Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2024-07-03 CVE-2024-37157 Server-Side Request Forgery (SSRF) vulnerability in Discourse
Discourse is an open-source discussion platform.
network
low complexity
discourse CWE-918
5.3
2024-06-28 CVE-2024-5736 Server-Side Request Forgery (SSRF) vulnerability in Admiror-Design-Studio Admirorframes
Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla! extension in afGdStream.php script allows to access local files or server pages available only from localhost. This issue affects AdmirorFrames: before 5.0.
network
low complexity
admiror-design-studio CWE-918
7.5
2024-06-25 CVE-2024-5014 Server-Side Request Forgery (SSRF) vulnerability in Progress Whatsup Gold
In WhatsUp Gold versions released before 2023.1.3, a Server Side Request Forgery vulnerability exists in the GetASPReport feature.
network
low complexity
progress CWE-918
6.5
2024-06-25 CVE-2024-5015 Server-Side Request Forgery (SSRF) vulnerability in Progress Whatsup Gold
In WhatsUp Gold versions released before 2023.1.3, an authenticated SSRF vulnerability in Wug.UI.Areas.Wug.Controllers.SessionControler.Update allows a low privileged user to chain this SSRF with an Improper Access Control vulnerability.
network
low complexity
progress CWE-918
8.8
2024-06-14 CVE-2024-4404 Server-Side Request Forgery (SSRF) vulnerability in Wpmet Elementskit
The ElementsKit PRO plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.6.2 via the 'render_raw' function.
network
low complexity
wpmet CWE-918
critical
9.6
2024-06-13 CVE-2024-37164 Server-Side Request Forgery (SSRF) vulnerability in Cvat Computer Vision Annotation Tool
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision.
network
low complexity
cvat CWE-918
8.5
2024-06-13 CVE-2024-34111 Server-Side Request Forgery (SSRF) vulnerability in Adobe Commerce and Magento
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read.
network
low complexity
adobe CWE-918
8.8
2024-06-10 CVE-2024-36414 Server-Side Request Forgery (SSRF) vulnerability in Salesagility Suitecrm
SuiteCRM is an open-source Customer Relationship Management (CRM) software application.
network
low complexity
salesagility CWE-918
6.5
2024-06-06 CVE-2024-5186 Server-Side Request Forgery (SSRF) vulnerability in Pribai Privategpt 0.5.0
A Server-Side Request Forgery (SSRF) vulnerability exists in the file upload section of imartinez/privategpt version 0.5.0.
network
low complexity
pribai CWE-918
7.2
2024-06-06 CVE-2024-4177 Server-Side Request Forgery (SSRF) vulnerability in Bitdefender Gravityzone
A host whitelist parser issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery.
network
low complexity
bitdefender CWE-918
critical
9.8