Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2024-1965
Server-Side Request Forgery vulnerability in Haivision's Aviwest Manager and Aviwest Steamhub. This vulnerability could allow an attacker to enumerat…
Maanager
Mitigation only
MEDIUM 6.4
CVE-2024-1568
The Seraphinite Accelerator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.20.52 via the O…
Seraphinite Accelerator
after 2.20.52
HIGH 7.5
CVE-2024-0759
Should an instance of AnythingLLM be hosted on an internal network and the attacked be explicitly granted a permission level of manager or admin, the…
Anythingllm
1.0.0+
HIGH 8.1
CVE-2024-22873
Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/service/s…
Blueking Configuration Management Database
after 3.9.47
HIGH 8.1
CVE-2024-1758
The SuperFaktura WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.40.3 via the w…
Superfaktura Woocommerce
1.40.4+
MEDIUM 6.5
CVE-2024-0440
Attacker, with permission to submit a link or submits a link via POST to be collected that is using the file:// protocol can then introspect host fi…
Anythingllm
Patch available
HIGH 7.5
CVE-2024-0455
The inclusion of the web scraper for AnythingLLM means that any user with the proper authorization level (manager, admin, and when in single user) co…
Anythingllm
Patch available
HIGH 8.1
CVE-2024-0243
With the following crawler configuration:
```python
from bs4 import BeautifulSoup as Soup
url = "https://example.com"
loader = RecursiveUrlLoader(
…
Langchain
0.1.0+
HIGH 8.8
CVE-2024-25915
Server-Side Request Forgery (SSRF) vulnerability in Raaj Trambadia Pexels: Free Stock Photos.This issue affects Pexels: Free Stock Photos: from n/a t…
Pexels\
after 1.2.2
HIGH 7.2
CVE-2024-23654
discourse-ai is the AI plugin for the open-source discussion platform Discourse. Prior to commit 94ba0dadc2cf38e8f81c3936974c167219878edd, interactio…
Ai
2024-02-21+
MEDIUM 5.7
CVE-2023-47635
Decidim is a participatory democracy framework. Starting in version 0.23.0 and prior to versions 0.27.5 and 0.28.0, the CSRF authenticity token check…
Decidim
0.27.5+
MEDIUM 5.3
CVE-2024-21498
All versions of the package github.com/greenpau/caddy-security are vulnerable to Server-side Request Forgery (SSRF) via X-Forwarded-Host header manip…
Caddy Security
No fix yet
MEDIUM 5.3
CVE-2023-5122
Grafana is an open-source platform for monitoring and observability. The CSV datasource plugin is a Grafana Labs maintained plugin for Grafana that a…
Grafana
0.6.13+
HIGH 8.1
CVE-2024-23788
Server-side request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a netw…
Jh Rvb1 Firmware
Mitigation only
CRITICAL 9.8
CVE-2024-23761
Server Side Template Injection in Gambio 4.9.2.0 allows attackers to run arbitrary code via crafted smarty email template.
Gambio
No fix yet
HIGH 7.2
CVE-2023-6294
The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could allow users with the adminis…
Popup Builder
4.2.6+
MEDIUM 5.3
CVE-2024-24829
Sentry is an error tracking and performance monitoring platform. Sentry’s integration platform provides a way for external services to interact with …
Sentry
24.1.2+
CRITICAL 9.8
CVE-2023-42282
The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable v…
Ip
1.1.9+
HIGH 8.8
CVE-2024-24113
xxl-job =< 2.4.1 has a Server-Side Request Forgery (SSRF) vulnerability, which causes low-privileged users to control executor to RCE.
Xxl Job
after 2.4.1
HIGH 7.3
CVE-2024-24806
libuv is a multi-platform support library with a focus on asynchronous I/O. The `uv_getaddrinfo` function in `src/unix/getaddrinfo.c` (and its window…
Libuv
1.48.0+
MEDIUM 5.0
CVE-2023-6388
Suite CRM version 7.14.2 allows making arbitrary HTTP requests through
the vulnerable server. This is possible because the application is vulnerable…
Suitecrm
No fix yet
MEDIUM 5.5
CVE-2023-22817
Server-side request forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL using another DNS address to …
My Cloud Pr2100 Firmware
5.27.161+
HIGH 8.2
CVE-2024-21893 KEVEPSS 100%
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivant…
Connect Secure
Mitigation only
HIGH 8.6
CVE-2023-50165
Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.
Platform
after 23.1.0
MEDIUM 5.3
CVE-2023-47116
Label Studio is a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to 1.11.0 and was tested on ve…
Label Studio
1.11.0+
HIGH 7.5
CVE-2023-44313
Server-Side Request Forgery (SSRF) vulnerability in Apache ServiceComb Service-Center. Attackers can obtain sensitive server information through spec…
Servicecomb
2.2.0+
HIGH 7.5
CVE-2024-23838
TrueLayer.NET is the .Net client for TrueLayer. The vulnerability could potentially allow a malicious actor to gain control over the destination URL…
Truelayer.net
1.6.0+
HIGH 7.5
CVE-2024-1063
Appwrite <= v1.4.13 is affected by a Server-Side Request Forgery (SSRF) via the '/v1/avatars/favicon' endpoint due to an incomplete fix of CVE-2023-2…
Appwrite
after 1.4.13
MEDIUM 5.3
CVE-2024-22648
A Blind SSRF vulnerability exists in the "Crawl Meta Data" functionality of SEO Panel version 4.10.0. This makes it possible for remote attackers to …
Seo Panel
No fix yet
CRITICAL 9.8
CVE-2024-1021EPSS 35%
A vulnerability, which was classified as critical, has been found in Rebuild up to 3.5.5. Affected by this issue is the function readRawText of the c…
Rebuild
after 3.5.5