Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 7.6 CVE-2025-29460 An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Add Mycode function. NOTE: the Supplier disputes this becaus… Mybb Mitigation only Fix from $1,9502025-04-17 HIGH 7.6 CVE-2025-29461 An issue in a-blogcms 3.1.15 allows a remote attacker to obtain sensitive information via the /bid/1/admin/entry-edit/ path. A Blogcms No fix yet Fix from $1,9502025-04-17 MEDIUM 6.5 CVE-2025-29453 An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the my-contacts… Personal Management System No fix yet Fix from $1,6002025-04-17 MEDIUM 6.5 CVE-2025-29449 An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the link identification function. Twonav No fix yet Fix from $1,6002025-04-17 MEDIUM 6.5 CVE-2025-29450 An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the site settings component. Twonav No fix yet Fix from $1,6002025-04-17 HIGH 7.6 CVE-2025-29451 An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Mail Setting component. Seo Panel No fix yet Fix from $1,9502025-04-17 HIGH 7.6 CVE-2025-29452 An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Proxy Manager component. Seo Panel No fix yet Fix from $1,9502025-04-17 MEDIUM 6.5 CVE-2025-29454 An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Upload func… Personal Management System No fix yet Fix from $1,6002025-04-17 MEDIUM 6.5 CVE-2025-29455 An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Travel Idea… Personal Management System No fix yet Fix from $1,6002025-04-17 MEDIUM 6.5 CVE-2024-56736 Server-Side Request Forgery (SSRF) vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat (incubating): before 1.7.0. Users are rec… Hertzbeat 1.7.0+ Fix from $1,6002025-04-16 MEDIUM 5.3 CVE-2025-3691 A vulnerability was found in mirweiye Seven Bears Library CMS 2023. It has been classified as problematic. Affected is an unknown function of the com… Seven Bears Library Cms 2023+ Fix from $1,6002025-04-16 MEDIUM 5.0 CVE-2025-32102EPSS 8% CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=telnetSocket request to the /W… Crushftp after 11.3.1 Fix from $1,6002025-04-15 MEDIUM 5.4 CVE-2025-30964 Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods Photography photography allows Server Side Request Forgery.This issue affects Photogra… Mitigation only Fix from $1,6002025-04-15 HIGH 7.5 CVE-2025-31490 AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prio… Autogpt Platform 0.6.1+ Fix from $1,9502025-04-14 HIGH 7.5 CVE-2025-3572 SmartRobot from INTUMIT has a Server-Side Request Forgery vulnerability, allowing unauthenticated remote attackers to probe internal network and even… Smartrobot 8.0.0+ Fix from $1,9502025-04-14 MEDIUM 6.0 CVE-2025-22374 A Server-Side Request Forgery (SSRF) vulnerability was discovered in the videx-legacy-ssl web service of Videx’s CyberAudit-Web, affecting versions p… Mitigation only Fix from $1,6002025-04-10 HIGH 8.8 CVE-2025-0539 In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests that contain authentication mat… Octopus Server 2024.3.13071 / 2024.4.7065+ Fix from $1,9502025-04-10 MEDIUM 6.8 CVE-2025-32675 Server-Side Request Forgery (SSRF) vulnerability in QuantumCloud SEO Help seo-help allows Server Side Request Forgery.This issue affects SEO Help: fr… Mitigation only Fix from $1,6002025-04-09 MEDIUM 5.4 CVE-2025-31009 Server-Side Request Forgery (SSRF) vulnerability in Jan Boddez IndieBlocks indieblocks allows Server Side Request Forgery.This issue affects IndieBlo… Mitigation only Fix from $1,6002025-04-09 HIGH 7.5 CVE-2025-32372 DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. A bypass has been identified for the pr… Dotnetnuke 9.13.8+ Fix from $1,9502025-04-09 MEDIUM 6.3 CVE-2025-3412 A vulnerability, which was classified as critical, was found in mymagicpower AIAS 20250308. Affected is an unknown function of the file 2_training_pl… Aias No fix yet Fix from $1,6002025-04-08 MEDIUM 6.3 CVE-2025-3411 A vulnerability, which was classified as critical, has been found in mymagicpower AIAS 20250308. This issue affects some unknown processing of the fi… Aias No fix yet Fix from $1,6002025-04-08 HIGH 7.5 CVE-2025-32013 LNbits is a Lightning wallet and accounts system. A Server-Side Request Forgery (SSRF) vulnerability has been discovered in LNbits' LNURL authenticat… Lnbits 0.12.12+ Fix from $1,9502025-04-06 CRITICAL 9.8 CVE-2025-3254 A vulnerability was found in xujiangfei admintwo 1.0. It has been classified as critical. Affected is an unknown function of the file /resource/add. … Admintwo No fix yet Fix from $2,3002025-04-04 HIGH 7.3 CVE-2025-2243 A server-side request forgery (SSRF) vulnerability in Bitdefender GravityZone Console allows an attacker to bypass input validation logic using leadi… Gravityzone 6.41.2-1+ Fix from $1,9502025-04-04 MEDIUM 5.3 CVE-2025-2245 A server-side request forgery (SSRF) vulnerability exists in the Bitdefender GravityZone Update Server when operating in Relay Mode. The HTTP proxy c… Gravityzone Update Server 3.5.2.689+ Fix from $1,6002025-04-04 HIGH 8.2 CVE-2025-3192 Versions of the package spatie/browsershot from 0.0.0 are vulnerable to Server-side Request Forgery (SSRF) in the setUrl() function due to a missing … Mitigation only Fix from $1,9502025-04-04 MEDIUM 5.4 CVE-2025-31824 Server-Side Request Forgery (SSRF) vulnerability in Wombat Plugins WP Optin Wheel wp-optin-wheel allows Server Side Request Forgery.This issue affect… Mitigation only Fix from $1,6002025-04-01 MEDIUM 5.4 CVE-2025-31796 Server-Side Request Forgery (SSRF) vulnerability in TheInnovs ElementsCSS Addons for Elementor css-for-elementor allows Server Side Request Forgery.T… Mitigation only Fix from $1,6002025-04-01 HIGH 8.8 CVE-2025-21384 An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a … Azure Health Bot Mitigation only Fix from $1,9502025-04-01