Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
CRITICAL 9.8 CVE-2023-48306 Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.11, 26.0.6… Nextcloud Server 22.2.10.16 / 23.0.12.11+ Fix from $2,3002023-11-21 CRITICAL 9.8 CVE-2023-48307 Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Starting in version 1.13.0 and prior to version 2.2.8 and 3.3.0, a… Mail 2.2.8 / 3.3.0+ Fix from $2,3002023-11-21 MEDIUM 6.5 CVE-2023-6199 Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF. Bookstack No fix yet Fix from $1,6002023-11-20 HIGH 8.8 CVE-2023-48240 XWiki Platform is a generic wiki platform. The rendered diff in XWiki embeds images to be able to compare the contents and not display a difference f… Xwiki 14.10.15 / 15.5.1+ Fix from $1,9502023-11-20 MEDIUM 6.5 CVE-2023-48204 An issue in PublicCMS v.4.0.202302.e allows a remote attacker to obtain sensitive information via the appToken and Parameters parameter of the api/me… Publiccms No fix yet Fix from $1,6002023-11-16 MEDIUM 6.5 CVE-2023-41239 Server-Side Request Forgery (SSRF) vulnerability in Blubrry PowerPress Podcasting plugin by Blubrry.This issue affects PowerPress Podcasting plugin b… Powerpress after 11.0.6 Fix from $1,6002023-11-13 HIGH 7.5 CVE-2023-46207 Server-Side Request Forgery (SSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing.This issue affects Motors – Car Dealer,… Motors Car Dealer\, Classifieds \& Listing after 1.4.6 Fix from $1,9502023-11-13 MEDIUM 6.5 CVE-2023-23800 Server-Side Request Forgery (SSRF) vulnerability in Vova Anokhin WP Shortcodes Plugin — Shortcodes Ultimate.This issue affects WP Shortcodes Plugin —… Shortcodes Ultimate after 5.12.6 Fix from $1,6002023-11-13 HIGH 7.5 CVE-2023-34013 Server-Side Request Forgery (SSRF) vulnerability in Poll Maker Team Poll Maker – Best WordPress Poll Plugin.This issue affects Poll Maker – Best Word… Poll Maker after 4.6.2 Fix from $1,9502023-11-13 HIGH 7.5 CVE-2022-45835EPSS 38% Server-Side Request Forgery (SSRF) vulnerability in PhonePe PhonePe Payment Solutions.This issue affects PhonePe Payment Solutions: from n/a through … Phonepe after 1.0.15 Fix from $1,9502023-11-13 MEDIUM 6.5 CVE-2023-23684 Server-Side Request Forgery (SSRF) vulnerability in WPGraphQL.This issue affects WPGraphQL: from n/a through 1.14.5. Wpgraphql after 1.14.5 Fix from $1,6002023-11-13 CRITICAL 9.8 CVE-2023-47121 Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` an… Discourse 3.1.3 / 3.2.0+ Fix from $2,3002023-11-10 MEDIUM 6.1 CVE-2023-46729 sentry-javascript provides Sentry SDKs for JavaScript. An unsanitized input of Next.js SDK tunnel endpoint allows sending HTTP requests to arbitrary … Sentry Software Development Kit 7.77.0+ Fix from $1,6002023-11-10 HIGH 7.8 CVE-2023-42361 Local File Inclusion vulnerability in Midori-global Better PDF Exporter for Jira Server and Jira Data Center v.10.3.0 and before allows an attacker t… Better Pdf Exporter 11.0.0+ Fix from $1,9502023-11-07 HIGH 8.8 CVE-2023-46730 Group-Office is an enterprise CRM and groupware tool. In affected versions there is full Server-Side Request Forgery (SSRF) vulnerability in the /api… Group Office 6.6.177 / 6.7.54+ Fix from $1,9502023-11-07 HIGH 8.2 CVE-2022-3172 A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to t… Apiserver 1.22.14 / 1.23.11+ Fix from $1,9502023-11-03 HIGH 8.8 CVE-2023-4769 A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfig.do component. This vulnerab… Manageengine Desktop Central Mitigation only Fix from $1,9502023-11-03 CRITICAL 9.8 CVE-2023-43982 Bon Presta boninstagramcarousel between v5.2.1 to v7.0.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at inst… Socialfeed Photos \& Video Using Instagram Api 7.0.0+ Fix from $2,3002023-11-03 MEDIUM 5.4 CVE-2023-35896 IBM Content Navigator 3.0.13 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized reque… Content Navigator Patch available Fix from $1,6002023-11-03 HIGH 7.5 CVE-2023-46725 FoodCoopShop is open source software for food coops and local shops. Versions starting with 3.2.0 prior to 3.6.1 are vulnerable to server-side reques… Foodcoopshop after 3.6.0 Fix from $1,9502023-11-02 HIGH 7.5 CVE-2023-46236 FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10, a server-side-request-forgery (SSRF) vul… Fogproject 1.5.10+ Fix from $1,9502023-10-31 MEDIUM 5.4 CVE-2023-43798 BigBlueButton is an open-source virtual classroom. BigBlueButton prior to versions 2.6.12 and 2.7.0-rc.1 is vulnerable to Server-Side Request Forgery… Bigbluebutton 2.6.12+ Fix from $1,6002023-10-30 CRITICAL 9.8 CVE-2023-46502 An issue in openCRX v.5.2.2 allows a remote attacker to read internal files and execute server side request forgery attack via insecure DocumentBuild… Opencrx Patch available Fix from $2,3002023-10-30 HIGH 7.2 CVE-2023-46124 Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in runtime environments, and the enforceme… Fides 2.22.1+ Fix from $1,9502023-10-25 CRITICAL 9.8 CVE-2023-43795EPSS 68% GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The OGC Web Processing Service (WPS)… Geoserver 2.22.5 / 2.23.2+ Fix from $2,3002023-10-25 MEDIUM 5.3 CVE-2023-41339 GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The WMS specification defines an ``s… Geoserver 2.22.5 / 2.23.2+ Fix from $1,6002023-10-25 HIGH 7.5 CVE-2023-45966 umputun remark42 version 1.12.1 and before has a Blind Server-Side Request Forgery (SSRF) vulnerability. Remark42 after 1.12.1 Fix from $1,9502023-10-23 HIGH 7.5 CVE-2023-46303 link_to_local_path in ebooks/conversion/plugins/html_input.py in calibre before 6.19.0 can, by default, add resources outside of the document root. Calibre 6.19.0+ Fix from $1,9502023-10-22 MEDIUM 6.5 CVE-2023-44256 A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 and Forti… Fortianalyzer after 7.2.3 Fix from $1,6002023-10-20 HIGH 7.2 CVE-2023-41899 Home assistant is an open source home automation. In affected versions the `hassio.addon_stdin` is vulnerable to a partial Server-Side Request Forger… Home Assistant 2023.9.0+ Fix from $1,9502023-10-19