Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2025-01-22 CVE-2024-13360 Server-Side Request Forgery (SSRF) vulnerability in Aipower
The AI Power: Complete AI Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.8.96 via the wpaicg_troubleshoot_add_vector().
network
low complexity
aipower CWE-918
5.4
2025-01-20 CVE-2025-0584 The a+HRD from aEnrich Technology has a Server-side Request Forgery, allowing unauthenticated remote attackers to exploit this vulnerability to probe internal network.
network
low complexity
CWE-918
5.3
2025-01-09 CVE-2025-21385 Server-Side Request Forgery (SSRF) vulnerability in Microsoft Purview
A Server-Side Request Forgery (SSRF) vulnerability in Microsoft Purview allows an authorized attacker to disclose information over a network.
network
low complexity
microsoft CWE-918
6.5
2025-01-05 CVE-2024-13139 Server-Side Request Forgery (SSRF) vulnerability in Wangl1989 Mysiteforme 1.0
A vulnerability was found in wangl1989 mysiteforme 1.0.
network
low complexity
wangl1989 CWE-918
8.8
2025-01-03 CVE-2024-12237 The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.15 via the rjg_get_youtube_info_justified_gallery_callback function.
network
low complexity
CWE-918
4.3
2024-12-30 CVE-2024-13032 Server-Side Request Forgery (SSRF) vulnerability in Antabot White-Jotter
A vulnerability classified as problematic was found in Antabot White-Jotter up to 0.2.2.
network
low complexity
antabot CWE-918
4.9
2024-12-21 CVE-2024-51463 IBM i 7.3, 7.4, and 7.5 is vulnerable to server-side request forgery (SSRF).
network
low complexity
CWE-918
5.4
2024-12-20 CVE-2024-12840 A server-side request forgery exists in Satellite.
network
high complexity
CWE-918
5.0
2024-12-19 CVE-2024-12121 The Broken Link Checker | Finder plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.5.0 via the 'moblc_check_link' function.
network
low complexity
CWE-918
5.4
2024-12-17 CVE-2024-9624 The WP All Import Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.9.3 due to missing SSRF protection on the pmxi_curl_download function.
network
low complexity
CWE-918
7.6