Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2023-45822
Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for CNCF projects. During a secu…
Hub
1.16.0+
MEDIUM 6.5
CVE-2023-25753
There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint. This vulnerability allows us to manip…
Shenyu
Mitigation only
HIGH 8.8
CVE-2023-46229EPSS 45%
LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal…
Langchain
0.0.317+
CRITICAL 9.8
CVE-2023-5572
Server-Side Request Forgery (SSRF) in GitHub repository vriteio/vrite prior to 0.3.0.
Vrite
0.3.0+
MEDIUM 6.8
CVE-2023-26366
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by a Server…
Commerce
Mitigation only
MEDIUM 5.3
CVE-2023-41763 KEVEPSS 90%
Skype for Business Elevation of Privilege Vulnerability
Skype For Business Server
Patch available
MEDIUM 6.5
CVE-2023-42477
SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a crafted request from a vulnerable web application, ca…
Netweaver Application Server Java
No fix yet
MEDIUM 6.5
CVE-2023-39854
The web interface of ATX Ucrypt through 3.5 allows authenticated users (or attackers using default credentials for the admin, master, or user account…
Ucrypt
after 3.5
HIGH 8.8
CVE-2023-3744
Server-Side Request Forgery vulnerability in SLims version 9.6.0. This vulnerability could allow an authenticated attacker to send requests to intern…
Senayan Library Management System
Mitigation only
CRITICAL 9.8
CVE-2023-43654EPSS 35%
TorchServe is a tool for serving and scaling PyTorch models in production. TorchServe default configuration lacks proper input validation, enabling t…
Torchserve
0.8.2+
CRITICAL 9.8
CVE-2023-41449
An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter.
Ajaxnewsticker
Mitigation only
HIGH 7.5
CVE-2023-42450
Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 4.2.0-beta1 and prior to version 4.2.0-rc2, by crafti…
Mastodon
Patch available
HIGH 7.2
CVE-2023-3025
The Dropbox Folder Share plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.9.7 via the 'link' par…
Dropbox Folder Share
after 1.9.7
MEDIUM 6.5
CVE-2023-42439
GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. A SSRF vulnerability exists star…
Geonode
4.1.3+
CRITICAL 9.8
CVE-2023-42398
An issue in zzCMS v.2023 allows a remote attacker to execute arbitrary code and obtain sensitive information via the ueditor component in controller.…
Zzcms
No fix yet
MEDIUM 5.4
CVE-2023-4893
The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Server Side Request Forgery via the 'crayon' shortcode in versions up to, and inc…
Crayon Syntax Highlighter
after 2.8.4
MEDIUM 5.4
CVE-2023-4878
Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
Instantcms
2.16.1+
MEDIUM 5.4
CVE-2023-41327
WireMock is a tool for mocking HTTP services. WireMock can be configured to only permit proxying (and therefore recording) to certain addresses. This…
Studio
2.35.1 / 3.0.3+
CRITICAL 10.0
CVE-2023-39967
WireMock is a tool for mocking HTTP services. When certain request URLs like “@127.0.0.1:1234" are used in WireMock Studio configuration fields, the …
Studio
after 2.32.0-17
HIGH 7.5
CVE-2023-41937
Jenkins Bitbucket Push and Pull Request Plugin 2.4.0 through 2.8.3 (both inclusive) trusts values provided in the webhook payload, including certain …
Bitbucket Push And Pull Request
after 2.8.3
MEDIUM 5.4
CVE-2023-36388
Improper REST API permission in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma users to test network connections, possib…
Superset
after 2.1.0
HIGH 7.5
CVE-2023-41055
LibreY is a fork of LibreX, a framework-less and javascript-free privacy respecting meta search engine. LibreY is subject to a Server-Side Request Fo…
Librey
2023-08-17+
CRITICAL 9.1
CVE-2023-41054
LibreY is a fork of LibreX, a framework-less and javascript-free privacy respecting meta search engine. LibreY is subject to a Server-Side Request Fo…
Librey
2023-08-29+
HIGH 7.5
CVE-2023-36088
Server Side Request Forgery (SSRF) vulnerability in NebulaGraph Studio version 3.7.0, allows remote attackers to gain sensitive information.
Nebulagraph Studio
No fix yet
MEDIUM 6.1
CVE-2023-40969
Senayan Library Management Systems SLIMS 9 Bulian v9.6.1 is vulnerable to Server Side Request Forgery (SSRF) via admin/modules/bibliography/pop_p2p.p…
Senayan Library Management System
No fix yet
MEDIUM 5.4
CVE-2023-4651
Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1.
Instantcms
2.16.1+
HIGH 7.5
CVE-2023-40017
GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. In versions 3.2.0 through 4.1.2,…
Geonode
after 4.1.2
HIGH 8.1
CVE-2023-37379
Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection ed…
Airflow
2.7.0+
MEDIUM 5.3
CVE-2023-37440
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to conduct a …
Edgeconnect Sd Wan Orchestrator
9.3.1+
MEDIUM 6.5
CVE-2023-24515
Server-Side Request Forgery (SSRF) vulnerability in API checker of Pandora FMS. Application does not have a check on the URL scheme used while retrie…
Pandora Fms
after 767