Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 6.5 CVE-2023-3188 Server-Side Request Forgery (SSRF) in GitHub repository owncast/owncast prior to 0.1.0. Owncast 0.1.0+ Fix from $1,6002023-06-10 HIGH 8.8 CVE-2023-2249EPSS 61% The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, a… Wpforo Forum after 2.1.7 Fix from $1,9502023-06-09 CRITICAL 9.6 CVE-2023-1895 The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Server Side Request Forgery via the get_remote_content REST API endpoint in versi… Getwid after 1.8.3 Fix from $2,3002023-06-09 MEDIUM 6.5 CVE-2023-32750 Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the background. Th… Cells 3.0.12 / 4.1.3+ Fix from $1,6002023-06-08 MEDIUM 5.3 CVE-2023-34959 An issue in Chamilo v1.11.* up to v1.11.18 allows attackers to execute a Server-Side Request Forgery (SSRF) and obtain information on the services ru… Chamilo Lms after 1.11.18 Fix from $1,6002023-06-08 MEDIUM 5.4 CVE-2023-32683 Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. A discovered oEmbed or image URL can bypass the `url_preview_ur… Synapse 1.85.0+ Fix from $1,6002023-06-06 HIGH 8.1 CVE-2023-23955 Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Server-Side Request Forgery vulnerability. Advanced Secure Gateway 3.1.6.0 / 7.3.13.1+ Fix from $1,9502023-06-01 CRITICAL 9.8 CVE-2023-3015 A vulnerability has been found in yiwent Vip Video Analysis 1.0 and classified as critical. Affected by this vulnerability is an unknown functionalit… Vip Video Analysis Mitigation only Fix from $2,3002023-05-31 CRITICAL 9.8 CVE-2023-2927 A vulnerability was found in JIZHICMS 2.4.5. It has been classified as critical. Affected is the function index of the file TemplateController.php. T… Jizhicms No fix yet Fix from $2,3002023-05-27 MEDIUM 5.3 CVE-2023-33184 Nextcloud Mail is a mail app in Nextcloud. A blind SSRF attack allowed to send GET requests to services running in the same web server. It is recomme… Mail 1.15.3 / 2.2.5+ Fix from $1,6002023-05-27 MEDIUM 5.8 CVE-2023-32348 Teltonika’s Remote Management System versions prior to 4.10.0 contain a virtual private network (VPN) hub feature for cross-device communication that… Remote Management System 4.10.0+ Fix from $1,6002023-05-22 HIGH 8.8 CVE-2023-31848 davinci 0.3.0-rc is vulnerable to Server-side request forgery (SSRF). Davinci No fix yet Fix from $1,9502023-05-17 MEDIUM 6.5 CVE-2023-23169 Synapsoft pdfocus 1.17 is vulnerable to local file inclusion and server-side request forgery Directory Traversal. Pdfocus No fix yet Fix from $1,6002023-05-12 MEDIUM 5.5 CVE-2022-29840 Server-Side Request Forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL to point back to the loopback… My Cloud Os 5.26.202+ Fix from $1,6002023-05-10 MEDIUM 6.5 CVE-2023-24954 Microsoft SharePoint Server Information Disclosure Vulnerability Windows 10 1507 10.0.10240.19926 / 10.0.14393.5921+ Fix from $1,6002023-05-09 MEDIUM 5.3 CVE-2023-30019 imgproxy <=3.14.0 is vulnerable to Server-Side Request Forgery (SSRF) due to a lack of sanitization of the imageURL parameter. Imgproxy after 3.14.0 Fix from $1,6002023-05-08 MEDIUM 6.5 CVE-2023-30444 IBM Watson Machine Learning on Cloud Pak for Data 4.0 and 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated at… Watson Machine Learning On Cloud Pak For Data Patch available Fix from $1,6002023-04-27 HIGH 7.5 CVE-2023-26735 blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface. This vulnerability allows attackers to detect int… Blackbox Exporter Mitigation only Fix from $1,9502023-04-26 CRITICAL 9.8 CVE-2022-48477 In JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing Hub 2023.1.15725+ Fix from $2,3002023-04-24 HIGH 7.5 CVE-2023-2140 A Server-Side Request Forgery vulnerability in DELMIA Apriso Release 2017 through Release 2022 could allow an unauthenticated attacker to issue re… Delmia Apriso after 2022 Fix from $1,9502023-04-21 MEDIUM 6.5 CVE-2023-25504 A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import dataset feature in order to condu… Superset after 2.0.1 Fix from $1,6002023-04-17 CRITICAL 9.8 CVE-2018-17452 An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Sid… GitLab 11.1.7 / 11.2.4+ Fix from $2,3002023-04-15 HIGH 8.1 CVE-2023-28288EPSS 6% Microsoft SharePoint Server Spoofing Vulnerability Sharepoint Foundation Patch available Fix from $1,9502023-04-11 HIGH 8.8 CVE-2023-29008 The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+server.js` file, containing endpoint han… Sveltekit 1.15.2+ Fix from $1,9502023-04-06 MEDIUM 6.5 CVE-2023-29010 Budibase is a low code platform for creating internal tools, workflows, and admin panels. Versions prior to 2.4.3 (07 March 2023) are vulnerable to S… Budibase 2.4.3+ Fix from $1,6002023-04-06 MEDIUM 5.4 CVE-2023-28633 GLPI is a free asset and IT management software package. Starting in version 0.84 and prior to versions 9.5.13 and 10.0.7, usage of RSS feeds is subj… Glpi 9.5.13 / 10.0.7+ Fix from $1,6002023-04-05 CRITICAL 9.1 CVE-2023-27162 openapi-generator up to v6.4.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/gen/clients/{language}. This vul… Openapi Generator after 6.4.0 Fix from $2,3002023-03-31 MEDIUM 6.5 CVE-2023-27163EPSS 7% request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This vulnerability… Request Baskets after 1.2.1 Fix from $1,6002023-03-31 HIGH 7.5 CVE-2023-27159EPSS 36% Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This vulnerability allows… Appwrite after 1.2.1 Fix from $1,9502023-03-31 HIGH 7.2 CVE-2023-27160 forem up to v2022.11.11 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /articles/{id}. This vulnerability allows at… Forem after 2022.11.11 Fix from $1,9502023-03-31