Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 5.3 CVE-2024-1965 Server-Side Request Forgery vulnerability in Haivision's Aviwest Manager and Aviwest Steamhub. This vulnerability could allow an attacker to enumerat… Maanager Mitigation only Fix from $1,6002024-02-28 MEDIUM 6.4 CVE-2024-1568 The Seraphinite Accelerator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.20.52 via the O… Seraphinite Accelerator after 2.20.52 Fix from $1,6002024-02-28 HIGH 7.5 CVE-2024-0759 Should an instance of AnythingLLM be hosted on an internal network and the attacked be explicitly granted a permission level of manager or admin, the… Anythingllm 1.0.0+ Fix from $1,9502024-02-27 HIGH 8.1 CVE-2024-22873 Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/service/s… Blueking Configuration Management Database after 3.9.47 Fix from $1,9502024-02-26 HIGH 8.1 CVE-2024-1758 The SuperFaktura WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.40.3 via the w… Superfaktura Woocommerce 1.40.4+ Fix from $1,9502024-02-26 MEDIUM 6.5 CVE-2024-0440 Attacker, with permission to submit a link or submits a link via POST to be collected that is using the file:// protocol can then introspect host fi… Anythingllm Patch available Fix from $1,6002024-02-26 HIGH 7.5 CVE-2024-0455 The inclusion of the web scraper for AnythingLLM means that any user with the proper authorization level (manager, admin, and when in single user) co… Anythingllm Patch available Fix from $1,9502024-02-26 HIGH 8.1 CVE-2024-0243 With the following crawler configuration: ```python from bs4 import BeautifulSoup as Soup url = "https://example.com" loader = RecursiveUrlLoader( … Langchain 0.1.0+ Fix from $1,9502024-02-26 HIGH 8.8 CVE-2024-25915 Server-Side Request Forgery (SSRF) vulnerability in Raaj Trambadia Pexels: Free Stock Photos.This issue affects Pexels: Free Stock Photos: from n/a t… Pexels\ after 1.2.2 Fix from $1,9502024-02-23 HIGH 7.2 CVE-2024-23654 discourse-ai is the AI plugin for the open-source discussion platform Discourse. Prior to commit 94ba0dadc2cf38e8f81c3936974c167219878edd, interactio… Ai 2024-02-21+ Fix from $1,9502024-02-21 MEDIUM 5.7 CVE-2023-47635 Decidim is a participatory democracy framework. Starting in version 0.23.0 and prior to versions 0.27.5 and 0.28.0, the CSRF authenticity token check… Decidim 0.27.5+ Fix from $1,6002024-02-20 MEDIUM 5.3 CVE-2024-21498 All versions of the package github.com/greenpau/caddy-security are vulnerable to Server-side Request Forgery (SSRF) via X-Forwarded-Host header manip… Caddy Security No fix yet Fix from $1,6002024-02-17 MEDIUM 5.3 CVE-2023-5122 Grafana is an open-source platform for monitoring and observability. The CSV datasource plugin is a Grafana Labs maintained plugin for Grafana that a… Grafana 0.6.13+ Fix from $1,6002024-02-14 HIGH 8.1 CVE-2024-23788 Server-side request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a netw… Jh Rvb1 Firmware Mitigation only Fix from $1,9502024-02-14 CRITICAL 9.8 CVE-2024-23761 Server Side Template Injection in Gambio 4.9.2.0 allows attackers to run arbitrary code via crafted smarty email template. Gambio No fix yet Fix from $2,3002024-02-12 HIGH 7.2 CVE-2023-6294 The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could allow users with the adminis… Popup Builder 4.2.6+ Fix from $1,9502024-02-12 MEDIUM 5.3 CVE-2024-24829 Sentry is an error tracking and performance monitoring platform. Sentry’s integration platform provides a way for external services to interact with … Sentry 24.1.2+ Fix from $1,6002024-02-09 CRITICAL 9.8 CVE-2023-42282 The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable v… Ip 1.1.9+ Fix from $2,3002024-02-08 HIGH 8.8 CVE-2024-24113 xxl-job =< 2.4.1 has a Server-Side Request Forgery (SSRF) vulnerability, which causes low-privileged users to control executor to RCE. Xxl Job after 2.4.1 Fix from $1,9502024-02-08 HIGH 7.3 CVE-2024-24806 libuv is a multi-platform support library with a focus on asynchronous I/O. The `uv_getaddrinfo` function in `src/unix/getaddrinfo.c` (and its window… Libuv 1.48.0+ Fix from $1,9502024-02-07 MEDIUM 5.0 CVE-2023-6388 Suite CRM version 7.14.2 allows making arbitrary HTTP requests through the vulnerable server. This is possible because the application is vulnerable… Suitecrm No fix yet Fix from $1,6002024-02-07 MEDIUM 5.5 CVE-2023-22817 Server-side request forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL using another DNS address to … My Cloud Pr2100 Firmware 5.27.161+ Fix from $1,6002024-02-05 HIGH 8.2 CVE-2024-21893 KEVEPSS 100% A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivant… Connect Secure Mitigation only Fix from $1,9502024-01-31 HIGH 8.6 CVE-2023-50165 Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents. Platform after 23.1.0 Fix from $1,9502024-01-31 MEDIUM 5.3 CVE-2023-47116 Label Studio is a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to 1.11.0 and was tested on ve… Label Studio 1.11.0+ Fix from $1,6002024-01-31 HIGH 7.5 CVE-2023-44313 Server-Side Request Forgery (SSRF) vulnerability in Apache ServiceComb Service-Center. Attackers can obtain sensitive server information through spec… Servicecomb 2.2.0+ Fix from $1,9502024-01-31 HIGH 7.5 CVE-2024-23838 TrueLayer.NET is the .Net client for TrueLayer. The vulnerability could potentially allow a malicious actor to gain control over the destination URL… Truelayer.net 1.6.0+ Fix from $1,9502024-01-30 HIGH 7.5 CVE-2024-1063 Appwrite <= v1.4.13 is affected by a Server-Side Request Forgery (SSRF) via the '/v1/avatars/favicon' endpoint due to an incomplete fix of CVE-2023-2… Appwrite after 1.4.13 Fix from $1,9502024-01-30 MEDIUM 5.3 CVE-2024-22648 A Blind SSRF vulnerability exists in the "Crawl Meta Data" functionality of SEO Panel version 4.10.0. This makes it possible for remote attackers to … Seo Panel No fix yet Fix from $1,6002024-01-30 CRITICAL 9.8 CVE-2024-1021EPSS 35% A vulnerability, which was classified as critical, has been found in Rebuild up to 3.5.5. Affected by this issue is the function readRawText of the c… Rebuild after 3.5.5 Fix from $2,3002024-01-29