Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 5.4 CVE-2023-31456 There is an SSRF vulnerability in the Fluid Topics platform that affects versions prior to 4.3, where the server can be forced to make arbitrary requ… Mitigation only Fix from $1,6002024-07-16 MEDIUM 5.1 CVE-2024-36458 The vulnerability allows a malicious low-privileged PAM user to perform server upgrade related actions. No fix yet Fix from $1,6002024-07-15 HIGH 8.8 CVE-2024-40543 PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/ueditor?action=catchimage. Publiccms after 4.0.202302.e Fix from $1,9502024-07-12 HIGH 8.8 CVE-2024-40544 PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/#maintenance_sysTask/edit. Publiccms after 4.0.202302.e Fix from $1,9502024-07-12 HIGH 7.5 CVE-2024-32987 Microsoft SharePoint Server Information Disclosure Vulnerability Sharepoint Server Patch available Fix from $1,9502024-07-09 MEDIUM 5.0 CVE-2024-37171 SAP Transportation Management (Collaboration Portal) allows an attacker with non-administrative privileges to send a crafted request from a vulnerabl… Saptmui Mitigation only Fix from $1,6002024-07-09 MEDIUM 5.0 CVE-2024-34689 WebFlow Services of SAP Business Workflow allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by speciall… Business Workflow Mitigation only Fix from $1,6002024-07-09 HIGH 7.7 CVE-2024-39598 SAP CRM (WebClient UI Framework) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially craftin… Customer Relationship Management S4fnd Mitigation only Fix from $1,9502024-07-09 MEDIUM 5.0 CVE-2024-39699 Directus is a real-time API and App dashboard for managing SQL database content. There was already a reported SSRF vulnerability via file import. It … Directus 10.9.3+ Fix from $1,6002024-07-08 MEDIUM 5.8 CVE-2024-6095 A vulnerability in the /models/apply endpoint of mudler/localai versions 2.15.0 allows for Server-Side Request Forgery (SSRF) and partial Local File … Localai 2.17.0+ Fix from $1,6002024-07-06 CRITICAL 9.3 CVE-2024-37260 Server-Side Request Forgery (SSRF) vulnerability in Theme-Ruby Foxiz.This issue affects Foxiz: from n/a through 2.3.5. Foxiz 2.3.6+ Fix from $2,3002024-07-06 HIGH 8.8 CVE-2024-34361 Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. A vulnerability in versions prior … Pi Hole 5.18.3+ Fix from $1,9502024-07-05 HIGH 7.2 CVE-2024-39687 Fedify is a TypeScript library for building federated server apps powered by ActivityPub and other standards. At present, when Fedify needs to retrie… Patch available Fix from $1,9502024-07-05 CRITICAL 9.8 CVE-2024-29319 Volmarg Personal Management System 1.4.64 is vulnerable to SSRF (Server Side Request Forgery) via uploading a SVG file. The server can make unintende… Personal Management System No fix yet Fix from $2,3002024-07-05 HIGH 8.8 CVE-2024-6524 A vulnerability was found in ShopXO up to 6.1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the … Shopxo after 6.1.0 Fix from $1,9502024-07-05 MEDIUM 5.3 CVE-2024-37157 Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 on the `beta` and `tests-passe… Discourse 3.2.3 / 3.3.0+ Fix from $1,6002024-07-03 HIGH 7.5 CVE-2024-38472EPSS 69% SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users … HTTP Server 2.4.60+ Fix from $1,9502024-07-01 HIGH 8.2 CVE-2024-6424 External server-side request vulnerability in MESbook 20221021.03 version, which could allow a remote, unauthenticated attacker to exploit the endpoi… Mesbook Mitigation only Fix from $1,9502024-07-01 MEDIUM 5.4 CVE-2023-50952 IBM InfoSphere Information Server 11.7 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthor… Infosphere Information Server Mitigation only Fix from $1,6002024-06-30 HIGH 7.4 CVE-2024-38514 NextChat is a cross-platform ChatGPT/Gemini UI. There is a Server-Side Request Forgery (SSRF) vulnerability due to a lack of validation of the `endpo… Patch available Fix from $1,9502024-06-28 HIGH 7.5 CVE-2024-5736 Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla! extension in afGdStream.php script allows to access local files or server p… Admirorframes 5.0+ Fix from $1,9502024-06-28 HIGH 8.6 CVE-2024-5885 stangirard/quivr version 0.0.236 contains a Server-Side Request Forgery (SSRF) vulnerability. The application does not provide sufficient controls wh… Quivr No fix yet Fix from $1,9502024-06-27 CRITICAL 9.8 CVE-2024-5822 A Server-Side Request Forgery (SSRF) vulnerability exists in the upload processing interface of gaizhenbiao/ChuanhuChatGPT versions <= ChuanhuChatGPT… Chuanhuchatgpt No fix yet Fix from $2,3002024-06-27 CRITICAL 9.8 CVE-2024-37098 Server-Side Request Forgery (SSRF) vulnerability in Blossom Themes BlossomThemes Email Newsletter.This issue affects BlossomThemes Email Newsletter: … Blossomthemes Email Newsletter 2.2.7+ Fix from $2,3002024-06-26 MEDIUM 5.3 CVE-2024-34580 Apache XML Security for C++ through 2.0.4 implements the XML Signature Syntax and Processing (XMLDsig) specification without protection against an SS… Mitigation only Fix from $1,6002024-06-26 HIGH 7.3 CVE-2024-34581 The W3C XML Signature Syntax and Processing (XMLDsig) specification, starting with 1.0, was originally published with a "RetrievalMethod is a URI ...… Mitigation only Fix from $1,9502024-06-26 MEDIUM 6.5 CVE-2024-5014 In WhatsUp Gold versions released before 2023.1.3, a Server Side Request Forgery vulnerability exists in the GetASPReport feature. This allows any au… Whatsup Gold 23.1.3+ Fix from $1,6002024-06-25 HIGH 8.8 CVE-2024-5015 In WhatsUp Gold versions released before 2023.1.3, an authenticated SSRF vulnerability in Wug.UI.Areas.Wug.Controllers.SessionControler.Update allows… Whatsup Gold 23.1.3+ Fix from $1,9502024-06-25 MEDIUM 5.3 CVE-2023-45195 Adminer and AdminerEvo are vulnerable to SSRF via database connection fields. This could allow an unauthenticated remote attacker to enumerate or acc… Adminerevo 4.8.4+ Fix from $1,6002024-06-24 HIGH 7.2 CVE-2024-5746 A Server-Side Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with the Site Administrator role to g… Enterprise Server 3.9.16 / 3.10.13+ Fix from $1,9502024-06-20