Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2024-07-17 CVE-2024-31979 Server-Side Request Forgery (SSRF) vulnerability in Apache Streampipes
Server-Side Request Forgery (SSRF) vulnerability in Apache StreamPipes during installation process of pipeline elements. Previously, StreamPipes allowed users to configure custom endpoints from which to install additional pipeline elements.
network
low complexity
apache CWE-918
4.3
2024-07-15 CVE-2024-39739 Server-Side Request Forgery (SSRF) vulnerability in IBM Datacap and Datacap Navigator
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to server-side request forgery (SSRF).
network
low complexity
ibm CWE-918
4.3
2024-07-12 CVE-2024-40543 Server-Side Request Forgery (SSRF) vulnerability in Publiccms
PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/ueditor?action=catchimage.
network
low complexity
publiccms CWE-918
8.8
2024-07-12 CVE-2024-40544 Server-Side Request Forgery (SSRF) vulnerability in Publiccms
PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/#maintenance_sysTask/edit.
network
low complexity
publiccms CWE-918
8.8
2024-07-08 CVE-2024-39699 Server-Side Request Forgery (SSRF) vulnerability in Monospace Directus
Directus is a real-time API and App dashboard for managing SQL database content.
network
low complexity
monospace CWE-918
5.0
2024-07-08 CVE-2024-31897 Server-Side Request Forgery (SSRF) vulnerability in IBM Cloud PAK for Business Automation
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, 22.0.2, 23.0.1, and 23.0.2 vulnerable to server-side request forgery (SSRF).
network
low complexity
ibm CWE-918
4.3
2024-07-06 CVE-2024-6095 Server-Side Request Forgery (SSRF) vulnerability in Mudler Localai
A vulnerability in the /models/apply endpoint of mudler/localai versions 2.15.0 allows for Server-Side Request Forgery (SSRF) and partial Local File Inclusion (LFI).
network
low complexity
mudler CWE-918
5.8
2024-07-06 CVE-2024-37260 Server-Side Request Forgery (SSRF) vulnerability in Themeruby Foxiz
Server-Side Request Forgery (SSRF) vulnerability in Theme-Ruby Foxiz.This issue affects Foxiz: from n/a through 2.3.5.
network
low complexity
themeruby CWE-918
critical
9.3
2024-07-05 CVE-2024-29319 Server-Side Request Forgery (SSRF) vulnerability in Personal-Management-System Personal Management System 1.4.64
Volmarg Personal Management System 1.4.64 is vulnerable to SSRF (Server Side Request Forgery) via uploading a SVG file.
network
low complexity
personal-management-system CWE-918
critical
9.8
2024-07-05 CVE-2024-6524 Server-Side Request Forgery (SSRF) vulnerability in Shopxo
A vulnerability was found in ShopXO up to 6.1.0.
network
low complexity
shopxo CWE-918
8.8