Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 8.6 CVE-2025-27501 OpenZiti is a free and open source project focused on bringing zero trust to any application. An endpoint on the admin panel can be accessed without … Openziti 3.7.1+ Fix from $1,9502025-03-03 MEDIUM 6.9 CVE-2025-25303 The MouseTooltipTranslator Chrome extension allows mouseover translation of any language at once. The MouseTooltipTranslator browser extension is vul… Mitigation only Fix from $1,6002025-03-03 HIGH 7.5 CVE-2025-25301 Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the /api/remove endpoint takes a URL query parameter that allows an image t… Rembg after 2.0.57 Fix from $1,9502025-03-03 HIGH 8.8 CVE-2025-1848 A vulnerability classified as critical has been found in zj1983 zz up to 2024-8. Affected is an unknown function of the file /import_data_check. The … Zz after 2024-8 Fix from $1,9502025-03-03 HIGH 8.8 CVE-2025-1849 A vulnerability classified as critical was found in zj1983 zz up to 2024-8. Affected by this vulnerability is an unknown functionality of the file /i… Zz 2024-8+ Fix from $1,9502025-03-03 HIGH 8.8 CVE-2025-1833 A vulnerability, which was classified as critical, has been found in zj1983 zz up to 2024-8. Affected by this issue is the function sendNotice of the… Zz 2024-8+ Fix from $1,9502025-03-02 MEDIUM 6.3 CVE-2025-1799 A vulnerability, which was classified as critical, was found in Zorlan SkyCaiji 2.9. This affects the function previewAction of the file vendor/skyca… Skycaiji Mitigation only Fix from $1,6002025-03-01 MEDIUM 6.5 CVE-2024-13697 The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Server-Side Reque… Better Messages 2.7.5+ Fix from $1,6002025-03-01 MEDIUM 6.4 CVE-2025-1662 The URL Media Uploader plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.0 via the 'url_med… Url Media Uploader after 1.0.1 Fix from $1,6002025-02-28 CRITICAL 9.8 CVE-2025-22952 elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploite… Memos Patch available Fix from $2,3002025-02-27 HIGH 7.5 CVE-2025-25760 A Server-Side Request Forgery (SSRF) in the component admin_webgather.php of SUCMS v1.0 allows attackers to access internal data and services via a c… Sucms Mitigation only Fix from $1,9502025-02-27 MEDIUM 6.5 CVE-2024-13907 The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Server-Side Request Forgery in al… Total Upkeep 1.16.9+ Fix from $1,6002025-02-27 CRITICAL 9.1 CVE-2024-13905 The OneStore Sites plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 0.1.1 via the class-export… Onestore Sites after 0.1.1 Fix from $2,3002025-02-27 MEDIUM 6.8 CVE-2025-25827 A Server-Side Request Forgery (SSRF) in the component sort.php of Emlog Pro v2.5.4 allows attackers to scan local and internal ports via supplying a … Emlog Mitigation only Fix from $1,6002025-02-26 CRITICAL 9.1 CVE-2025-25785 JizhiCMS v2.5.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component \c\PluginsController.php. This vulnerability allows … Jizhicms Mitigation only Fix from $2,3002025-02-26 CRITICAL 9.1 CVE-2024-30150 HCL MyCloud is affected by Improper Access Control - an unauthenticated privilege escalation vulnerability which may lead to information disclosure a… Dryice Mycloud Mitigation only Fix from $2,3002025-02-25 MEDIUM 5.4 CVE-2024-13695 The Enfold theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.9 via the 'attachment_id' param… Enfold 7.0.0+ Fix from $1,6002025-02-25 MEDIUM 6.4 CVE-2025-1043 The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Server-Side Request Forgery in all version… Mitigation only Fix from $1,6002025-02-20 HIGH 8.6 CVE-2024-37359 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensu… Mitigation only Fix from $1,9502025-02-19 MEDIUM 5.3 CVE-2025-27090 Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security test… Sliver 1.5.43+ Fix from $1,6002025-02-19 MEDIUM 5.4 CVE-2024-13741 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up … Profilegrid 5.9.4.3+ Fix from $1,6002025-02-18 HIGH 7.2 CVE-2025-20075 Server-side request forgery (SSRF) vulnerability exists in FileMegane versions above 3.0.0.0 prior to 3.4.0.0. Executing arbitrary backend Web API re… Mitigation only Fix from $1,9502025-02-18 MEDIUM 5.5 CVE-2024-13879 The Stream plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.2 due to insufficient validati… Mitigation only Fix from $1,6002025-02-17 MEDIUM 5.4 CVE-2024-13834 The Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme plugin for WordPress is vulnerable to Server-… Responsive Addons 3.1.5+ Fix from $1,6002025-02-15 HIGH 7.7 CVE-2025-25297 Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's S3 storage integration feature contains a Server-Side Requ… Label Studio 1.16.0+ Fix from $1,9502025-02-14 HIGH 8.8 CVE-2024-9870 An external service interaction vulnerability in GitLab EE affecting all versions from 15.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to… GitLab 17.6.5 / 17.7.4+ Fix from $1,9502025-02-12 HIGH 7.7 CVE-2025-26494 Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server allows Authentication Bypass.This issue affects Tableau Server: from 20… Tableau Server after 2023.3.5 Fix from $1,9502025-02-11 HIGH 7.8 CVE-2025-22399 Dell UCC Edge, version 2.3.0, contains a Blind SSRF on Add Customer SFTP Server vulnerability. An unauthenticated attacker with local access could po… Utility Configuration Collector Edge Patch available Fix from $1,9502025-02-11 CRITICAL 9.8 CVE-2024-52606 SolarWinds Platform is affected by server-side request forgery vulnerability. Proper input sanitation was not applied allowing for the possibility of… Solarwinds Platform 2025.1+ Fix from $2,3002025-02-11 MEDIUM 6.5 CVE-2025-1211 Versions of the package hackney before 1.21.0 are vulnerable to Server-side Request Forgery (SSRF) due to improper parsing of URLs by URI built-in mo… Patch available Fix from $1,6002025-02-11