Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2024-02-07 CVE-2024-0628 Server-Side Request Forgery (SSRF) vulnerability in Wprssaggregator WP RSS Aggregator
The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.23.5 via the RSS feed source in admin settings.
network
low complexity
wprssaggregator CWE-918
3.8
2024-02-05 CVE-2023-22817 Server-Side Request Forgery (SSRF) vulnerability in Westerndigital products
Server-side request forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL using another DNS address to point back to the loopback adapter.
local
low complexity
westerndigital CWE-918
5.5
2024-01-31 CVE-2023-50165 Server-Side Request Forgery (SSRF) vulnerability in Pega Platform
Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.
network
low complexity
pega CWE-918
8.6
2024-01-31 CVE-2024-21893 Server-Side Request Forgery (SSRF) vulnerability in Ivanti Connect Secure and Policy Secure
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.
network
low complexity
ivanti CWE-918
8.2
2024-01-31 CVE-2023-47116 Server-Side Request Forgery (SSRF) vulnerability in Humansignal Label Studio
Label Studio is a popular open source data labeling tool.
network
low complexity
humansignal CWE-918
5.3
2024-01-30 CVE-2024-23825 Server-Side Request Forgery (SSRF) vulnerability in Tablepress
TablePress is a table plugin for Wordpress.
network
low complexity
tablepress CWE-918
4.9
2024-01-30 CVE-2024-1063 Server-Side Request Forgery (SSRF) vulnerability in Appwrite
Appwrite <= v1.4.13 is affected by a Server-Side Request Forgery (SSRF) via the '/v1/avatars/favicon' endpoint due to an incomplete fix of CVE-2023-27159.
network
low complexity
appwrite CWE-918
7.5
2024-01-30 CVE-2024-22648 Server-Side Request Forgery (SSRF) vulnerability in Seopanel SEO Panel 4.10.0
A Blind SSRF vulnerability exists in the "Crawl Meta Data" functionality of SEO Panel version 4.10.0.
network
low complexity
seopanel CWE-918
5.3
2024-01-29 CVE-2024-1021 Server-Side Request Forgery (SSRF) vulnerability in Ruifang-Tech Rebuild
A vulnerability, which was classified as critical, has been found in Rebuild up to 3.5.5.
network
low complexity
ruifang-tech CWE-918
critical
9.8
2024-01-26 CVE-2024-0945 Server-Side Request Forgery (SSRF) vulnerability in 60Indexpage Project 60Indexpage
A vulnerability classified as critical has been found in 60IndexPage up to 1.8.5.
network
low complexity
60indexpage-project CWE-918
critical
9.8