Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 5.5 CVE-2023-50374 Server-Side Request Forgery (SSRF) vulnerability in NiteoThemes CMP – Coming Soon & Maintenance.This issue affects CMP – Coming Soon & Maintenance: f… Mitigation only Fix from $1,6002024-03-28 MEDIUM 6.8 CVE-2024-29090 Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a thr… Ai Engine 2.1.5+ Fix from $1,6002024-03-28 MEDIUM 6.5 CVE-2024-23500 Server-Side Request Forgery (SSRF) vulnerability in StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks.This issue affects Gutenberg Blocks b… Gutenberg Blocks With Ai 3.2.20+ Fix from $1,6002024-03-28 MEDIUM 6.5 CVE-2023-36679 Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a through 2.6.6. Spectra 2.6.7+ Fix from $1,6002024-03-28 HIGH 7.7 CVE-2023-39313 Server-Side Request Forgery (SSRF) vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1. Avada 7.11.2+ Fix from $1,9502024-03-28 HIGH 7.1 CVE-2023-34370 Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates, Brainstorm … Mitigation only Fix from $1,9502024-03-28 MEDIUM 5.1 CVE-2024-0677 The Pz-LinkCard WordPress plugin through 2.5.1 does not prevent users from pinging arbitrary hosts via some of its shortcodes, which could allow high… Pz Linkcard 2.5.3+ Fix from $1,6002024-03-28 MEDIUM 6.5 CVE-2024-2206 An SSRF vulnerability exists in the gradio-app/gradio due to insufficient validation of user-supplied URLs in the `/proxy` route. Attackers can explo… Gradio 4.18.0+ Fix from $1,6002024-03-27 MEDIUM 5.4 CVE-2024-28435 The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload. Twenty No fix yet Fix from $1,6002024-03-25 HIGH 7.5 CVE-2024-29190 Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analy… Mobile Security Framework 3.9.7+ Fix from $1,9502024-03-22 HIGH 8.8 CVE-2024-2828 A vulnerability, which was classified as critical, was found in lakernote EasyAdmin up to 20240315. Affected is the function thumbnail of the file sr… Easyadmin after 2024-03-15 Fix from $1,9502024-03-22 HIGH 8.8 CVE-2024-2827 A vulnerability, which was classified as critical, has been found in lakernote EasyAdmin up to 20240315. This issue affects some unknown processing o… Easyadmin after 2024-03-15 Fix from $1,9502024-03-22 MEDIUM 6.5 CVE-2024-27927 RSSHub is an open source RSS feed generator. Prior to version 1.0.0-master.a429472, RSSHub allows remote attackers to use the server as a proxy to se… Rsshub 1.0.0-master.a429472+ Fix from $1,6002024-03-21 MEDIUM 5.9 CVE-2024-24028 Server Side Request Forgery (SSRF) vulnerability in Likeshop before 2.5.7 allows attackers to view sensitive information via the avatar parameter in … Likeshop 2.5.7+ Fix from $1,6002024-03-21 CRITICAL 9.1 CVE-2024-25294 An SSRF issue in REBUILD v.3.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the FileDownloader.java, proxy… Rebuild Mitigation only Fix from $2,3002024-03-20 CRITICAL 9.6 CVE-2024-27098EPSS 36% GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authe… Glpi 10.0.13+ Fix from $2,3002024-03-18 CRITICAL 9.3 CVE-2024-28752 A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style att… Cxf 3.5.8 / 3.6.3+ Fix from $2,3002024-03-15 MEDIUM 6.5 CVE-2024-1884EPSS 38% This is a Server-Side Request Forgery (SSRF) vulnerability in the PaperCut NG/MF server-side module that allows an attacker to induce the server-sid… Papercut Mf 20.1.10 / 21.2.14+ Fix from $1,6002024-03-14 MEDIUM 6.1 CVE-2024-28668 DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/mychannel_add.php Dedecms No fix yet Fix from $1,6002024-03-13 MEDIUM 5.3 CVE-2024-2049 Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose … Sd Wan 1000 Firmware 11.4.4.46+ Fix from $1,6002024-03-12 CRITICAL 9.8 CVE-2023-49785EPSS 83% NextChat, also known as ChatGPT-Next-Web, is a cross-platform chat user interface for use with ChatGPT. Versions 2.11.2 and prior are vulnerable to s… Nextchat after 2.11.2 Fix from $2,3002024-03-12 CRITICAL 9.8 CVE-2024-27565 A Server-Side Request Forgery (SSRF) in weixin.php of ChatGPT-wechat-personal commit a0857f6 allows attackers to force the application to make arbitr… Chatgpt Wechat Personal No fix yet Fix from $2,3002024-03-05 HIGH 8.1 CVE-2024-27561 A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers to force the application to … Wondercms No fix yet Fix from $1,9502024-03-05 MEDIUM 5.3 CVE-2024-27563 A Server-Side Request Forgery (SSRF) in the getFileFromRepo function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary … Wondercms No fix yet Fix from $1,6002024-03-05 MEDIUM 6.5 CVE-2024-27564EPSS 41% pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references section has an archived copy of … Chatgpt No fix yet Fix from $1,6002024-03-05 CRITICAL 9.8 CVE-2024-2057 A vulnerability was found in LangChain langchain_community 0.0.26. It has been classified as critical. Affected is the function load_local in the lib… Langchain Patch available Fix from $2,3002024-03-01 MEDIUM 5.4 CVE-2024-27949 Server-Side Request Forgery (SSRF) vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: from n/a through <= 7.2.0. Sirv 7.2.1+ Fix from $1,6002024-03-01 MEDIUM 6.5 CVE-2024-0403 Recipes version 1.5.10 allows arbitrary HTTP requests to be made through the server. This is possible because the application is vulnerable to SSRF. Recipes No fix yet Fix from $1,6002024-03-01 MEDIUM 5.5 CVE-2024-1978 The Friends plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.5 via the discover_available_… Friends 2.8.6+ Fix from $1,6002024-02-29 HIGH 8.8 CVE-2022-34269 An issue was discovered in RWS WorldServer before 11.7.3. An authenticated, remote attacker can perform a ws-legacy/load_dtd?system_id= blind SSRF at… Worldserver 11.7.3+ Fix from $1,9502024-02-29