Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 6.5 CVE-2024-10524 Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these c… Mitigation only Fix from $1,6002024-11-19 CRITICAL 9.8 CVE-2024-47208 Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apac… Ofbiz 18.12.17+ Fix from $2,3002024-11-18 HIGH 8.8 CVE-2021-3742 A Server-Side Request Forgery (SSRF) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.5.0. The vulnerability allo… Chatwoot 2.5.0+ Fix from $1,9502024-11-15 HIGH 7.7 CVE-2024-49521 Adobe Commerce versions 3.2.5 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to a security feature by… Commerce 3.2.6+ Fix from $1,9502024-11-12 MEDIUM 6.4 CVE-2024-10814 The Code Embed plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5 via the ce_get_file() func… Mitigation only Fix from $1,6002024-11-09 CRITICAL 9.1 CVE-2024-50811 hopetree izone lts c011b48 contains a server-side request forgery (SSRF) vulnerability in the active push function as \\apps\\tool\\apis\\bd_push.py … Mitigation only Fix from $2,3002024-11-08 MEDIUM 6.5 CVE-2024-46947 Northern.tech Mender before 3.6.6 and 3.7.x before 3.7.7 allows SSRF. Mitigation only Fix from $1,6002024-11-08 HIGH 7.5 CVE-2024-48951 An issue was discovered in Logpoint before 7.5.0. Server-Side Request Forgery (SSRF) on SOAR can be used to leak Logpoint's API Token leading to auth… Siem 7.5.0+ Fix from $1,9502024-11-07 MEDIUM 6.5 CVE-2024-20531 A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of a… Identity Services Engine Mitigation only Fix from $1,6002024-11-06 CRITICAL 9.8 CVE-2024-51358 An issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a crafted script to the Add new application. Mitigation only Fix from $2,3002024-11-05 HIGH 8.8 CVE-2024-51740 Combodo iTop is a simple, web based IT Service Management tool. This vulnerability can be used to create HTTP requests on behalf of the server, from … Itop 2.7.11 / 3.0.5+ Fix from $1,9502024-11-05 MEDIUM 6.5 CVE-2024-48052 In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_… Gradio after 4.42.0 Fix from $1,6002024-11-04 MEDIUM 6.5 CVE-2024-51408 AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadata credent… Appsmith 1.46+ Fix from $1,6002024-11-04 HIGH 7.5 CVE-2024-48360 Qualitor v8.24 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /request/viewValidacao.php. Qualitor No fix yet Fix from $1,9502024-10-31 MEDIUM 6.1 CVE-2024-48346 xtreme1 <= v0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the /api/data/upload path. The vulnerability is triggered through th… Mitigation only Fix from $1,6002024-10-30 MEDIUM 6.5 CVE-2024-51242 A Server-Side Request Forgery (SSRF) vulnerability has been identified in eladmin 2.7 and earlier in ServerDeployController.java. The manipulation of… Eladmin after 2.7 Fix from $1,6002024-10-30 MEDIUM 6.5 CVE-2024-48107 SparkShop <=1.1.7 is vulnerable to server-side request forgery (SSRF). This vulnerability allows attacks to scan ports on the Intranet or local netwo… Sparkshop after 1.1.7 Fix from $1,6002024-10-28 HIGH 8.1 CVE-2024-48178 newbee-mall v1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via the goodsCoverImg parameter. Newbee Mall No fix yet Fix from $1,9502024-10-28 MEDIUM 6.5 CVE-2024-48450 An arbitrary file upload vulnerability in Huly Platform v0.6.295 allows attackers to execute arbitrary code via uploading a crafted HTML file into ch… Mitigation only Fix from $1,6002024-10-25 CRITICAL 9.1 CVE-2024-47883 The OpenRefine fork of the MIT Simile Butterfly server is a modular web application framework. The Butterfly framework uses the `java.net.URL` class … Butterfly after 1.2.6 Fix from $2,3002024-10-24 HIGH 8.8 CVE-2024-45518EPSS 20% An issue was discovered in Zimbra Collaboration (ZCS) 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41, and 8.8.15 before Patch 46. … Collaboration 10.0.9+ Fix from $1,9502024-10-22 HIGH 8.6 CVE-2024-49312 Server-Side Request Forgery (SSRF) vulnerability in WisdmLabs Edwiser Bridge edwiser-bridge.This issue affects Edwiser Bridge: from n/a through <= 3.… Bridge 3.0.8+ Fix from $1,9502024-10-17 HIGH 8.3 CVE-2012-10018 The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and including 6.1, 1.0 respective… Mapplic after 6.1 Fix from $1,9502024-10-16 HIGH 7.5 CVE-2024-46468 A Server-Side Request Forgery (SSRF) vulnerability exists in the jpress <= v5.1.1, which can be exploited by an attacker to obtain sensitive informat… Jpress after 5.1.1 Fix from $1,9502024-10-11 MEDIUM 5.8 CVE-2024-47830 Plane is an open-source project management tool. Plane uses the ** wildcard support to retrieve the image from any hostname as in /web/next.config.js… Plane 0.23.0+ Fix from $1,6002024-10-11 HIGH 7.5 CVE-2024-45317 A Server-Side Request Forgery (SSRF) vulnerability in SMA1000 appliance firmware versions 12.4.3-02676 and earlier allows a remote, unauthenticated a… Mitigation only Fix from $1,9502024-10-11 CRITICAL 9.8 CVE-2024-47167 Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **Server-Side Request Forgery (SSRF)** in the `… Gradio 5.0.0+ Fix from $2,3002024-10-10 HIGH 8.1 CVE-2024-8977 An issue has been discovered in GitLab EE affecting all versions starting from 15.10 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior … GitLab 17.2.9 / 17.3.5+ Fix from $1,9502024-10-10 HIGH 7.5 CVE-2024-47008EPSS 47% Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information. Avalanche 6.4.5+ Fix from $1,9502024-10-08 HIGH 7.5 CVE-2024-45290 PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file which links m… Phpspreadsheet 1.29.2 / 2.1.1+ Fix from $1,9502024-10-07