Show filters
1,106 Total Results
Displaying 301-310 of 1,106
Sort by:
Attacker Value
Unknown
CVE-2024-1884
Disclosure Date: March 14, 2024 (last updated February 26, 2025)
This is a Server-Side Request Forgery (SSRF) vulnerability in the PaperCut NG/MF server-side module that allows an attacker to induce the server-side application to make HTTP requests to an arbitrary domain of the attacker's choosing.
0
Attacker Value
Unknown
CVE-2024-2049
Disclosure Date: March 12, 2024 (last updated February 26, 2025)
Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose limited information from the appliance via Access to management IP.
0
Attacker Value
Unknown
CVE-2023-49785
Disclosure Date: March 12, 2024 (last updated February 27, 2025)
NextChat, also known as ChatGPT-Next-Web, is a cross-platform chat user interface for use with ChatGPT. Versions 2.11.2 and prior are vulnerable to server-side request forgery and cross-site scripting. This vulnerability enables read access to internal HTTP endpoints but also write access using HTTP POST, PUT, and other methods. Attackers can also use this vulnerability to mask their source IP by forwarding malicious traffic intended for other Internet targets through these open proxies. As of time of publication, no patch is available, but other mitigation strategies are available. Users may avoid exposing the application to the public internet or, if exposing the application to the internet, ensure it is an isolated network with no access to any other internal resources.
0
Attacker Value
Unknown
CVE-2024-27707
Disclosure Date: March 07, 2024 (last updated February 26, 2025)
Server Side Request Forgery (SSRF) vulnerability in hcengineering Huly Platform v.0.6.202 allows attackers to run arbitrary code via upload of crafted SVG file.
0
Attacker Value
Unknown
CVE-2024-27565
Disclosure Date: March 05, 2024 (last updated February 26, 2025)
A Server-Side Request Forgery (SSRF) in weixin.php of ChatGPT-wechat-personal commit a0857f6 allows attackers to force the application to make arbitrary requests.
0
Attacker Value
Unknown
CVE-2024-27564
Disclosure Date: March 05, 2024 (last updated February 26, 2025)
A Server-Side Request Forgery (SSRF) in pictureproxy.php of ChatGPT commit f9f4bbc allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the urlparameter.
0
Attacker Value
Unknown
CVE-2024-27563
Disclosure Date: March 05, 2024 (last updated February 26, 2025)
A Server-Side Request Forgery (SSRF) in the getFileFromRepo function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the pluginThemeUrl parameter.
0
Attacker Value
Unknown
CVE-2024-27561
Disclosure Date: March 05, 2024 (last updated February 26, 2025)
A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the installThemePlugin parameter.
0
Attacker Value
Unknown
CVE-2024-2057
Disclosure Date: March 01, 2024 (last updated February 26, 2025)
A vulnerability was found in LangChain langchain_community 0.0.26. It has been classified as critical. Affected is the function load_local in the library libs/community/langchain_community/retrievers/tfidf.py of the component TFIDFRetriever. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.0.27 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-255372.
0
Attacker Value
Unknown
CVE-2024-27949
Disclosure Date: March 01, 2024 (last updated February 26, 2025)
Server-Side Request Forgery (SSRF) vulnerability in sirv.Com Image Optimizer, Resizer and CDN – Sirv.This issue affects Image Optimizer, Resizer and CDN – Sirv: from n/a through 7.2.0.
0