Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2025-31116
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analy…
Mobile Security Framework
4.3.2+
HIGH 7.5
CVE-2025-31117
OpenEMR is a free and open source electronic health records and medical practice management application. An Out-of-Band Server-Side Request Forgery (…
Openemr
7.0.3.1+
HIGH 8.8
CVE-2025-2997
A vulnerability was found in zhangyanbo2007 youkefu 4.2.0. It has been classified as critical. Affected is an unknown function of the file /res/url. …
Youkefu
No fix yet
MEDIUM 6.4
CVE-2025-31527
Server-Side Request Forgery (SSRF) vulnerability in Kishan WP Link Preview wp-link-preview allows Server Side Request Forgery.This issue affects WP L…
Mitigation only
CRITICAL 9.1
CVE-2025-28091
maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.
Maccms
No fix yet
MEDIUM 6.3
CVE-2025-28092
ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function.
Shopxo
No fix yet
MEDIUM 6.3
CVE-2025-28093
ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) in Email Settings.
Shopxo
No fix yet
MEDIUM 6.5
CVE-2025-28094
shopxo v6.4.0 has a ssrf/xss vulnerability in multiple places.
Shopxo
No fix yet
MEDIUM 5.4
CVE-2025-28096
OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers.
Onenav
No fix yet
CRITICAL 9.1
CVE-2025-28089
maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.
Maccms
No fix yet
CRITICAL 9.1
CVE-2025-28090
maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature.
Maccms
No fix yet
MEDIUM 6.5
CVE-2024-48944
Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. Through a kylin server, an attacker may forge a request to invoke "/kylin/api/xxx/d…
Kylin
5.0.2+
HIGH 7.6
CVE-2025-27406
Icinga Reporting is the central component for reporting related functionality in the monitoring web frontend and framework Icinga Web 2. A vulnerabil…
Mitigation only
HIGH 7.6
CVE-2025-1912
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Server-Side Request Forgery in all …
Product Import Export For Woocommerce
2.5.1+
MEDIUM 6.4
CVE-2024-13411
The Zapier for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.5.1 via the update…
Mitigation only
MEDIUM 5.8
CVE-2025-2109
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, a…
Wp Compress
6.30.16+
MEDIUM 6.9
CVE-2024-10206
A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an unauthenticated network-based attacker t…
Mitigation only
MEDIUM 5.3
CVE-2024-10207
A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an authenticated network-based attacker to …
Mitigation only
CRITICAL 9.1
CVE-2025-2691
Versions of the package nossrf before 1.0.4 are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide a hostname that resolv…
Nossrf
1.0.4+
HIGH 7.6
CVE-2025-1970
The Export and Import Users and Customers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6…
Import Export Wordpress Users
2.6.3+
MEDIUM 6.4
CVE-2024-13856
The Your Friendly Drag and Drop Page Builder — Make Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, …
Mitigation only
CRITICAL 9.8
CVE-2024-48590
Inflectra SpiraTeam 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) via the NewsReaderService. This allows an attacker to escalate privile…
Spirateam
Mitigation only
MEDIUM 5.4
CVE-2025-27888
Severity: medium (5.8) / important
Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scri…
Druid
31.0.2+
MEDIUM 6.5
CVE-2024-13923
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin…
Order Export \& Order Import For Woocommerce
2.6.1+
HIGH 7.5
CVE-2025-0454
A Server-Side Request Forgery (SSRF) vulnerability was identified in the Requests utility of significant-gravitas/autogpt versions prior to v0.4.0. T…
Autogpt Platform
0.4.0+
MEDIUM 6.5
CVE-2025-0184
A Server-Side Request Forgery (SSRF) vulnerability was identified in langgenius/dify version 0.10.2. The vulnerability occurs in the 'Create Knowledg…
Dify
0.11.0+
MEDIUM 6.5
CVE-2025-0188
A Server-Side Request Forgery (SSRF) vulnerability was discovered in gaizhenbiao/chuanhuchatgpt version 20240914. The vulnerability allows an attacke…
Chuanhuchatgpt
No fix yet
CRITICAL 9.3
CVE-2024-9309
A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Controller API Server in haotian-li…
Llava
No fix yet
HIGH 7.5
CVE-2024-8955
A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.4. This vulnerability allows an attacker to read the co…
Composio
No fix yet
HIGH 7.5
CVE-2024-8952
A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.2, specifically in the /api/actions/execute/WEBTOOL_SCR…
Composio
No fix yet