Vulnerabilities (CVE)

Filtered by CWE-918
Total 2645 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-2245 1 Bitdefender 1 Gravityzone Update Server 2026-06-17 N/A 5.3 MEDIUM
A server-side request forgery (SSRF) vulnerability exists in the Bitdefender GravityZone Update Server when operating in Relay Mode. The HTTP proxy component on port 7074 uses a domain allowlist to restrict outbound requests, but fails to properly sanitize hostnames containing null-byte (%00) sequences. By crafting a request to a domain such as evil.com%00.bitdefender.com, an attacker can bypass the allowlist check, causing the proxy to forward requests to arbitrary external or internal systems.
CVE-2025-2243 1 Bitdefender 1 Gravityzone 2026-06-17 N/A 7.3 HIGH
A server-side request forgery (SSRF) vulnerability in Bitdefender GravityZone Console allows an attacker to bypass input validation logic using leading characters in DNS requests. Paired with other potential vulnerabilities, this bypass could be used for execution of third party code. This issue affects GravityZone Console: before 6.41.2.1.
CVE-2025-2192 2026-06-17 4.3 MEDIUM 4.3 MEDIUM
A vulnerability, which was classified as problematic, was found in Stoque Zeev.it 4.24. This affects an unknown part of the file /Login?inpLostSession=1 of the component Login Page. The manipulation of the argument inpRedirectURL leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-2170 1 Sonicwall 2 Sma1000, Sma1000 Firmware 2026-06-17 N/A 7.2 HIGH
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface, which in specific conditions could potentially enable a remote unauthenticated attacker to cause the appliance to make requests to an unintended location.
CVE-2025-2116 2026-06-17 4.0 MEDIUM 4.3 MEDIUM
A vulnerability has been found in Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System 3.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /newsedit/newsedit/xy/imageProxy.do of the component File Protocol Handler. The manipulation of the argument xyImgUrl leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-2109 1 Wpcompress 1 Wp Compress 2026-06-17 N/A 5.8 MEDIUM
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.30.15 via the init() function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query information from internal services.
CVE-2025-29972 1 Microsoft 1 Azure Storage Resource Provider 2026-06-17 N/A 9.9 CRITICAL
Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network.
CVE-2025-29720 1 Langgenius 1 Dify 2026-06-17 N/A 4.8 MEDIUM
Dify v1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi.
CVE-2025-29461 1 Appleple 1 A-blogcms 2026-06-17 N/A 7.6 HIGH
An issue in a-blogcms 3.1.15 allows a remote attacker to obtain sensitive information via the /bid/1/admin/entry-edit/ path.
CVE-2025-29460 1 Mybb 1 Mybb 2026-06-17 N/A 7.6 HIGH
An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Add Mycode function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.
CVE-2025-29459 1 Mybb 1 Mybb 2026-06-17 N/A 7.6 HIGH
An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Mail function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.
CVE-2025-29458 1 Mybb 1 Mybb 2026-06-17 N/A 7.6 HIGH
An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Change Avatar function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.
CVE-2025-29457 1 Mybb 1 Mybb 2026-06-17 N/A 7.6 HIGH
An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Import a Theme function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.
CVE-2025-29456 1 Personal-management-system 1 Personal Management System 2026-06-17 N/A 6.5 MEDIUM
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the create Notes function.
CVE-2025-29455 1 Personal-management-system 1 Personal Management System 2026-06-17 N/A 6.5 MEDIUM
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Travel Ideas" function.
CVE-2025-29454 1 Personal-management-system 1 Personal Management System 2026-06-17 N/A 6.5 MEDIUM
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Upload function.
CVE-2025-29453 1 Personal-management-system 1 Personal Management System 2026-06-17 N/A 6.5 MEDIUM
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the my-contacts-settings component.
CVE-2025-29452 1 Seopanel 1 Seo Panel 2026-06-17 N/A 7.6 HIGH
An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Proxy Manager component.
CVE-2025-29451 1 Seopanel 1 Seo Panel 2026-06-17 N/A 7.6 HIGH
An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Mail Setting component.
CVE-2025-29450 1 Lm21 1 Twonav 2026-06-17 N/A 6.5 MEDIUM
An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the site settings component.