Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.6
CVE-2025-29460
An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Add Mycode function. NOTE: the Supplier disputes this becaus…
Mybb
Mitigation only
HIGH 7.6
CVE-2025-29461
An issue in a-blogcms 3.1.15 allows a remote attacker to obtain sensitive information via the /bid/1/admin/entry-edit/ path.
A Blogcms
No fix yet
MEDIUM 6.5
CVE-2025-29453
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the my-contacts…
Personal Management System
No fix yet
MEDIUM 6.5
CVE-2025-29449
An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the link identification function.
Twonav
No fix yet
MEDIUM 6.5
CVE-2025-29450
An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the site settings component.
Twonav
No fix yet
HIGH 7.6
CVE-2025-29451
An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Mail Setting component.
Seo Panel
No fix yet
HIGH 7.6
CVE-2025-29452
An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Proxy Manager component.
Seo Panel
No fix yet
MEDIUM 6.5
CVE-2025-29454
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Upload func…
Personal Management System
No fix yet
MEDIUM 6.5
CVE-2025-29455
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Travel Idea…
Personal Management System
No fix yet
MEDIUM 6.5
CVE-2024-56736
Server-Side Request Forgery (SSRF) vulnerability in Apache HertzBeat.
This issue affects Apache HertzBeat (incubating): before 1.7.0.
Users are rec…
Hertzbeat
1.7.0+
MEDIUM 5.3
CVE-2025-3691
A vulnerability was found in mirweiye Seven Bears Library CMS 2023. It has been classified as problematic. Affected is an unknown function of the com…
Seven Bears Library Cms
2023+
MEDIUM 5.0
CVE-2025-32102EPSS 8%
CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=telnetSocket request to the /W…
Crushftp
after 11.3.1
MEDIUM 5.4
CVE-2025-30964
Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods Photography photography allows Server Side Request Forgery.This issue affects Photogra…
Mitigation only
HIGH 7.5
CVE-2025-31490
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prio…
Autogpt Platform
0.6.1+
HIGH 7.5
CVE-2025-3572
SmartRobot from INTUMIT has a Server-Side Request Forgery vulnerability, allowing unauthenticated remote attackers to probe internal network and even…
Smartrobot
8.0.0+
MEDIUM 6.0
CVE-2025-22374
A Server-Side Request Forgery (SSRF) vulnerability was discovered in the videx-legacy-ssl web service of Videx’s CyberAudit-Web, affecting versions p…
Mitigation only
HIGH 8.8
CVE-2025-0539
In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests that contain authentication mat…
Octopus Server
2024.3.13071 / 2024.4.7065+
MEDIUM 6.8
CVE-2025-32675
Server-Side Request Forgery (SSRF) vulnerability in QuantumCloud SEO Help seo-help allows Server Side Request Forgery.This issue affects SEO Help: fr…
Mitigation only
MEDIUM 5.4
CVE-2025-31009
Server-Side Request Forgery (SSRF) vulnerability in Jan Boddez IndieBlocks indieblocks allows Server Side Request Forgery.This issue affects IndieBlo…
Mitigation only
HIGH 7.5
CVE-2025-32372
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. A bypass has been identified for the pr…
Dotnetnuke
9.13.8+
MEDIUM 6.3
CVE-2025-3412
A vulnerability, which was classified as critical, was found in mymagicpower AIAS 20250308. Affected is an unknown function of the file 2_training_pl…
Aias
No fix yet
MEDIUM 6.3
CVE-2025-3411
A vulnerability, which was classified as critical, has been found in mymagicpower AIAS 20250308. This issue affects some unknown processing of the fi…
Aias
No fix yet
HIGH 7.5
CVE-2025-32013
LNbits is a Lightning wallet and accounts system. A Server-Side Request Forgery (SSRF) vulnerability has been discovered in LNbits' LNURL authenticat…
Lnbits
0.12.12+
CRITICAL 9.8
CVE-2025-3254
A vulnerability was found in xujiangfei admintwo 1.0. It has been classified as critical. Affected is an unknown function of the file /resource/add. …
Admintwo
No fix yet
HIGH 7.3
CVE-2025-2243
A server-side request forgery (SSRF) vulnerability in Bitdefender GravityZone Console allows an attacker to bypass input validation logic using leadi…
Gravityzone
6.41.2-1+
MEDIUM 5.3
CVE-2025-2245
A server-side request forgery (SSRF) vulnerability exists in the Bitdefender GravityZone Update Server when operating in Relay Mode. The HTTP proxy c…
Gravityzone Update Server
3.5.2.689+
HIGH 8.2
CVE-2025-3192
Versions of the package spatie/browsershot from 0.0.0 are vulnerable to Server-side Request Forgery (SSRF) in the setUrl() function due to a missing …
Mitigation only
MEDIUM 5.4
CVE-2025-31824
Server-Side Request Forgery (SSRF) vulnerability in Wombat Plugins WP Optin Wheel wp-optin-wheel allows Server Side Request Forgery.This issue affect…
Mitigation only
MEDIUM 5.4
CVE-2025-31796
Server-Side Request Forgery (SSRF) vulnerability in TheInnovs ElementsCSS Addons for Elementor css-for-elementor allows Server Side Request Forgery.T…
Mitigation only
HIGH 8.8
CVE-2025-21384
An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a …
Azure Health Bot
Mitigation only