Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 8.8 CVE-2024-13029 A vulnerability, which was classified as problematic, was found in Antabot White-Jotter up to 0.2.2. Affected is an unknown function of the file /adm… White Jotter after 0.2.2 Fix from $1,9502024-12-30 HIGH 7.5 CVE-2024-50714 A Server-Side Request Forgery (SSRF) in smarts-srl.com Smart Agent v.1.1.0 allows a remote attacker to obtain sensitive information via a crafted scr… Mitigation only Fix from $1,9502024-12-27 MEDIUM 5.3 CVE-2024-12989 A vulnerability was found in WISI Tangram GT31 up to 20241214 and classified as problematic. Affected by this issue is some unknown functionality of … Mitigation only Fix from $1,6002024-12-27 MEDIUM 5.4 CVE-2024-51463 IBM i 7.3, 7.4, and 7.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests… I Mitigation only Fix from $1,6002024-12-21 HIGH 8.8 CVE-2024-12867 Server-Side Request Forgery in URL Mapper in Arctic Security's Arctic Hub versions 3.0.1764-5.6.1877 allows an unauthenticated remote attacker to exf… Mitigation only Fix from $1,9502024-12-20 MEDIUM 5.4 CVE-2024-49336 IBM Security Guardium 11.5 and 12.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorize… Security Guardium Mitigation only Fix from $1,6002024-12-19 HIGH 7.5 CVE-2024-55082 A Server-Side Request Forgery (SSRF) in the endpoint http://{your-server}/url-to-pdf of Stirling-PDF 0.35.1 allows attackers to access sensitive info… Mitigation only Fix from $1,9502024-12-19 MEDIUM 5.4 CVE-2024-12121 The Broken Link Checker | Finder plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.5.0 … Mitigation only Fix from $1,6002024-12-19 MEDIUM 5.4 CVE-2024-52579 Misskey is an open source, federated social media platform. Some APIs using `HttpRequestService` do not properly check the target host. This vulnerab… Misskey 2024.11.0+ Fix from $1,6002024-12-18 HIGH 7.2 CVE-2024-55086 In the GetSimple CMS CE 3.3.19 management page, Server-Side Request Forgery (SSRF) can be achieved in the plug-in download address in the backend man… Getsimple Cms Mitigation only Fix from $1,9502024-12-18 HIGH 7.6 CVE-2024-9624 The WP All Import Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.9.3 due to missing SS… Mitigation only Fix from $1,9502024-12-17 HIGH 7.2 CVE-2024-54385EPSS 5% Server-Side Request Forgery (SSRF) vulnerability in princeahmed Radio Player radio-player allows Server Side Request Forgery.This issue affects Radio… Mitigation only Fix from $1,9502024-12-16 HIGH 7.2 CVE-2024-54330 Server-Side Request Forgery (SSRF) vulnerability in hurraki Hurrakify hurrakify allows Server Side Request Forgery.This issue affects Hurrakify: from… Mitigation only Fix from $1,9502024-12-13 HIGH 7.5 CVE-2024-11836 Server-Side Request Forgery (SSRF) vulnerability in PlexTrac allowing requests to internal system resources.This issue affects PlexTrac: from 1.61.3 … Plextrac 2.8.1+ Fix from $1,9502024-12-13 CRITICAL 9.8 CVE-2024-55875 http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 6.50.0.0, there is a potential XXE (XML External Entity Injection) vuln… Patch available Fix from $2,3002024-12-12 HIGH 7.2 CVE-2024-54197 SAP NetWeaver Administrator(System Overview) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by speci… Mitigation only Fix from $1,9502024-12-10 CRITICAL 9.1 CVE-2024-47578 Adobe Document Service allows an attacker with administrator privileges to send a crafted request from a vulnerable web application. It is usually us… Mitigation only Fix from $2,3002024-12-10 CRITICAL 9.8 CVE-2024-48874 Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could give attackers the ability to force Ruijie's proxy servers to perform any requ… Reyee Os 2.320.0+ Fix from $2,3002024-12-06 CRITICAL 9.1 CVE-2023-50913 Oxide control plane software before 5 allows SSRF. Mitigation only Fix from $2,3002024-12-05 CRITICAL 9.9 CVE-2024-6784 Server-Side Request Forgery vulnerabilities were found providing a potential for access to unauthorized resources and unintended information disclosu… Aspect Ent 2 Firmware 3.08.03+ Fix from $2,3002024-12-05 MEDIUM 6.5 CVE-2024-45206 A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the netw… Veeam Service Provider Console 8.1.0.21377+ Fix from $1,6002024-12-04 HIGH 7.5 CVE-2024-54000 Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analy… Mobile Security Framework 3.9.7+ Fix from $1,9502024-12-03 MEDIUM 5.4 CVE-2024-53983 The Backstage Scaffolder plugin Houses types and utilities for building scaffolder-related modules. A vulnerability is identified in Backstage Scaffo… Mitigation only Fix from $1,6002024-11-29 HIGH 8.6 CVE-2024-32965EPSS 24% Lobe Chat is an open-source, AI chat framework. Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnerability. An attacker can const… Lobe Chat 1.19.13+ Fix from $1,9502024-11-26 MEDIUM 5.3 CVE-2024-6538 A flaw was found in OpenShift Console. A Server Side Request Forgery (SSRF) attack can happen if an attacker supplies all or part of a URL to the ser… Mitigation only Fix from $1,6002024-11-25 HIGH 8.3 CVE-2024-9710 PostHog database_schema Server-Side Request Forgery Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sens… Posthog 2024-10-04+ Fix from $1,9502024-11-22 HIGH 7.3 CVE-2024-11618 A vulnerability classified as critical was found in IPC Unigy Management System 04.03.00.08.0027. Affected by this vulnerability is an unknown functi… Mitigation only Fix from $1,9502024-11-22 MEDIUM 6.5 CVE-2024-38645 A server-side request forgery (SSRF) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote au… Notes Station 3 3.9.7+ Fix from $1,6002024-11-22 CRITICAL 9.8 CVE-2021-38135 Possible External Service Interaction attack in iManager has been discovered in OpenText™ iManager 3.2.6.0000. Imanager after 3.2.5 Fix from $2,3002024-11-22 HIGH 7.5 CVE-2024-52598 2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Two interconnected vulnerabilities exist in… 2fauth 5.4.1+ Fix from $1,9502024-11-20