Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 7.5 CVE-2023-50968EPSS 63% Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations. Th… Ofbiz 18.12.11+ Fix from $1,9502023-12-26 CRITICAL 9.1 CVE-2023-50731 MindsDB is a SQL Server for artificial intelligence. Prior to version 23.11.4.1, the `put` method in `mindsdb/mindsdb/api/http/namespaces/file.py` do… Mindsdb 23.11.4.1+ Fix from $2,3002023-12-22 HIGH 8.8 CVE-2023-50714 yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to v… Yii2 Authclient 2.2.15+ Fix from $1,9502023-12-22 MEDIUM 5.3 CVE-2023-50258 Medusa is an automatic video library manager for TV shows. Versions prior to 1.0.19 are vulnerable to unauthenticated blind server-side request forge… Medusa 1.0.19+ Fix from $1,6002023-12-22 MEDIUM 5.3 CVE-2023-50259 Medusa is an automatic video library manager for TV shows. Versions prior to 1.0.19 are vulnerable to unauthenticated blind server-side request forge… Medusa 1.0.19+ Fix from $1,6002023-12-22 HIGH 8.8 CVE-2023-7037 A vulnerability was found in automad up to 1.10.9. It has been declared as critical. This vulnerability affects the function import of the file FileC… Automad after 1.10.9 Fix from $1,9502023-12-21 CRITICAL 9.8 CVE-2023-6974 A malicious user could use this issue to access internal HTTP(s) servers and in the worst case (ie: aws instance) it could be abuse to get a remote c… Mlflow 2.9.2+ Fix from $2,3002023-12-20 HIGH 7.5 CVE-2023-46262EPSS 83% An unauthenticated attacked could send a specifically crafted web request causing a Server-Side Request Forgery (SSRF) in Ivanti Avalanche Remote Con… Avalanche after 6.4.1 Fix from $1,9502023-12-19 MEDIUM 6.5 CVE-2022-40312 Server-Side Request Forgery (SSRF) vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform.This issue affects GiveWP – Donation Plu… Givewp after 2.25.1 Fix from $1,6002023-12-18 CRITICAL 9.8 CVE-2023-6852 A vulnerability classified as critical has been found in kalcaddle KodExplorer up to 4.51.03. Affected is an unknown function of the file plugins/web… Kodexplorer 4.52.01+ Fix from $2,3002023-12-16 CRITICAL 9.8 CVE-2023-6853 A vulnerability classified as critical was found in kalcaddle KodExplorer up to 4.51.03. Affected by this vulnerability is the function index of the … Kodexplorer 4.52.01+ Fix from $2,3002023-12-16 CRITICAL 9.8 CVE-2023-6849 A vulnerability was found in kalcaddle kodbox up to 1.48. It has been rated as critical. Affected by this issue is the function cover of the file plu… Kodbox 1.48.04+ Fix from $2,3002023-12-16 MEDIUM 5.3 CVE-2023-50266 Bazarr manages and downloads subtitles. In version 1.2.4, the proxy method in bazarr/bazarr/app/ui.py does not validate the user-controlled protocol … Bazarr Patch available Fix from $1,6002023-12-15 HIGH 7.5 CVE-2023-49159 Server-Side Request Forgery (SSRF) vulnerability in Elegant Digital Solutions CommentLuv.This issue affects CommentLuv: from n/a through 3.0.4. Commentluv after 3.0.4 Fix from $1,9502023-12-15 MEDIUM 5.3 CVE-2023-48379 Softnext Mail SQR Expert is an email management platform, it has inadequate filtering for a specific URL parameter within a specific function. An una… Mail Sqr Expert after 230330 Fix from $1,6002023-12-15 MEDIUM 6.5 CVE-2023-6570 Server-Side Request Forgery (SSRF) in kubeflow/kubeflow Kubeflow No fix yet Fix from $1,6002023-12-14 CRITICAL 9.8 CVE-2023-40630 Unauthenticated LFI/SSRF in JCDashboards component for Joomla. Jcdashboard after 1.1.30 Fix from $2,3002023-12-14 MEDIUM 6.5 CVE-2023-47619 Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, users with the update permission are able to read arbitrar… Audiobookshelf after 2.4.3 Fix from $1,6002023-12-13 MEDIUM 5.3 CVE-2023-49795 MindsDB connects artificial intelligence models to real time data. Versions prior to 23.11.4.1 contain a server-side request forgery vulnerability in… Mindsdb 23.11.4.1+ Fix from $1,6002023-12-11 HIGH 7.5 CVE-2023-49799 `nuxt-api-party` is an open source module to proxy API requests. nuxt-api-party attempts to check if the user has passed an absolute URL to prevent t… Nuxt Api Party after 0.21.3 Fix from $1,9502023-12-09 MEDIUM 5.4 CVE-2023-46641 Server-Side Request Forgery (SSRF) vulnerability in Code for Recovery 12 Step Meeting List.This issue affects 12 Step Meeting List: from n/a through … 12 Step Meeting List 3.14.25+ Fix from $1,6002023-12-07 MEDIUM 6.5 CVE-2022-45362EPSS 42% Server-Side Request Forgery (SSRF) vulnerability in Paytm Paytm Payment Gateway.This issue affects Paytm Payment Gateway: from n/a through 2.7.0. Payment Gateway after 2.7.0 Fix from $1,6002023-12-07 MEDIUM 5.4 CVE-2023-41804 Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates.This issue a… Starter Templates 3.2.5+ Fix from $1,6002023-12-07 MEDIUM 6.5 CVE-2023-46736 EspoCRM is an Open Source CRM (Customer Relationship Management) software. In affected versions there is Server-Side Request Forgery (SSRF) vulnerabi… Espocrm after 8.0.2 Fix from $1,6002023-12-05 CRITICAL 9.8 CVE-2023-48910 Microcks up to 1.17.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download. This vulnerabili… Microcks after 1.17.1 Fix from $2,3002023-12-04 CRITICAL 9.1 CVE-2023-48023EPSS 35% Anyscale Ray 2.6.3 and 2.8.0 allows /log_proxy SSRF. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its docu… Ray No fix yet Fix from $2,3002023-11-28 CRITICAL 9.8 CVE-2023-48022EPSS 84% Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the vendor's position is that this … Ray No fix yet Fix from $2,3002023-11-28 CRITICAL 9.8 CVE-2023-46480 An issue in OwnCast v.0.1.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the authHost parameter of the ind… Owncast Mitigation only Fix from $2,3002023-11-27 CRITICAL 9.8 CVE-2023-5974 The WPB Show Core WordPress plugin through 2.2 is vulnerable to server-side request forgery (SSRF) via the `path` parameter. Wpb Show Core after 2.2 Fix from $2,3002023-11-27 HIGH 8.8 CVE-2023-27451 Server-Side Request Forgery (SSRF) vulnerability in Darren Cooney Instant Images plugin <= 5.1.0.2 versions. Instant Images after 5.1.0.2 Fix from $1,9502023-11-22