Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 6.4 CVE-2024-4789 Cost Calculator Builder Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to 3.1.72, via the send_demo_webhook… Mitigation only Fix from $1,6002024-05-17 HIGH 8.2 CVE-2023-46784 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Server-Side Request Forgery (SSRF) vulnerability in Room 34 Creative … Mitigation only Fix from $1,9502024-05-17 HIGH 7.5 CVE-2024-3970 Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure by… Imanager 3.2.6+ Fix from $1,9502024-05-15 HIGH 7.5 CVE-2024-3485 Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure. Imanager 3.2.6+ Fix from $1,9502024-05-15 MEDIUM 5.3 CVE-2024-4894 ITPison OMICARD EDM fails to properly filter specific URL parameter, allowing unauthenticated remote attackers to modify the parameters and conduct … Mitigation only Fix from $1,6002024-05-15 MEDIUM 5.3 CVE-2024-4561 In WhatsUp Gold versions released before 2023.1.2 , a blind SSRF vulnerability exists in Whatsup Gold's FaviconController that allows an attacker t… Whatsup Gold 23.1.2+ Fix from $1,6002024-05-14 MEDIUM 5.4 CVE-2024-4562 In WhatsUp Gold versions released before 2023.1.2 , an SSRF vulnerability exists in Whatsup Gold's Issue exists in the HTTP Monitoring functional… Whatsup Gold 23.1.2+ Fix from $1,6002024-05-14 MEDIUM 5.0 CVE-2024-0862 The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains a Server-Side Request Forgery vulnerability that allows an authentica… Mitigation only Fix from $1,6002024-05-14 MEDIUM 5.9 CVE-2024-33864 An issue was discovered in linqi before 1.4.0.1 on Windows. There is SSRF via Document template generation; i.e., via remote images in process creati… Linqi 1.4.0.1+ Fix from $1,6002024-05-14 HIGH 7.5 CVE-2024-34351EPSS 5% Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery (SSRF) vulnerability was iden… Next.js 14.1.1+ Fix from $1,9502024-05-14 HIGH 7.2 CVE-2024-33250 An issue in Open-Source Technology Committee SRS real-time video server RS/4.0.268(Leo) and SRS/4.0.195(Leo) allows a remote attacker to execute arbi… Mitigation only Fix from $1,9502024-05-14 CRITICAL 9.0 CVE-2024-32964EPSS 53% Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat … Lobe Chat 0.150.6+ Fix from $2,3002024-05-14 CRITICAL 9.6 CVE-2024-33857 An issue was discovered in Logpoint before 7.4.0. Due to a lack of input validation on URLs in threat intelligence, an attacker with low-level access… Siem 7.4.0+ Fix from $2,3002024-05-07 MEDIUM 5.3 CVE-2024-33117 crmeb_java v1.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the mergeList method in class com.zbkj.front.pub.ImageMergeContr… Crmeb Java Mitigation only Fix from $1,6002024-05-06 MEDIUM 6.4 CVE-2024-34068 Pterodactyl wings is the server control plane for Pterodactyl Panel. An authenticated user who has access to a game server is able to bypass the prev… Wings 1.11.2+ Fix from $1,6002024-05-03 HIGH 7.2 CVE-2024-3047 The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, … Woocommerce Pdf Invoices\& Packing Slips 3.8.1+ Fix from $1,9502024-05-02 CRITICAL 9.8 CVE-2023-46295 An issue was discovered in Teledyne FLIR M300 2.00-19. Unauthenticated remote code execution can occur in the web server. An attacker can exploit thi… Mitigation only Fix from $2,3002024-05-01 MEDIUM 5.0 CVE-2024-23336 MyBB is a free and open source forum software. The default list of disallowed remote hosts does not contain the `127.0.0.0/8` block, which may result… Mybb 1.8.38+ Fix from $1,6002024-05-01 MEDIUM 6.3 CVE-2024-33832 OneNav v0.9.35-20240318 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /index.php?c=api&method=get_link_info. Mitigation only Fix from $1,6002024-04-30 HIGH 8.3 CVE-2024-2663 The ZD YouTube FLV Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2.6 via the $_GET… Mitigation only Fix from $1,9502024-04-30 MEDIUM 6.4 CVE-2024-0216 The Google Doc Embedder plugin for WordPress is vulnerable to Server Side Request Forgery via the 'gview' shortcode in versions up to, and including,… Mitigation only Fix from $1,6002024-04-30 MEDIUM 5.0 CVE-2024-33590 Server-Side Request Forgery (SSRF) vulnerability in codeSavory Knowledge Base documentation & wiki plugin – BasePress.This issue affects Knowledge Ba… Mitigation only Fix from $1,6002024-04-29 MEDIUM 5.4 CVE-2024-33634 Server-Side Request Forgery (SSRF) vulnerability in Piotnet Piotnet Addons For Elementor Pro.This issue affects Piotnet Addons For Elementor Pro: fro… Mitigation only Fix from $1,6002024-04-29 MEDIUM 5.4 CVE-2024-33592 Server-Side Request Forgery (SSRF) vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73. Mitigation only Fix from $1,6002024-04-25 MEDIUM 6.4 CVE-2024-32803 Server-Side Request Forgery (SSRF) vulnerability in 2day.Sk, Webikon SuperFaktura WooCommerce.This issue affects SuperFaktura WooCommerce: from n/a t… Mitigation only Fix from $1,6002024-04-24 MEDIUM 5.4 CVE-2024-32812 Server-Side Request Forgery (SSRF) vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through … Podlove Podcast Publisher 4.0.12+ Fix from $1,6002024-04-24 MEDIUM 5.4 CVE-2024-32718 Server-Side Request Forgery (SSRF) vulnerability in Webangon The Pack Elementor.This issue affects The Pack Elementor addons: from n/a through 2.0.8.… The Pack Elementor Addons 2.0.8.3+ Fix from $1,6002024-04-24 MEDIUM 6.1 CVE-2023-7253 The Import WP WordPress plugin before 2.13.1 does not prevent users with the administrator role from pinging conducting SSRF attacks, which may be a… Import Wp 2.13.1+ Fix from $1,6002024-04-24 HIGH 8.8 CVE-2024-32407 An issue in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Page Sandbox feature. Relate 2024.1+ Fix from $1,9502024-04-22 MEDIUM 5.3 CVE-2024-27347 Server-Side Request Forgery (SSRF) vulnerability in Apache HugeGraph-Hubble.This issue affects Apache HugeGraph-Hubble: from 1.0.0 before 1.3.0. Use… Hugegraph Hubble 1.3.0+ Fix from $1,6002024-04-22