Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
CRITICAL 9.8 CVE-2025-31116 Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analy… Mobile Security Framework 4.3.2+ Fix from $2,3002025-03-31 HIGH 7.5 CVE-2025-31117 OpenEMR is a free and open source electronic health records and medical practice management application. An Out-of-Band Server-Side Request Forgery (… Openemr 7.0.3.1+ Fix from $1,9502025-03-31 HIGH 8.8 CVE-2025-2997 A vulnerability was found in zhangyanbo2007 youkefu 4.2.0. It has been classified as critical. Affected is an unknown function of the file /res/url. … Youkefu No fix yet Fix from $1,9502025-03-31 MEDIUM 6.4 CVE-2025-31527 Server-Side Request Forgery (SSRF) vulnerability in Kishan WP Link Preview wp-link-preview allows Server Side Request Forgery.This issue affects WP L… Mitigation only Fix from $1,6002025-03-31 CRITICAL 9.1 CVE-2025-28091 maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article. Maccms No fix yet Fix from $2,3002025-03-28 MEDIUM 6.3 CVE-2025-28092 ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function. Shopxo No fix yet Fix from $1,6002025-03-28 MEDIUM 6.3 CVE-2025-28093 ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) in Email Settings. Shopxo No fix yet Fix from $1,6002025-03-28 MEDIUM 6.5 CVE-2025-28094 shopxo v6.4.0 has a ssrf/xss vulnerability in multiple places. Shopxo No fix yet Fix from $1,6002025-03-28 MEDIUM 5.4 CVE-2025-28096 OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers. Onenav No fix yet Fix from $1,6002025-03-28 CRITICAL 9.1 CVE-2025-28089 maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function. Maccms No fix yet Fix from $2,3002025-03-28 CRITICAL 9.1 CVE-2025-28090 maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature. Maccms No fix yet Fix from $2,3002025-03-28 MEDIUM 6.5 CVE-2024-48944 Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. Through a kylin server, an attacker may forge a request to invoke "/kylin/api/xxx/d… Kylin 5.0.2+ Fix from $1,6002025-03-27 HIGH 7.6 CVE-2025-27406 Icinga Reporting is the central component for reporting related functionality in the monitoring web frontend and framework Icinga Web 2. A vulnerabil… Mitigation only Fix from $1,9502025-03-26 HIGH 7.6 CVE-2025-1912 The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Server-Side Request Forgery in all … Product Import Export For Woocommerce 2.5.1+ Fix from $1,9502025-03-26 MEDIUM 6.4 CVE-2024-13411 The Zapier for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.5.1 via the update… Mitigation only Fix from $1,6002025-03-26 MEDIUM 5.8 CVE-2025-2109 The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, a… Wp Compress 6.30.16+ Fix from $1,6002025-03-25 MEDIUM 6.9 CVE-2024-10206 A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an unauthenticated network-based attacker t… Mitigation only Fix from $1,6002025-03-25 MEDIUM 5.3 CVE-2024-10207 A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an authenticated network-based attacker to … Mitigation only Fix from $1,6002025-03-25 CRITICAL 9.1 CVE-2025-2691 Versions of the package nossrf before 1.0.4 are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide a hostname that resolv… Nossrf 1.0.4+ Fix from $2,3002025-03-23 HIGH 7.6 CVE-2025-1970 The Export and Import Users and Customers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6… Import Export Wordpress Users 2.6.3+ Fix from $1,9502025-03-22 MEDIUM 6.4 CVE-2024-13856 The Your Friendly Drag and Drop Page Builder — Make Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, … Mitigation only Fix from $1,6002025-03-22 CRITICAL 9.8 CVE-2024-48590 Inflectra SpiraTeam 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) via the NewsReaderService. This allows an attacker to escalate privile… Spirateam Mitigation only Fix from $2,3002025-03-20 MEDIUM 5.4 CVE-2025-27888 Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scri… Druid 31.0.2+ Fix from $1,6002025-03-20 MEDIUM 6.5 CVE-2024-13923 The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin… Order Export \& Order Import For Woocommerce 2.6.1+ Fix from $1,6002025-03-20 HIGH 7.5 CVE-2025-0454 A Server-Side Request Forgery (SSRF) vulnerability was identified in the Requests utility of significant-gravitas/autogpt versions prior to v0.4.0. T… Autogpt Platform 0.4.0+ Fix from $1,9502025-03-20 MEDIUM 6.5 CVE-2025-0184 A Server-Side Request Forgery (SSRF) vulnerability was identified in langgenius/dify version 0.10.2. The vulnerability occurs in the 'Create Knowledg… Dify 0.11.0+ Fix from $1,6002025-03-20 MEDIUM 6.5 CVE-2025-0188 A Server-Side Request Forgery (SSRF) vulnerability was discovered in gaizhenbiao/chuanhuchatgpt version 20240914. The vulnerability allows an attacke… Chuanhuchatgpt No fix yet Fix from $1,6002025-03-20 CRITICAL 9.3 CVE-2024-9309 A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Controller API Server in haotian-li… Llava No fix yet Fix from $2,3002025-03-20 HIGH 7.5 CVE-2024-8955 A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.4. This vulnerability allows an attacker to read the co… Composio No fix yet Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-8952 A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.2, specifically in the /api/actions/execute/WEBTOOL_SCR… Composio No fix yet Fix from $1,9502025-03-20