Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
CRITICAL 9.8 CVE-2024-0945 A vulnerability classified as critical has been found in 60IndexPage up to 1.8.5. This affects an unknown part of the file /include/file.php of the c… 60indexpage 1.8.5+ Fix from $2,3002024-01-26 CRITICAL 9.8 CVE-2024-0946 A vulnerability classified as critical was found in 60IndexPage up to 1.8.5. This vulnerability affects unknown code of the file /apply/index.php of … 60indexpage 1.8.5+ Fix from $2,3002024-01-26 MEDIUM 6.5 CVE-2024-22134 Server-Side Request Forgery (SSRF) vulnerability in Renzo Johnson Contact Form 7 Extension For Mailchimp.This issue affects Contact Form 7 Extension … Contact Form 7 Extension For Mailchimp after 0.5.70 Fix from $1,6002024-01-24 HIGH 7.1 CVE-2023-52331 A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central could allow an attacker to interact with internal o… Apex Central Mitigation only Fix from $1,9502024-01-23 MEDIUM 5.4 CVE-2023-38624 A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacke… Apex Central Mitigation only Fix from $1,6002024-01-23 MEDIUM 5.4 CVE-2023-38625 A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacke… Apex Central Mitigation only Fix from $1,6002024-01-23 MEDIUM 5.4 CVE-2023-38626 A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacke… Apex Central Mitigation only Fix from $1,6002024-01-23 MEDIUM 5.4 CVE-2023-38627 A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacke… Apex Central Mitigation only Fix from $1,6002024-01-23 MEDIUM 5.3 CVE-2024-23330 Tuta is an encrypted email service. In versions prior to 119.10, an attacker can attach an image in a html mail which is loaded from external resourc… Tutanota 119.10+ Fix from $1,6002024-01-23 CRITICAL 9.8 CVE-2024-22203 Whoogle Search is a self-hosted metasearch engine. In versions prior to 0.8.4, the `element` method in `app/routes.py` does not validate the user-con… Whoogle Search 0.8.4+ Fix from $2,3002024-01-23 CRITICAL 9.8 CVE-2024-22205 Whoogle Search is a self-hosted metasearch engine. In versions 0.8.3 and prior, the `window` endpoint does not sanitize user-supplied input from the … Whoogle Search 0.8.4+ Fix from $2,3002024-01-23 CRITICAL 9.8 CVE-2022-40700 Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Managemen… Admin Css Mu after 6.0.1 Fix from $2,3002024-01-19 MEDIUM 5.4 CVE-2023-32337 IBM Maximo Spatial Asset Management 8.10 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauth… Maximo Application Suite 8.10.6+ Fix from $1,6002024-01-19 CRITICAL 9.8 CVE-2024-0649 A vulnerability was found in ZhiHuiYun up to 4.4.13 and classified as critical. This issue affects the function download_network_image of the file /a… Zhihuiyun after 4.4.13 Fix from $2,3002024-01-17 HIGH 8.1 CVE-2024-22408 Shopware is an open headless commerce platform. The implemented Flow Builder functionality in the Shopware application does not adequately validate t… Shopware 6.5.7.4+ Fix from $1,9502024-01-16 MEDIUM 6.5 CVE-2024-0601 A vulnerability was found in ZhongFuCheng3y Austin 1.0. It has been rated as critical. Affected by this issue is the function getRemoteUrl2File of th… Austin No fix yet Fix from $1,6002024-01-16 HIGH 8.8 CVE-2023-6991 The JSM file_get_contents() Shortcode WordPress plugin before 2.7.1 does not validate one of its shortcode's parameters before making a request to it… Jsm File Get Contents\(\) Shortcode 2.7.1+ Fix from $1,9502024-01-15 CRITICAL 9.8 CVE-2024-0510 A vulnerability, which was classified as critical, has been found in HaoKeKeJi YiQiNiu up to 3.1. Affected by this issue is the function http_post of… Yiqiniu after 3.1 Fix from $2,3002024-01-13 HIGH 7.5 CVE-2023-51804 An issue in rymcu forest v.0.02 allows a remote attacker to obtain sensitive information via manipulation of the HTTP body URL in the com.rymcu.fores… Forest Patch available Fix from $1,9502024-01-13 HIGH 8.8 CVE-2023-49471 Blind Server-Side Request Forgery (SSRF) vulnerability in karlomikus Bar Assistant before version 3.2.0 does not validate a parameter before making a… Bar Assistant 3.2.0+ Fix from $1,9502024-01-10 HIGH 8.8 CVE-2024-0308 A vulnerability was found in Inis up to 2.0.1. It has been rated as critical. This issue affects some unknown processing of the file app/api/controll… Inis after 2.0.1 Fix from $1,9502024-01-08 CRITICAL 9.8 CVE-2024-0303 A vulnerability, which was classified as critical, was found in Youke365 up to 1.5.3. Affected is an unknown function of the file /app/api/controller… Youke 365 after 1.5.3 Fix from $2,3002024-01-08 CRITICAL 9.8 CVE-2024-0304 A vulnerability has been found in Youke365 up to 1.5.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the … Youke 365 after 1.5.3 Fix from $2,3002024-01-08 HIGH 7.2 CVE-2023-51441 ** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Axis allowed users with access to the admin service to perform poss… Axis after 1.3 Fix from $1,9502024-01-06 HIGH 7.5 CVE-2024-21642 D-Tale is a visualizer for Pandas data structures. Users hosting versions D-Tale prior to 3.9.0 publicly can be vulnerable to server-side request for… D Tale 3.9.0+ Fix from $1,9502024-01-05 MEDIUM 6.5 CVE-2023-51676 Server-Side Request Forgery (SSRF) vulnerability in Leevio Happy Addons for Elementor.This issue affects Happy Addons for Elementor: from n/a through… Happy Addons For Elementor after 3.9.1.1 Fix from $1,6002023-12-29 HIGH 8.1 CVE-2023-7078 Sending specially crafted HTTP requests to Miniflare's server could result in arbitrary HTTP and WebSocket requests being sent from the server. If Mi… Miniflare 3.20231030.2+ Fix from $1,9502023-12-29 HIGH 7.5 CVE-2023-51665 Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenticated blind server-side reque… Audiobookshelf 2.7.0+ Fix from $1,9502023-12-27 HIGH 7.5 CVE-2023-51697 Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenticated blind server-side reque… Audiobookshelf 2.7.0+ Fix from $1,9502023-12-27 CRITICAL 9.8 CVE-2023-51467EPSS 96% The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code Ofbiz 18.12.11+ Fix from $2,3002023-12-26