Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2023-3188
Server-Side Request Forgery (SSRF) in GitHub repository owncast/owncast prior to 0.1.0.
Owncast
0.1.0+
HIGH 8.8
CVE-2023-2249EPSS 61%
The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, a…
Wpforo Forum
after 2.1.7
CRITICAL 9.6
CVE-2023-1895
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Server Side Request Forgery via the get_remote_content REST API endpoint in versi…
Getwid
after 1.8.3
MEDIUM 6.5
CVE-2023-32750
Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the background. Th…
Cells
3.0.12 / 4.1.3+
MEDIUM 5.3
CVE-2023-34959
An issue in Chamilo v1.11.* up to v1.11.18 allows attackers to execute a Server-Side Request Forgery (SSRF) and obtain information on the services ru…
Chamilo Lms
after 1.11.18
MEDIUM 5.4
CVE-2023-32683
Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. A discovered oEmbed or image URL can bypass the `url_preview_ur…
Synapse
1.85.0+
HIGH 8.1
CVE-2023-23955
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Server-Side Request Forgery vulnerability.
Advanced Secure Gateway
3.1.6.0 / 7.3.13.1+
CRITICAL 9.8
CVE-2023-3015
A vulnerability has been found in yiwent Vip Video Analysis 1.0 and classified as critical. Affected by this vulnerability is an unknown functionalit…
Vip Video Analysis
Mitigation only
CRITICAL 9.8
CVE-2023-2927
A vulnerability was found in JIZHICMS 2.4.5. It has been classified as critical. Affected is the function index of the file TemplateController.php. T…
Jizhicms
No fix yet
MEDIUM 5.3
CVE-2023-33184
Nextcloud Mail is a mail app in Nextcloud. A blind SSRF attack allowed to send GET requests to services running in the same web server. It is recomme…
Mail
1.15.3 / 2.2.5+
MEDIUM 5.8
CVE-2023-32348
Teltonika’s Remote Management System versions prior to 4.10.0 contain a virtual private network (VPN) hub feature for cross-device communication that…
Remote Management System
4.10.0+
HIGH 8.8
CVE-2023-31848
davinci 0.3.0-rc is vulnerable to Server-side request forgery (SSRF).
Davinci
No fix yet
MEDIUM 6.5
CVE-2023-23169
Synapsoft pdfocus 1.17 is vulnerable to local file inclusion and server-side request forgery Directory Traversal.
Pdfocus
No fix yet
MEDIUM 5.5
CVE-2022-29840
Server-Side Request Forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL to point back to the loopback…
My Cloud Os
5.26.202+
MEDIUM 6.5
CVE-2023-24954
Microsoft SharePoint Server Information Disclosure Vulnerability
Windows 10 1507
10.0.10240.19926 / 10.0.14393.5921+
MEDIUM 5.3
CVE-2023-30019
imgproxy <=3.14.0 is vulnerable to Server-Side Request Forgery (SSRF) due to a lack of sanitization of the imageURL parameter.
Imgproxy
after 3.14.0
MEDIUM 6.5
CVE-2023-30444
IBM Watson Machine Learning on Cloud Pak for Data 4.0 and 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated at…
Watson Machine Learning On Cloud Pak For Data
Patch available
HIGH 7.5
CVE-2023-26735
blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface. This vulnerability allows attackers to detect int…
Blackbox Exporter
Mitigation only
CRITICAL 9.8
CVE-2022-48477
In JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing
Hub
2023.1.15725+
HIGH 7.5
CVE-2023-2140
A Server-Side Request Forgery vulnerability in DELMIA Apriso Release 2017 through Release 2022
could allow an unauthenticated attacker to issue re…
Delmia Apriso
after 2022
MEDIUM 6.5
CVE-2023-25504
A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import dataset feature in order to condu…
Superset
after 2.0.1
CRITICAL 9.8
CVE-2018-17452
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Sid…
GitLab
11.1.7 / 11.2.4+
HIGH 8.1
CVE-2023-28288EPSS 6%
Microsoft SharePoint Server Spoofing Vulnerability
Sharepoint Foundation
Patch available
HIGH 8.8
CVE-2023-29008
The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+server.js` file, containing endpoint han…
Sveltekit
1.15.2+
MEDIUM 6.5
CVE-2023-29010
Budibase is a low code platform for creating internal tools, workflows, and admin panels. Versions prior to 2.4.3 (07 March 2023) are vulnerable to S…
Budibase
2.4.3+
MEDIUM 5.4
CVE-2023-28633
GLPI is a free asset and IT management software package. Starting in version 0.84 and prior to versions 9.5.13 and 10.0.7, usage of RSS feeds is subj…
Glpi
9.5.13 / 10.0.7+
CRITICAL 9.1
CVE-2023-27162
openapi-generator up to v6.4.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/gen/clients/{language}. This vul…
Openapi Generator
after 6.4.0
MEDIUM 6.5
CVE-2023-27163EPSS 7%
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This vulnerability…
Request Baskets
after 1.2.1
HIGH 7.5
CVE-2023-27159EPSS 36%
Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This vulnerability allows…
Appwrite
after 1.2.1
HIGH 7.2
CVE-2023-27160
forem up to v2022.11.11 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /articles/{id}. This vulnerability allows at…
Forem
after 2022.11.11