Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.1
CVE-2024-41651
An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE: this is disp…
Prestashop
after 8.1.7
CRITICAL 10.0
CVE-2024-42467
openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. In versions 3.4.0.M4 through 4…
Openhab Web Interface
4.2.1+
CRITICAL 9.8
CVE-2024-41570
An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send arbitrary network traffic or…
Havoc
No fix yet
HIGH 7.5
CVE-2024-39338
axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs.
Axios
1.7.4+
CRITICAL 9.6
CVE-2024-6522
The Modern Events Calendar plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.12.1 via the 'me…
Modern Events Calendar
7.13.0+
MEDIUM 6.5
CVE-2024-38206EPSS 12%
An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a n…
Copilot Studio
Patch available
HIGH 7.5
CVE-2024-42352
Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. `nuxt/icon` provides an API to allow client …
Nuxt
1.4.5+
HIGH 7.3
CVE-2024-36448
** UNSUPPORTED WHEN ASSIGNED ** Server-Side Request Forgery (SSRF) vulnerability in Apache IoTDB Workbench.
This issue affects Apache IoTDB Workbenc…
Iotdb Workbench
Mitigation only
HIGH 8.6
CVE-2024-39713
A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
Rocket.chat
6.10.1+
MEDIUM 5.4
CVE-2024-39637
Server-Side Request Forgery (SSRF) vulnerability in pixelcurve Edubin edubin.This issue affects Edubin: from n/a through <= 9.2.0.
Mitigation only
HIGH 7.1
CVE-2024-38791
Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot allows Server Side Request Forgery.This issue affects AI En…
Ai Engine
2.4.8+
MEDIUM 6.4
CVE-2024-2090
The Remote Content Shortcode plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.5 via the remo…
Remote Content Shortcode
after 1.5
MEDIUM 6.3
CVE-2024-7330
A vulnerability has been found in YouDianCMS 7 and classified as critical. Affected by this vulnerability is the function curl_exec of the file /App/…
Youdiancms
No fix yet
CRITICAL 9.8
CVE-2024-6980
A verbose error handling issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request fo…
Gravityzone
6.38.1-5+
CRITICAL 9.8
CVE-2024-41120
streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `url` va…
Streamlit Geospatial
2024-07-19+
CRITICAL 9.8
CVE-2024-41118
streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `url` va…
Streamlit Geospatial
2024-07-19+
HIGH 7.5
CVE-2024-41812
txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Prior to version 1.7.0, a Server-Side …
Txtdot
1.7.0+
HIGH 7.5
CVE-2024-41813
txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Starting in version 1.4.0 and prior to…
Txtdot
1.6.1+
MEDIUM 6.9
CVE-2024-6922EPSS 30%
Automation Anywhere Automation 360 v21-v32 is vulnerable to Server-Side Request Forgery in a web API component. An attacker with unauthenticated acce…
Mitigation only
HIGH 8.3
CVE-2024-41668
The cBioPortal for Cancer Genomics provides visualization, analysis, and download of large-scale cancer genomics data sets. When running a publicly e…
Patch available
MEDIUM 5.4
CVE-2024-41664
Canarytokens help track activity and actions on a network. Prior to `sha-8ea5315`, Canarytokens.org was vulnerable to a blind SSRF in the Webhook ale…
Mitigation only
MEDIUM 6.5
CVE-2024-4260
The Page Builder Gutenberg Blocks WordPress plugin before 3.1.12 does not prevent users from pinging arbitrary hosts via some of its shortcodes, whi…
Coblocks
3.1.12+
MEDIUM 6.4
CVE-2024-38730
Server-Side Request Forgery (SSRF) vulnerability in Noor alam Magical Addons For Elementor.This issue affects Magical Addons For Elementor: from n/a …
Magical Addons For Elementor
1.1.42+
MEDIUM 6.4
CVE-2024-38723
Server-Side Request Forgery (SSRF) vulnerability in Bernhard Kux JSON Content Importer.This issue affects JSON Content Importer: from n/a through 1.5…
Json Content Importer
1.6.0+
MEDIUM 6.4
CVE-2024-38728
Server-Side Request Forgery (SSRF) vulnerability in Seraphinite Solutions Seraphinite Post .DOCX Source.This issue affects Seraphinite Post .DOCX Sou…
Seraphinite Post .docx Source
2.16.10+
HIGH 7.2
CVE-2024-37942
Server-Side Request Forgery (SSRF) vulnerability in Berqier Ltd BerqWP.This issue affects BerqWP: from n/a through 1.7.5.
Berqwp
1.7.6+
CRITICAL 9.1
CVE-2024-29736
A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style att…
Cxf
3.5.9 / 3.6.4+
HIGH 8.2
CVE-2024-21527
Versions of the package github.com/gotenberg/gotenberg/v8/pkg/gotenberg before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/pkg/m…
Patch available
MEDIUM 6.2
CVE-2024-30125
HCL BigFix Compliance server can respond with an HTTP status of 500, indicating a server-side error that may cause the server process to die.
Bigfix Compliance
2.0.11+
HIGH 7.5
CVE-2024-40898
SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF…
HTTP Server
2.4.62+