Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2023-11-28 CVE-2023-48022 Server-Side Request Forgery (SSRF) vulnerability in Anyscale RAY 2.6.3/2.8.0
Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API.
network
low complexity
anyscale CWE-918
critical
9.8
2023-11-28 CVE-2023-48023 Server-Side Request Forgery (SSRF) vulnerability in Anyscale RAY 2.6.3/2.8.0
Anyscale Ray 2.6.3 and 2.8.0 allows /log_proxy SSRF.
network
low complexity
anyscale CWE-918
critical
9.1
2023-11-27 CVE-2023-46480 Server-Side Request Forgery (SSRF) vulnerability in Owncast Project Owncast 0.1.1
An issue in OwnCast v.0.1.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the authHost parameter of the indieauth function.
network
low complexity
owncast-project CWE-918
critical
9.8
2023-11-27 CVE-2023-5974 Server-Side Request Forgery (SSRF) vulnerability in WPB Show Core Project WPB Show Core 2.2
The WPB Show Core WordPress plugin through 2.2 is vulnerable to server-side request forgery (SSRF) via the `path` parameter.
network
low complexity
wpb-show-core-project CWE-918
critical
9.8
2023-11-21 CVE-2023-48306 Server-Side Request Forgery (SSRF) vulnerability in Nextcloud Server
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform.
network
low complexity
nextcloud CWE-918
critical
9.8
2023-11-20 CVE-2023-6199 Server-Side Request Forgery (SSRF) vulnerability in Bookstackapp Bookstack 23.10.2
Book Stack version 23.10.2 allows filtering local files on the server.
network
low complexity
bookstackapp CWE-918
6.5
2023-11-20 CVE-2023-48240 Server-Side Request Forgery (SSRF) vulnerability in Xwiki
XWiki Platform is a generic wiki platform.
network
low complexity
xwiki CWE-918
8.8
2023-11-16 CVE-2023-48204 Server-Side Request Forgery (SSRF) vulnerability in Publiccms 4.0.202302.E
An issue in PublicCMS v.4.0.202302.e allows a remote attacker to obtain sensitive information via the appToken and Parameters parameter of the api/method/getHtml component.
network
low complexity
publiccms CWE-918
6.5
2023-11-14 CVE-2023-6124 Server-Side Request Forgery (SSRF) vulnerability in Salesagility Suitecrm
Server-Side Request Forgery (SSRF) in GitHub repository salesagility/suitecrm prior to 7.14.2, 8.4.2, 7.12.14.
network
low complexity
salesagility CWE-918
4.3
2023-11-13 CVE-2023-46207 Server-Side Request Forgery (SSRF) vulnerability in Stylemixthemes Motors - CAR Dealer, Classifieds & Listing
Server-Side Request Forgery (SSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing.This issue affects Motors – Car Dealer, Classifieds & Listing: from n/a through 1.4.6.
network
low complexity
stylemixthemes CWE-918
7.5