Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 5.3 CVE-2023-45822 Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for CNCF projects. During a secu… Hub 1.16.0+ Fix from $1,6002023-10-19 MEDIUM 6.5 CVE-2023-25753 There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint. This vulnerability allows us to manip… Shenyu Mitigation only Fix from $1,6002023-10-19 HIGH 8.8 CVE-2023-46229EPSS 45% LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal… Langchain 0.0.317+ Fix from $1,9502023-10-19 CRITICAL 9.8 CVE-2023-5572 Server-Side Request Forgery (SSRF) in GitHub repository vriteio/vrite prior to 0.3.0. Vrite 0.3.0+ Fix from $2,3002023-10-13 MEDIUM 6.8 CVE-2023-26366 Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by a Server… Commerce Mitigation only Fix from $1,6002023-10-13 MEDIUM 5.3 CVE-2023-41763 KEVEPSS 90% Skype for Business Elevation of Privilege Vulnerability Skype For Business Server Patch available Fix from $1,6002023-10-10 MEDIUM 6.5 CVE-2023-42477 SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a crafted request from a vulnerable web application, ca… Netweaver Application Server Java No fix yet Fix from $1,6002023-10-10 MEDIUM 6.5 CVE-2023-39854 The web interface of ATX Ucrypt through 3.5 allows authenticated users (or attackers using default credentials for the admin, master, or user account… Ucrypt after 3.5 Fix from $1,6002023-10-09 HIGH 8.8 CVE-2023-3744 Server-Side Request Forgery vulnerability in SLims version 9.6.0. This vulnerability could allow an authenticated attacker to send requests to intern… Senayan Library Management System Mitigation only Fix from $1,9502023-10-02 CRITICAL 9.8 CVE-2023-43654EPSS 35% TorchServe is a tool for serving and scaling PyTorch models in production. TorchServe default configuration lacks proper input validation, enabling t… Torchserve 0.8.2+ Fix from $2,3002023-09-28 CRITICAL 9.8 CVE-2023-41449 An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter. Ajaxnewsticker Mitigation only Fix from $2,3002023-09-27 HIGH 7.5 CVE-2023-42450 Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 4.2.0-beta1 and prior to version 4.2.0-rc2, by crafti… Mastodon Patch available Fix from $1,9502023-09-19 HIGH 7.2 CVE-2023-3025 The Dropbox Folder Share plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.9.7 via the 'link' par… Dropbox Folder Share after 1.9.7 Fix from $1,9502023-09-16 MEDIUM 6.5 CVE-2023-42439 GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. A SSRF vulnerability exists star… Geonode 4.1.3+ Fix from $1,6002023-09-15 CRITICAL 9.8 CVE-2023-42398 An issue in zzCMS v.2023 allows a remote attacker to execute arbitrary code and obtain sensitive information via the ueditor component in controller.… Zzcms No fix yet Fix from $2,3002023-09-15 MEDIUM 5.4 CVE-2023-4893 The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Server Side Request Forgery via the 'crayon' shortcode in versions up to, and inc… Crayon Syntax Highlighter after 2.8.4 Fix from $1,6002023-09-12 MEDIUM 5.4 CVE-2023-4878 Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1-git. Instantcms 2.16.1+ Fix from $1,6002023-09-10 MEDIUM 5.4 CVE-2023-41327 WireMock is a tool for mocking HTTP services. WireMock can be configured to only permit proxying (and therefore recording) to certain addresses. This… Studio 2.35.1 / 3.0.3+ Fix from $1,6002023-09-06 CRITICAL 10.0 CVE-2023-39967 WireMock is a tool for mocking HTTP services. When certain request URLs like “@127.0.0.1:1234" are used in WireMock Studio configuration fields, the … Studio after 2.32.0-17 Fix from $2,3002023-09-06 HIGH 7.5 CVE-2023-41937 Jenkins Bitbucket Push and Pull Request Plugin 2.4.0 through 2.8.3 (both inclusive) trusts values provided in the webhook payload, including certain … Bitbucket Push And Pull Request after 2.8.3 Fix from $1,9502023-09-06 MEDIUM 5.4 CVE-2023-36388 Improper REST API permission in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma users to test network connections, possib… Superset after 2.1.0 Fix from $1,6002023-09-06 HIGH 7.5 CVE-2023-41055 LibreY is a fork of LibreX, a framework-less and javascript-free privacy respecting meta search engine. LibreY is subject to a Server-Side Request Fo… Librey 2023-08-17+ Fix from $1,9502023-09-04 CRITICAL 9.1 CVE-2023-41054 LibreY is a fork of LibreX, a framework-less and javascript-free privacy respecting meta search engine. LibreY is subject to a Server-Side Request Fo… Librey 2023-08-29+ Fix from $2,3002023-09-04 HIGH 7.5 CVE-2023-36088 Server Side Request Forgery (SSRF) vulnerability in NebulaGraph Studio version 3.7.0, allows remote attackers to gain sensitive information. Nebulagraph Studio No fix yet Fix from $1,9502023-09-01 MEDIUM 6.1 CVE-2023-40969 Senayan Library Management Systems SLIMS 9 Bulian v9.6.1 is vulnerable to Server Side Request Forgery (SSRF) via admin/modules/bibliography/pop_p2p.p… Senayan Library Management System No fix yet Fix from $1,6002023-09-01 MEDIUM 5.4 CVE-2023-4651 Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1. Instantcms 2.16.1+ Fix from $1,6002023-08-31 HIGH 7.5 CVE-2023-40017 GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. In versions 3.2.0 through 4.1.2,… Geonode after 4.1.2 Fix from $1,9502023-08-24 HIGH 8.1 CVE-2023-37379 Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection ed… Airflow 2.7.0+ Fix from $1,9502023-08-23 MEDIUM 5.3 CVE-2023-37440 A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to conduct a … Edgeconnect Sd Wan Orchestrator 9.3.1+ Fix from $1,6002023-08-22 MEDIUM 6.5 CVE-2023-24515 Server-Side Request Forgery (SSRF) vulnerability in API checker of Pandora FMS. Application does not have a check on the URL scheme used while retrie… Pandora Fms after 767 Fix from $1,6002023-08-22