Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 8.3 CVE-2024-8099 A Server-Side Request Forgery (SSRF) vulnerability exists in the latest version of vanna-ai/vanna when using DuckDB as the database. An attacker can … Mitigation only Fix from $1,9502025-03-20 HIGH 7.7 CVE-2024-7959 The `/openai/models` endpoint in open-webui/open-webui version 0.3.8 is vulnerable to Server-Side Request Forgery (SSRF). An attacker can change the … Open Webui No fix yet Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-12882 comfyanonymous/comfyui version v0.2.4 suffers from a non-blind Server-Side Request Forgery (SSRF) vulnerability. This vulnerability can be exploited … Comfyui No fix yet Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-12766 parisneo/lollms-webui version V13 (feather) suffers from a Server-Side Request Forgery (SSRF) vulnerability in the `POST /api/proxy` REST API. Attack… Lollms Web Ui No fix yet Fix from $1,9502025-03-20 MEDIUM 6.5 CVE-2024-12775 langgenius/dify version 0.10.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the test functionality for the Create Custom Tool optio… Dify No fix yet Fix from $1,6002025-03-20 HIGH 7.5 CVE-2024-12779 A Server-Side Request Forgery (SSRF) vulnerability exists in infiniflow/ragflow version 0.12.0. The vulnerability is present in the `POST /v1/llm/add… Ragflow No fix yet Fix from $1,9502025-03-20 MEDIUM 6.5 CVE-2024-12392 A Server-Side Request Forgery (SSRF) vulnerability exists in binary-husky/gpt_academic version git 310122f. The application has a functionality to do… Gpt Academic No fix yet Fix from $1,6002025-03-20 CRITICAL 9.8 CVE-2024-12450 In infiniflow/ragflow versions 0.12.0, the `web_crawl` function in `document_app.py` contains multiple vulnerabilities. The function does not filter … Ragflow Patch available Fix from $2,3002025-03-20 HIGH 7.5 CVE-2024-12068 A Server-Side Request Forgery (SSRF) vulnerability was discovered in haotian-liu/llava, affecting version git c121f04. This vulnerability allows an a… Llava No fix yet Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-12376 A Server-Side Request Forgery (SSRF) vulnerability was identified in the lm-sys/fastchat web server, specifically in the affected version git 2c68a13… Fastchat No fix yet Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-11449 A vulnerability in haotian-liu/llava version 1.2.0 (LLaVA-1.6) allows for Server-Side Request Forgery (SSRF) through the /run/predict endpoint. An at… Large Language And Vision Assistant No fix yet Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-11603 A Server-Side Request Forgery (SSRF) vulnerability exists in lm-sys/fastchat version 0.2.36. The vulnerability is present in the `/queue/join?` endpo… Fastchat No fix yet Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-11822 langgenius/dify version 0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability. The vulnerability exists due to improper handling of the a… Dify No fix yet Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-11030 GPT Academic version 3.83 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability through its HotReload plugin function, which calls the … Gpt Academic No fix yet Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-11031 In version 3.83 of binary-husky/gpt_academic, a Server-Side Request Forgery (SSRF) vulnerability exists in the Markdown_Translate.get_files_from_ever… Gpt Academic No fix yet Fix from $1,9502025-03-20 MEDIUM 6.5 CVE-2024-10457 Multiple Server-Side Request Forgery (SSRF) vulnerabilities were identified in the significant-gravitas/autogpt repository, specifically in the GitHu… Patch available Fix from $1,6002025-03-20 MEDIUM 5.3 CVE-2025-27774 Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) and file write in `model_download.py… Applio after 3.2.7 Fix from $1,6002025-03-19 MEDIUM 5.3 CVE-2025-27775 Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) and file write in `model_download.py… Applio after 3.2.7 Fix from $1,6002025-03-19 MEDIUM 5.3 CVE-2025-27776 Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) and file write in `model_download.py… Applio after 3.2.7 Fix from $1,6002025-03-19 HIGH 7.5 CVE-2025-27777 Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) in `model_download.py` (line 195 in … Applio after 3.2.7 Fix from $1,9502025-03-19 MEDIUM 6.8 CVE-2025-22474 Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) a Server-Side Request Forgery (SSRF) vulnerability. A h… Smartfabric Os10 10.5.4.14 / 10.5.5.13+ Fix from $1,6002025-03-17 HIGH 8.1 CVE-2025-22603 AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Vers… Autogpt Platform 0.4.2+ Fix from $1,9502025-03-10 CRITICAL 9.1 CVE-2024-13924 The Starter Templates by FancyWP plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.0.0 … Starter Templates after 2.0.0 Fix from $2,3002025-03-08 MEDIUM 5.3 CVE-2025-27152 axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to a… Axios 0.30.0+ Fix from $1,6002025-03-07 MEDIUM 5.5 CVE-2024-13857 The WPGet API – Connect to any external REST API plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includi… Mitigation only Fix from $1,6002025-03-07 CRITICAL 9.1 CVE-2024-13904 The Platform.ly for WooCommerce plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.1.6 v… Platform.ly For Woocommerce 1.1.7+ Fix from $2,3002025-03-07 MEDIUM 6.5 CVE-2025-27600 FastGPT is a knowledge-based platform built on the LLMs. Since the web crawling plug-in does not perform intranet IP verification, an attacker can in… Fastgpt 4.9.0+ Fix from $1,6002025-03-06 CRITICAL 9.8 CVE-2025-27652 Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Server-Side Request Forgery: rfIDEAS V-2023-… Vasion Print 20.0.2014 / 22.0.862+ Fix from $2,3002025-03-05 CRITICAL 9.8 CVE-2025-27655 Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Server-Side Request Forgery: CPA v1 V-2023-0… Vasion Print 20.0.2014 / 22.0.862+ Fix from $2,3002025-03-05 CRITICAL 9.8 CVE-2025-27651 Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Server-Side Request Forgery: Elatec V-2023-0… Vasion Print 20.0.2014 / 22.0.862+ Fix from $2,3002025-03-05