Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-918 (服务端请求伪造(SSRF)) — Vulnerability Class 1489

1489 vulnerabilities classified as CWE-918 (服务端请求伪造(SSRF)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-27564 ChatGPT 安全漏洞 — mm1.ltd source code 5.8 Medium2024-03-05
CVE-2024-2057 LangChain langchain_community TFIDFRetriever tfidf.py load_local server-side request forgery — langchain_community 6.3 Medium2024-03-01
CVE-2024-27949 WordPress Sirv plugin <= 7.2.0 - Server Side Request Forgery (SSRF) vulnerability — Sirv 5.4 Medium2024-03-01
CVE-2024-0403 Recipes 1.5.10 - Blind SSRF — Recipes 6.5 Medium2024-02-29
CVE-2024-1978 Friends <= 2.8.5 - Authenticated (Admin+) Blind Server-Side Request Forgery — Friends 5.5 Medium2024-02-29
CVE-2024-1965 Server-Side Request Forgery Vulnerability in Haivision Products — Aviwest Manager 6.5 Medium2024-02-28
CVE-2024-1568 Seraphinite Accelerator <= 2.20.52 - Authenticated (Subscriber+) Server-Side Request Forgery in OnAdminApi_HtmlCheck — Seraphinite Accelerator 6.4 Medium2024-02-28
CVE-2024-0759 Collection of internally resolving IPs — mintplex-labs/anything-llm 9.3 -2024-02-27
CVE-2024-0440 SSRF - file:// unsanitized access to underlying host files — mintplex-labs/anything-llm 6.5 -2024-02-25
CVE-2024-0455 SSRF on AWS deployed instances of AnythingLLM via /metadata — mintplex-labs/anything-llm 8.8 -2024-02-25
CVE-2024-0243 Server-side Request Forgery In Recursive URL Loader — langchain-ai/langchain 9.3 -2024-02-24
CVE-2024-1758 SuperFaktura WooCommerce <= 1.40.3 - Authenticated (Subscriber+) Blind Server-Side Request Forgery — SuperFaktura WooCommerce 5.4 Medium2024-02-24
CVE-2024-25915 WordPress Pexels: Free Stock Photos Plugin <= 1.2.2 is vulnerable to Server Side Request Forgery (SSRF) — Pexels: Free Stock Photos 4.9 Medium2024-02-23
CVE-2024-23654 discourse-ai admin-initiated SSRF when interacting with AI services — discourse-ai 4.1 Medium2024-02-21
CVE-2023-47635 Decidim vulnerable to possible CSRF attack at questionnaire templates preview — decidim 4.5 Medium2024-02-20
CVE-2024-21498 Caddy 安全漏洞 — github.com/greenpau/caddy-security 5.3 Medium2024-02-17
CVE-2023-5122 SSRF in CSV Datasource Plugin — grafana-csv-datasource 5.0 Medium2024-02-14
CVE-2024-24829 SSRF in Sentry via Phabricator integration — sentry 4.3 Medium2024-02-08
CVE-2024-24806 Improper Domain Lookup that potentially leads to SSRF attacks in libuv — libuv 7.3 High2024-02-07
CVE-2023-6388 Suite CRM v7.14.2 - SSRF — Suite CRM 5.0 Medium2024-02-07
CVE-2023-22817 Server-side Request Forgery vulnerability in Western Digital My Cloud, My Cloud Home and SanDisk ibi products — My Cloud OS 5 5.5 Medium2024-02-05
CVE-2023-50165 Pegasystem PEGA Platform 安全漏洞 — Pega Platform 8.5 High2024-01-31
CVE-2023-47116 Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections — label-studio 5.3 Medium2024-01-31
CVE-2023-44313 Apache ServiceComb Service-Center: attacker can perform SSRF through the frontend API — Apache ServiceComb Service-Center 7.6 High2024-01-31
CVE-2024-23838 TrueLayer.Client SSRF when fetching payment or payment provider — truelayer-dotnet 7.5 -2024-01-30
CVE-2024-23825 TablePress SSRF vulnerability due to insufficient filtering of cloud provider hosts — TablePress 3.0 Low2024-01-30
CVE-2024-1063 Appwrite 代码问题漏洞 — Appwrite 5.3 Medium2024-01-30
CVE-2024-1021 Rebuild HTTP Request readRawText server-side request forgery — Rebuild 6.3 Medium2024-01-29
CVE-2024-0946 60IndexPage Parameter index.php server-side request forgery — 60IndexPage 7.3 High2024-01-26
CVE-2024-0945 60IndexPage Parameter file.php server-side request forgery — 60IndexPage 7.3 High2024-01-26

Vulnerabilities classified as CWE-918 (服务端请求伪造(SSRF)) represent 1489 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.