Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 8.8 CVE-2024-45291 PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file that links im… Phpspreadsheet 1.29.2 / 2.1.1+ Fix from $1,9502024-10-07 MEDIUM 5.3 CVE-2024-9410 Ada.cx's Sentry configuration allowed for blind server-side request forgeries (SSRF) through the use of a data scraping endpoint. Ada 2024-10-01+ Fix from $1,6002024-10-04 MEDIUM 5.4 CVE-2024-45843 Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker … Mattermost Server 9.5.9+ Fix from $1,6002024-09-26 CRITICAL 9.8 CVE-2024-47222 New Cloud MyOffice SDK Collaborative Editing Server 2.2.2 through 2.8 allows SSRF via manipulation of requests from external document storage via the… My Office Sdk after 2.8.0 Fix from $2,3002024-09-23 MEDIUM 6.6 CVE-2024-40441 An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a d… Mitigation only Fix from $1,6002024-09-23 HIGH 8.8 CVE-2024-47066EPSS 12% Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forgery protection implemented in `… Lobe Chat 1.19.3+ Fix from $1,9502024-09-23 HIGH 7.5 CVE-2024-43989EPSS 13% Server-Side Request Forgery (SSRF) vulnerability in Firsh Justified Image Grid justified-image-grid.This issue affects Justified Image Grid: from n/a… Mitigation only Fix from $1,9502024-09-23 MEDIUM 5.0 CVE-2024-46990 Directus is a real-time API and App dashboard for managing SQL database content. When relying on blocking access to localhost using the default `0.0.… Directus 10.13.3 / 11.1.0+ Fix from $1,6002024-09-18 MEDIUM 6.5 CVE-2022-25777 Prior to the patched version, an authenticated user of Mautic could read system files and access the internal addresses of the application due to a S… Mautic 4.4.12 / 5.0.4+ Fix from $1,6002024-09-18 CRITICAL 9.8 CVE-2024-38183 An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network. Groupme Patch available Fix from $2,3002024-09-17 HIGH 8.2 CVE-2024-47049 The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrl and make… File Handling 1.5.0 / 2.3.0+ Fix from $1,9502024-09-17 HIGH 7.5 CVE-2024-6587EPSS 37% A Server-Side Request Forgery (SSRF) vulnerability exists in berriai/litellm version 1.38.10. This vulnerability allows users to specify the `api_bas… Litellm Patch available Fix from $1,9502024-09-13 MEDIUM 6.5 CVE-2024-8635 A server-side request forgery issue has been discovered in GitLab EE affecting all versions starting from 16.8 prior to 17.1.7, from 17.2 prior to 17… GitLab 17.1.7 / 17.2.5+ Fix from $1,6002024-09-12 CRITICAL 9.8 CVE-2021-38132 Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000. Edirectory 9.2.6.0000+ Fix from $2,3002024-09-12 CRITICAL 9.8 CVE-2024-44677 eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabaseContro… Eladmin after 2.7 Fix from $2,3002024-09-10 HIGH 8.8 CVE-2023-37229 Loftware Spectrum before 5.1 allows SSRF. Spectrum 5.1+ Fix from $1,9502024-09-10 HIGH 8.8 CVE-2023-37230 Loftware Spectrum (testDeviceConnection) before 5.1 allows SSRF. Spectrum 5.1+ Fix from $1,9502024-09-10 CRITICAL 9.8 CVE-2024-44721 SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php. Seacms No fix yet Fix from $2,3002024-09-09 HIGH 8.8 CVE-2024-40718 A server side request forgery vulnerability allows a low-privileged user to perform local privilege escalation through exploiting an SSRF vulnerabili… Mitigation only Fix from $1,9502024-09-07 CRITICAL 9.1 CVE-2024-24759 MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-sid… Mindsdb 23.12.4.2+ Fix from $2,3002024-09-05 CRITICAL 9.8 CVE-2024-45507EPSS 93% Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apac… Ofbiz 18.12.16+ Fix from $2,3002024-09-04 MEDIUM 6.5 CVE-2024-43371 CKAN is an open-source data management system for powering data hubs and data portals. There are a number of CKAN plugins, including XLoader, DataPus… Ckan 2.10.5+ Fix from $1,6002024-08-21 HIGH 7.2 CVE-2022-1751 The Skitter Slideshow plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.2 via the /image.ph… Mitigation only Fix from $1,9502024-08-17 MEDIUM 6.5 CVE-2024-22217 A Server-Side Request Forgery (SSRF) vulnerability in Terminalfour before 8.3.19 allows authenticated users to use specific features to access intern… Terminalfour 8.3.19+ Fix from $1,6002024-08-15 MEDIUM 6.3 CVE-2024-22219 XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows authenticated users to submi… Mitigation only Fix from $1,6002024-08-15 CRITICAL 9.8 CVE-2024-7743 A vulnerability was found in wanglongcn ltcms 1.0.20. It has been declared as critical. Affected by this vulnerability is the function downloadUrl of… Ltcms No fix yet Fix from $2,3002024-08-13 CRITICAL 9.8 CVE-2024-7742 A vulnerability was found in wanglongcn ltcms 1.0.20. It has been classified as critical. Affected is the function multiDownload of the file /api/fil… Ltcms No fix yet Fix from $2,3002024-08-13 CRITICAL 9.8 CVE-2024-7740 A vulnerability has been found in wanglongcn ltcms 1.0.20 and classified as critical. This vulnerability affects the function download of the file /a… Ltcms No fix yet Fix from $2,3002024-08-13 HIGH 8.8 CVE-2024-38109 An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a … Azure Health Bot Patch available Fix from $1,9502024-08-13 MEDIUM 5.0 CVE-2024-41737 SAP CRM ABAP (Insights Management) allows an authenticated attacker to enumerate HTTP endpoints in the internal network by specially crafting HTTP re… Crm Abap Insights Management Mitigation only Fix from $1,6002024-08-13