerability was found in playeduxyz PlayEdu 开源培训系统 up to 1.8 and classified as problematic. This issue affects some unknown processing of t… Playedu after 1.8 Fix from $1,9502025-04-28 MEDIUM 6.5 CVE-2025-3775 The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnera… Shoplentor 3.1.3+ Fix from $1,6002025-04-25 MEDIUM 6.4 CVE-2025-46511 Server-Side Request Forgery (SSRF) vulnerability in Derek Springer BeerXML Shortcode beerxml-shortcode allows Server Side Request Forgery.This issue … Mitigation only Fix from $1,6002025-04-24 MEDIUM 6.5 CVE-2025-1521 PostHog slack_incoming_webhook Server-Side Request Forgery Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclo… Posthog 0.3.7+ Fix from $1,6002025-04-23 MEDIUM 6.5 CVE-2025-1522 PostHog database_schema Server-Side Request Forgery Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sens… Posthog 0.3.7+ Fix from $1,6002025-04-23 MEDIUM 5.4 CVE-2025-2987 IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorize… Maximo Asset Management Mitigation only Fix from $1,6002025-04-22 CRITICAL 9.1 CVE-2025-28197 Crawl4AI <=0.4.247 is vulnerable to SSRF in /crawl4ai/async_dispatcher.py. Crawl4ai after 0.4.247 Fix from $2,3002025-04-18 MEDIUM 6.5 CVE-2025-3787 A vulnerability was found in PbootCMS 3.2.5. It has been classified as problematic. Affected is an unknown function of the component Image Handler. T… Pbootcms No fix yet Fix from $1,6002025-04-18 MEDIUM 6.5 CVE-2025-29456 An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the create Note… Personal Management System No fix yet Fix from $1,6002025-04-17 HIGH 7.6 CVE-2025-29457 An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Import a Theme function. NOTE: the Supplier disputes this be… Mybb No fix yet Fix from $1,9502025-04-17 HIGH 7.6 CVE-2025-29458 An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Change Avatar function. NOTE: the Supplier disputes this bec… Mybb No fix yet Fix from $1,9502025-04-17 HIGH 7.6 CVE-2025-29459 An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Mail function. NOTE: the Supplier disputes this because of t… Mybb No fix yet Fix from $1,9502025-04-17