Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2023-50968EPSS 63%
Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations.
Th…
Ofbiz
18.12.11+
CRITICAL 9.1
CVE-2023-50731
MindsDB is a SQL Server for artificial intelligence. Prior to version 23.11.4.1, the `put` method in `mindsdb/mindsdb/api/http/namespaces/file.py` do…
Mindsdb
23.11.4.1+
HIGH 8.8
CVE-2023-50714
yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to v…
Yii2 Authclient
2.2.15+
MEDIUM 5.3
CVE-2023-50258
Medusa is an automatic video library manager for TV shows. Versions prior to 1.0.19 are vulnerable to unauthenticated blind server-side request forge…
Medusa
1.0.19+
MEDIUM 5.3
CVE-2023-50259
Medusa is an automatic video library manager for TV shows. Versions prior to 1.0.19 are vulnerable to unauthenticated blind server-side request forge…
Medusa
1.0.19+
HIGH 8.8
CVE-2023-7037
A vulnerability was found in automad up to 1.10.9. It has been declared as critical. This vulnerability affects the function import of the file FileC…
Automad
after 1.10.9
CRITICAL 9.8
CVE-2023-6974
A malicious user could use this issue to access internal HTTP(s) servers and in the worst case (ie: aws instance) it could be abuse to get a remote c…
Mlflow
2.9.2+
HIGH 7.5
CVE-2023-46262EPSS 83%
An unauthenticated attacked could send a specifically crafted web request causing a Server-Side Request Forgery (SSRF) in Ivanti Avalanche Remote Con…
Avalanche
after 6.4.1
MEDIUM 6.5
CVE-2022-40312
Server-Side Request Forgery (SSRF) vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform.This issue affects GiveWP – Donation Plu…
Givewp
after 2.25.1
CRITICAL 9.8
CVE-2023-6852
A vulnerability classified as critical has been found in kalcaddle KodExplorer up to 4.51.03. Affected is an unknown function of the file plugins/web…
Kodexplorer
4.52.01+
CRITICAL 9.8
CVE-2023-6853
A vulnerability classified as critical was found in kalcaddle KodExplorer up to 4.51.03. Affected by this vulnerability is the function index of the …
Kodexplorer
4.52.01+
CRITICAL 9.8
CVE-2023-6849
A vulnerability was found in kalcaddle kodbox up to 1.48. It has been rated as critical. Affected by this issue is the function cover of the file plu…
Kodbox
1.48.04+
MEDIUM 5.3
CVE-2023-50266
Bazarr manages and downloads subtitles. In version 1.2.4, the proxy method in bazarr/bazarr/app/ui.py does not validate the user-controlled protocol …
Bazarr
Patch available
HIGH 7.5
CVE-2023-49159
Server-Side Request Forgery (SSRF) vulnerability in Elegant Digital Solutions CommentLuv.This issue affects CommentLuv: from n/a through 3.0.4.
Commentluv
after 3.0.4
MEDIUM 5.3
CVE-2023-48379
Softnext Mail SQR Expert is an email management platform, it has inadequate filtering for a specific URL parameter within a specific function. An una…
Mail Sqr Expert
after 230330
MEDIUM 6.5
CVE-2023-6570
Server-Side Request Forgery (SSRF) in kubeflow/kubeflow
Kubeflow
No fix yet
CRITICAL 9.8
CVE-2023-40630
Unauthenticated LFI/SSRF in JCDashboards component for Joomla.
Jcdashboard
after 1.1.30
MEDIUM 6.5
CVE-2023-47619
Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, users with the update permission are able to read arbitrar…
Audiobookshelf
after 2.4.3
MEDIUM 5.3
CVE-2023-49795
MindsDB connects artificial intelligence models to real time data. Versions prior to 23.11.4.1 contain a server-side request forgery vulnerability in…
Mindsdb
23.11.4.1+
HIGH 7.5
CVE-2023-49799
`nuxt-api-party` is an open source module to proxy API requests. nuxt-api-party attempts to check if the user has passed an absolute URL to prevent t…
Nuxt Api Party
after 0.21.3
MEDIUM 5.4
CVE-2023-46641
Server-Side Request Forgery (SSRF) vulnerability in Code for Recovery 12 Step Meeting List.This issue affects 12 Step Meeting List: from n/a through …
12 Step Meeting List
3.14.25+
MEDIUM 6.5
CVE-2022-45362EPSS 42%
Server-Side Request Forgery (SSRF) vulnerability in Paytm Paytm Payment Gateway.This issue affects Paytm Payment Gateway: from n/a through 2.7.0.
Payment Gateway
after 2.7.0
MEDIUM 5.4
CVE-2023-41804
Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates.This issue a…
Starter Templates
3.2.5+
MEDIUM 6.5
CVE-2023-46736
EspoCRM is an Open Source CRM (Customer Relationship Management) software. In affected versions there is Server-Side Request Forgery (SSRF) vulnerabi…
Espocrm
after 8.0.2
CRITICAL 9.8
CVE-2023-48910
Microcks up to 1.17.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download. This vulnerabili…
Microcks
after 1.17.1
CRITICAL 9.1
CVE-2023-48023EPSS 35%
Anyscale Ray 2.6.3 and 2.8.0 allows /log_proxy SSRF. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its docu…
Ray
No fix yet
CRITICAL 9.8
CVE-2023-48022EPSS 84%
Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the vendor's position is that this …
Ray
No fix yet
CRITICAL 9.8
CVE-2023-46480
An issue in OwnCast v.0.1.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the authHost parameter of the ind…
Owncast
Mitigation only
CRITICAL 9.8
CVE-2023-5974
The WPB Show Core WordPress plugin through 2.2 is vulnerable to server-side request forgery (SSRF) via the `path` parameter.
Wpb Show Core
after 2.2
HIGH 8.8
CVE-2023-27451
Server-Side Request Forgery (SSRF) vulnerability in Darren Cooney Instant Images plugin <= 5.1.0.2 versions.
Instant Images
after 5.1.0.2