Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 6.1 CVE-2024-29029 memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthentica… Memos 0.22.0+ Fix from $1,6002024-04-19 MEDIUM 5.3 CVE-2024-29028 memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthent… Memos 0.16.1+ Fix from $1,6002024-04-19 MEDIUM 5.3 CVE-2024-29030 memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /api/resource that allows authenticat… Memos 0.22.0+ Fix from $1,6002024-04-19 CRITICAL 9.3 CVE-2024-2796 A server-side request forgery (SSRF) was discovered in the Akana API Platform in versions prior to and including 2022.1.3. Reported by Jakob Antonsso… Mitigation only Fix from $2,3002024-04-18 CRITICAL 9.0 CVE-2024-29021EPSS 20% Judge0 is an open-source online code execution system. The default configuration of Judge0 leaves the service vulnerable to a sandbox escape via Serv… Mitigation only Fix from $2,3002024-04-18 MEDIUM 5.5 CVE-2024-31229 Server-Side Request Forgery (SSRF) vulnerability in Really Simple Plugins Really Simple SSL.This issue affects Really Simple SSL: from n/a through 7.… Mitigation only Fix from $1,6002024-04-18 MEDIUM 5.3 CVE-2024-29035 Umbraco is an ASP.NET CMS. Failing webhooks logs are available when solution is not in debug mode. Those logs can contain information that is critica… Umbraco Cms 13.1.1+ Fix from $1,6002024-04-17 MEDIUM 6.4 CVE-2023-6805 The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-S… Rss Aggregator By Feedzy 4.4.8+ Fix from $1,6002024-04-17 MEDIUM 6.4 CVE-2024-30256 Open WebUI is a user-friendly WebUI for LLMs. Open-webui is vulnerable to authenticated blind server-side request forgery. This vulnerability is fixe… Open Webui 0.1.117+ Fix from $1,6002024-04-16 HIGH 8.1 CVE-2024-22262 Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the … Mitigation only Fix from $1,9502024-04-16 CRITICAL 9.8 CVE-2024-32430 Server-Side Request Forgery (SSRF) vulnerability in ActiveCampaign.This issue affects ActiveCampaign: from n/a through 8.1.14. Activecampaign 8.1.15+ Fix from $2,3002024-04-15 CRITICAL 9.1 CVE-2024-31461 Plane, an open-source project management tool, has a Server-Side Request Forgery (SSRF) vulnerability in versions prior to 0.17-dev. This issue may a… Patch available Fix from $2,3002024-04-10 MEDIUM 5.0 CVE-2024-3448 Users with low privileges can perform certain AJAX actions. In this vulnerability instance, improper access to ajax?action=plugin:focus:checkIframeA… Mitigation only Fix from $1,6002024-04-10 MEDIUM 6.5 CVE-2023-40148 Server-side request forgery (SSRF) in PingFederate allows unauthenticated http requests to attack network resources and consume server-side resources… Mitigation only Fix from $1,6002024-04-10 MEDIUM 6.4 CVE-2024-2343 The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and i… Avada 7.11.7+ Fix from $1,6002024-04-09 HIGH 7.2 CVE-2024-1812 The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.7 via the 'font_url' pa… Everest Forms 2.0.8+ Fix from $1,9502024-04-09 MEDIUM 6.4 CVE-2023-6964 The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up t… Gutenberg Blocks With Ai 3.2.12+ Fix from $1,6002024-04-09 HIGH 7.3 CVE-2024-1233 A flaw was found in` JwtValidator.resolvePublicKey` in JBoss EAP, where the validator checks jku and sends a HTTP request. During this process, no wh… Patch available Fix from $1,9502024-04-09 MEDIUM 5.3 CVE-2024-27898 SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vulnerable web application targe… Netweaver Mitigation only Fix from $1,6002024-04-09 HIGH 7.2 CVE-2024-31288 Server-Side Request Forgery (SSRF) vulnerability in RapidLoad RapidLoad Power-Up for Autoptimize.This issue affects RapidLoad Power-Up for Autoptimiz… Mitigation only Fix from $1,9502024-04-07 HIGH 7.5 CVE-2024-27620 An issue in Ladder v.0.0.1 thru v.0.0.21 allows a remote attacker to obtain sensitive information via a crafted request to the API. No fix yet Fix from $1,9502024-04-06 HIGH 7.3 CVE-2024-29007 The CloudStack management server and secondary storage VM could be tricked into making requests to restricted or random resources by means of followi… Cloudstack 4.18.1.1+ Fix from $1,9502024-04-04 MEDIUM 5.5 CVE-2024-20332 A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduc… Identity Services Engine Mitigation only Fix from $1,6002024-04-03 CRITICAL 9.4 CVE-2021-27312 Server Side Request Forgery (SSRF) vulnerability in Gleez Cms 1.2.0, allows remote attackers to execute arbitrary code and obtain sensitive informati… Gleez Cms No fix yet Fix from $2,3002024-04-03 CRITICAL 9.1 CVE-2024-25864 Server Side Request Forgery (SSRF) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbitrary code and obtain… Mitigation only Fix from $2,3002024-04-03 MEDIUM 6.5 CVE-2024-24888 Server-Side Request Forgery (SSRF) vulnerability in StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks.This issue affects Gutenberg Blocks b… Gutenberg Blocks With Ai 3.2.26+ Fix from $1,6002024-04-02 HIGH 8.6 CVE-2024-25187 Server Side Request Forgery (SSRF) vulnerability in 71cms v1.0.0, allows remote unauthenticated attackers to obtain sensitive information via getweat… 71cms No fix yet Fix from $1,9502024-04-02 MEDIUM 5.4 CVE-2024-30453 Server-Side Request Forgery (SSRF) vulnerability in Brave Brave Popup Builder.This issue affects Brave Popup Builder: from n/a through 0.6.5. Mitigation only Fix from $1,6002024-03-29 HIGH 7.2 CVE-2023-45705 An administrative user of WebReports may perform a Server Side Request Forgery (SSRF) exploit through SMTP configuration options. Bigfix Platform 10.0.11 / 11.0.2+ Fix from $1,9502024-03-28 HIGH 7.2 CVE-2024-27775 SysAid before version 23.2.14 b18 - CWE-918: Server-Side Request Forgery (SSRF) may allow exposing the local OS user's NTLMv2 hash Mitigation only Fix from $1,9502024-03-28