Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 8.1 CVE-2024-41651 An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE: this is disp… Prestashop after 8.1.7 Fix from $1,9502024-08-12 CRITICAL 10.0 CVE-2024-42467 openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. In versions 3.4.0.M4 through 4… Openhab Web Interface 4.2.1+ Fix from $2,3002024-08-12 CRITICAL 9.8 CVE-2024-41570 An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send arbitrary network traffic or… Havoc No fix yet Fix from $2,3002024-08-12 HIGH 7.5 CVE-2024-39338 axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs. Axios 1.7.4+ Fix from $1,9502024-08-12 CRITICAL 9.6 CVE-2024-6522 The Modern Events Calendar plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.12.1 via the 'me… Modern Events Calendar 7.13.0+ Fix from $2,3002024-08-07 MEDIUM 6.5 CVE-2024-38206EPSS 12% An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a n… Copilot Studio Patch available Fix from $1,6002024-08-06 HIGH 7.5 CVE-2024-42352 Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. `nuxt/icon` provides an API to allow client … Nuxt 1.4.5+ Fix from $1,9502024-08-05 HIGH 7.3 CVE-2024-36448 ** UNSUPPORTED WHEN ASSIGNED ** Server-Side Request Forgery (SSRF) vulnerability in Apache IoTDB Workbench. This issue affects Apache IoTDB Workbenc… Iotdb Workbench Mitigation only Fix from $1,9502024-08-05 HIGH 8.6 CVE-2024-39713 A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1. Rocket.chat 6.10.1+ Fix from $1,9502024-08-05 MEDIUM 5.4 CVE-2024-39637 Server-Side Request Forgery (SSRF) vulnerability in pixelcurve Edubin edubin.This issue affects Edubin: from n/a through <= 9.2.0. Mitigation only Fix from $1,6002024-08-01 HIGH 7.1 CVE-2024-38791 Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot allows Server Side Request Forgery.This issue affects AI En… Ai Engine 2.4.8+ Fix from $1,9502024-08-01 MEDIUM 6.4 CVE-2024-2090 The Remote Content Shortcode plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.5 via the remo… Remote Content Shortcode after 1.5 Fix from $1,6002024-08-01 MEDIUM 6.3 CVE-2024-7330 A vulnerability has been found in YouDianCMS 7 and classified as critical. Affected by this vulnerability is the function curl_exec of the file /App/… Youdiancms No fix yet Fix from $1,6002024-08-01 CRITICAL 9.8 CVE-2024-6980 A verbose error handling issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request fo… Gravityzone 6.38.1-5+ Fix from $2,3002024-07-31 CRITICAL 9.8 CVE-2024-41120 streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `url` va… Streamlit Geospatial 2024-07-19+ Fix from $2,3002024-07-26 CRITICAL 9.8 CVE-2024-41118 streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `url` va… Streamlit Geospatial 2024-07-19+ Fix from $2,3002024-07-26 HIGH 7.5 CVE-2024-41812 txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Prior to version 1.7.0, a Server-Side … Txtdot 1.7.0+ Fix from $1,9502024-07-26 HIGH 7.5 CVE-2024-41813 txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Starting in version 1.4.0 and prior to… Txtdot 1.6.1+ Fix from $1,9502024-07-26 MEDIUM 6.9 CVE-2024-6922EPSS 30% Automation Anywhere Automation 360 v21-v32 is vulnerable to Server-Side Request Forgery in a web API component. An attacker with unauthenticated acce… Mitigation only Fix from $1,6002024-07-26 HIGH 8.3 CVE-2024-41668 The cBioPortal for Cancer Genomics provides visualization, analysis, and download of large-scale cancer genomics data sets. When running a publicly e… Patch available Fix from $1,9502024-07-23 MEDIUM 5.4 CVE-2024-41664 Canarytokens help track activity and actions on a network. Prior to `sha-8ea5315`, Canarytokens.org was vulnerable to a blind SSRF in the Webhook ale… Mitigation only Fix from $1,6002024-07-23 MEDIUM 6.5 CVE-2024-4260 The Page Builder Gutenberg Blocks WordPress plugin before 3.1.12 does not prevent users from pinging arbitrary hosts via some of its shortcodes, whi… Coblocks 3.1.12+ Fix from $1,6002024-07-23 MEDIUM 6.4 CVE-2024-38730 Server-Side Request Forgery (SSRF) vulnerability in Noor alam Magical Addons For Elementor.This issue affects Magical Addons For Elementor: from n/a … Magical Addons For Elementor 1.1.42+ Fix from $1,6002024-07-22 MEDIUM 6.4 CVE-2024-38723 Server-Side Request Forgery (SSRF) vulnerability in Bernhard Kux JSON Content Importer.This issue affects JSON Content Importer: from n/a through 1.5… Json Content Importer 1.6.0+ Fix from $1,6002024-07-22 MEDIUM 6.4 CVE-2024-38728 Server-Side Request Forgery (SSRF) vulnerability in Seraphinite Solutions Seraphinite Post .DOCX Source.This issue affects Seraphinite Post .DOCX Sou… Seraphinite Post .docx Source 2.16.10+ Fix from $1,6002024-07-22 HIGH 7.2 CVE-2024-37942 Server-Side Request Forgery (SSRF) vulnerability in Berqier Ltd BerqWP.This issue affects BerqWP: from n/a through 1.7.5. Berqwp 1.7.6+ Fix from $1,9502024-07-22 CRITICAL 9.1 CVE-2024-29736 A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style att… Cxf 3.5.9 / 3.6.4+ Fix from $2,3002024-07-19 HIGH 8.2 CVE-2024-21527 Versions of the package github.com/gotenberg/gotenberg/v8/pkg/gotenberg before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/pkg/m… Patch available Fix from $1,9502024-07-19 MEDIUM 6.2 CVE-2024-30125 HCL BigFix Compliance server can respond with an HTTP status of 500, indicating a server-side error that may cause the server process to die. Bigfix Compliance 2.0.11+ Fix from $1,6002024-07-18 HIGH 7.5 CVE-2024-40898 SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF… HTTP Server 2.4.62+ Fix from $1,9502024-07-18