Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 8.6 CVE-2024-37818 Strapi v4.24.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /strapi.io/_next/image. This vulnerability allows att… Strapi No fix yet Fix from $1,9502024-06-20 CRITICAL 9.3 CVE-2024-5021 The WordPress Picture / Portfolio / Media Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includ… Mitigation only Fix from $2,3002024-06-19 CRITICAL 9.6 CVE-2024-4404 The ElementsKit PRO plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.6.2 via the 'render_raw' fu… Elementskit 3.6.3+ Fix from $2,3002024-06-14 HIGH 8.5 CVE-2024-37164 Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. CVAT allows users to supply custom endp… Computer Vision Annotation Tool 2.14.3+ Fix from $1,9502024-06-13 HIGH 8.8 CVE-2024-34111 Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could… Commerce after 1.4.0 Fix from $1,9502024-06-13 HIGH 7.5 CVE-2024-36471 Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL.  Project administrators can run these imp… Allura 1.17.0+ Fix from $1,9502024-06-10 MEDIUM 6.5 CVE-2024-36414 SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in the co… Suitecrm 7.14.4 / 8.6.1+ Fix from $1,6002024-06-10 MEDIUM 6.4 CVE-2024-4354 The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including… Tablepress 2.3.2+ Fix from $1,6002024-06-07 CRITICAL 9.3 CVE-2024-5328 A Server-Side Request Forgery (SSRF) vulnerability exists in the lunary-ai/lunary application, specifically within the endpoint '/auth/saml/tto/downl… Lunary No fix yet Fix from $2,3002024-06-06 HIGH 7.2 CVE-2024-5186 A Server-Side Request Forgery (SSRF) vulnerability exists in the file upload section of imartinez/privategpt version 0.5.0. This vulnerability allows… Privategpt No fix yet Fix from $1,9502024-06-06 HIGH 7.7 CVE-2024-4851 A Server-Side Request Forgery (SSRF) vulnerability exists in the stangirard/quivr application, version 0.0.204, which allows attackers to access inte… Quivr No fix yet Fix from $1,9502024-06-06 HIGH 8.8 CVE-2024-3149 A Server-Side Request Forgery (SSRF) vulnerability exists in the upload link feature of mintplex-labs/anything-llm. This feature, intended for users … Anythingllm 1.0.0+ Fix from $1,9502024-06-06 HIGH 7.7 CVE-2024-3095 A Server-Side Request Forgery (SSRF) vulnerability exists in the Web Research Retriever component of langchain-ai/langchain version 0.1.5. The vulner… Langchain 0.2.9+ Fix from $1,9502024-06-06 CRITICAL 9.8 CVE-2024-5482 A Server-Side Request Forgery (SSRF) vulnerability exists in the 'add_webpage' endpoint of the parisneo/lollms-webui application, affecting the lates… Lollms Web Ui No fix yet Fix from $2,3002024-06-06 HIGH 8.6 CVE-2024-4325EPSS 37% A Server-Side Request Forgery (SSRF) vulnerability exists in the gradio-app/gradio version 4.21.0, specifically within the `/queue/join` endpoint and… Gradio 4.41.0+ Fix from $1,9502024-06-06 HIGH 8.8 CVE-2024-3152 mintplex-labs/anything-llm is vulnerable to multiple security issues due to improper input validation in several endpoints. An attacker can exploit t… Anythingllm 1.0.0+ Fix from $1,9502024-06-06 CRITICAL 9.8 CVE-2024-4177 A host whitelist parser issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request for… Gravityzone 6.38.1-2+ Fix from $2,3002024-06-06 MEDIUM 5.3 CVE-2024-20404EPSS 23% A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on a… Finesse 11.6+ Fix from $1,6002024-06-05 CRITICAL 9.1 CVE-2024-5526 Grafana OnCall is an easy-to-use on-call management tool that will help reduce toil in on-call management through simpler workflows and interfaces th… Oncall 1.5.2+ Fix from $2,3002024-06-05 HIGH 7.5 CVE-2024-4084 A Server-Side Request Forgery (SSRF) vulnerability exists in the latest version of mintplex-labs/anything-llm, allowing attackers to bypass the offic… Anythingllm after 1.5.4 Fix from $1,9502024-06-05 CRITICAL 9.1 CVE-2024-36675 LyLme_spage v1.9.5 is vulnerable to Server-Side Request Forgery (SSRF) via the get_head function. Lylme Spage No fix yet Fix from $2,3002024-06-04 CRITICAL 9.1 CVE-2024-4219 Prior to 23.2, it is possible to perform arbitrary Server-Side requests via HTTP-based connectors within BeyondInsight, resulting in a server-side re… Beyondinsight 23.2+ Fix from $2,3002024-06-04 MEDIUM 6.4 CVE-2023-7073 The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including,… Mitigation only Fix from $1,6002024-05-31 HIGH 7.5 CVE-2024-4469 The WP STAGING WordPress Backup Plugin WordPress plugin before 3.5.0 does not prevent users with the administrator role from pinging conducting SSRF… Wp Staging 3.5.0+ Fix from $1,9502024-05-31 HIGH 8.1 CVE-2024-36427 The file-serving function in TARGIT Decision Suite before 24.06.19002 (TARGIT Decision Suite 2024 – June) allows authenticated attackers to read or w… Mitigation only Fix from $1,9502024-05-29 HIGH 8.1 CVE-2024-29415EPSS 8% The ip package through 2.0.1 for Node.js might allow SSRF because some IP addresses (such as 127.1, 01200034567, 012.1.2.3, 000:0:0000::01, and ::fFF… Patch available Fix from $1,9502024-05-27 CRITICAL 9.1 CVE-2024-4399 The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack Central Authentication Service No fix yet Fix from $2,3002024-05-23 MEDIUM 5.3 CVE-2024-1855 The WPCafe – Restaurant Menu, Online Ordering for WooCommerce, Pickup / Delivery and Table Reservation plugin for WordPress is vulnerable to Server-S… Wpcafe 2.2.24+ Fix from $1,6002024-05-23 CRITICAL 9.1 CVE-2024-25738 A Server-Side Request Forgery (SSRF) vulnerability in the /Upgrade/FixConfig route in Open Library Foundation VuFind 2.0 through 9.1 before 9.1.1 all… Mitigation only Fix from $2,3002024-05-22 MEDIUM 6.4 CVE-2024-5031 The Memberpress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.11.29 via the 'mepr-u… Memberpress 1.11.30+ Fix from $1,6002024-05-22