Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2024-10524
Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these c…
Mitigation only
CRITICAL 9.8
CVE-2024-47208
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz.
This issue affects Apac…
Ofbiz
18.12.17+
HIGH 8.8
CVE-2021-3742
A Server-Side Request Forgery (SSRF) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.5.0. The vulnerability allo…
Chatwoot
2.5.0+
HIGH 7.7
CVE-2024-49521
Adobe Commerce versions 3.2.5 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to a security feature by…
Commerce
3.2.6+
MEDIUM 6.4
CVE-2024-10814
The Code Embed plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5 via the ce_get_file() func…
Mitigation only
CRITICAL 9.1
CVE-2024-50811
hopetree izone lts c011b48 contains a server-side request forgery (SSRF) vulnerability in the active push function as \\apps\\tool\\apis\\bd_push.py …
Mitigation only
MEDIUM 6.5
CVE-2024-46947
Northern.tech Mender before 3.6.6 and 3.7.x before 3.7.7 allows SSRF.
Mitigation only
HIGH 7.5
CVE-2024-48951
An issue was discovered in Logpoint before 7.5.0. Server-Side Request Forgery (SSRF) on SOAR can be used to leak Logpoint's API Token leading to auth…
Siem
7.5.0+
MEDIUM 6.5
CVE-2024-20531
A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of a…
Identity Services Engine
Mitigation only
CRITICAL 9.8
CVE-2024-51358
An issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a crafted script to the Add new application.
Mitigation only
HIGH 8.8
CVE-2024-51740
Combodo iTop is a simple, web based IT Service Management tool. This vulnerability can be used to create HTTP requests on behalf of the server, from …
Itop
2.7.11 / 3.0.5+
MEDIUM 6.5
CVE-2024-48052
In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_…
Gradio
after 4.42.0
MEDIUM 6.5
CVE-2024-51408
AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadata credent…
Appsmith
1.46+
HIGH 7.5
CVE-2024-48360
Qualitor v8.24 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /request/viewValidacao.php.
Qualitor
No fix yet
MEDIUM 6.1
CVE-2024-48346
xtreme1 <= v0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the /api/data/upload path. The vulnerability is triggered through th…
Mitigation only
MEDIUM 6.5
CVE-2024-51242
A Server-Side Request Forgery (SSRF) vulnerability has been identified in eladmin 2.7 and earlier in ServerDeployController.java. The manipulation of…
Eladmin
after 2.7
MEDIUM 6.5
CVE-2024-48107
SparkShop <=1.1.7 is vulnerable to server-side request forgery (SSRF). This vulnerability allows attacks to scan ports on the Intranet or local netwo…
Sparkshop
after 1.1.7
HIGH 8.1
CVE-2024-48178
newbee-mall v1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via the goodsCoverImg parameter.
Newbee Mall
No fix yet
MEDIUM 6.5
CVE-2024-48450
An arbitrary file upload vulnerability in Huly Platform v0.6.295 allows attackers to execute arbitrary code via uploading a crafted HTML file into ch…
Mitigation only
CRITICAL 9.1
CVE-2024-47883
The OpenRefine fork of the MIT Simile Butterfly server is a modular web application framework. The Butterfly framework uses the `java.net.URL` class …
Butterfly
after 1.2.6
HIGH 8.8
CVE-2024-45518EPSS 20%
An issue was discovered in Zimbra Collaboration (ZCS) 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41, and 8.8.15 before Patch 46. …
Collaboration
10.0.9+
HIGH 8.6
CVE-2024-49312
Server-Side Request Forgery (SSRF) vulnerability in WisdmLabs Edwiser Bridge edwiser-bridge.This issue affects Edwiser Bridge: from n/a through <= 3.…
Bridge
3.0.8+
HIGH 8.3
CVE-2012-10018
The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and including 6.1, 1.0 respective…
Mapplic
after 6.1
HIGH 7.5
CVE-2024-46468
A Server-Side Request Forgery (SSRF) vulnerability exists in the jpress <= v5.1.1, which can be exploited by an attacker to obtain sensitive informat…
Jpress
after 5.1.1
MEDIUM 5.8
CVE-2024-47830
Plane is an open-source project management tool. Plane uses the ** wildcard support to retrieve the image from any hostname as in /web/next.config.js…
Plane
0.23.0+
HIGH 7.5
CVE-2024-45317
A Server-Side Request Forgery (SSRF) vulnerability in SMA1000 appliance firmware versions 12.4.3-02676 and earlier allows a remote, unauthenticated a…
Mitigation only
CRITICAL 9.8
CVE-2024-47167
Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **Server-Side Request Forgery (SSRF)** in the `…
Gradio
5.0.0+
HIGH 8.1
CVE-2024-8977
An issue has been discovered in GitLab EE affecting all versions starting from 15.10 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior …
GitLab
17.2.9 / 17.3.5+
HIGH 7.5
CVE-2024-47008EPSS 47%
Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.
Avalanche
6.4.5+
HIGH 7.5
CVE-2024-45290
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file which links m…
Phpspreadsheet
1.29.2 / 2.1.1+