Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Xml Graphics Batik HIGH 7.1
CVE-2022-44729

Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik…

Fix: after 1.16
Fix from $1,950 2023-08-22
Cognos Analytics MEDIUM 5.4
CVE-2023-35011

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send…

Fix: 11.1.7 / 11.2.4+
Fix from $1,600 2023-08-16
Flarum HIGH 7.1
CVE-2023-40033

Flarum is an open source forum software. Flarum is affected by a vulnerability that allows an attacker to conduct a Blind Server-Side Request Forgery…

Fix: 1.8.0+
Fix from $1,950 2023-08-16
Wp Remote Users Sync MEDIUM 5.4
CVE-2023-3958

The WP Remote Users Sync plugin for WordPress is vulnerable to Server Side Request Forgery via the 'notify_ping_remote' AJAX function in versions up …

Fix: 1.2.13+
Fix from $1,600 2023-08-16
Openrefine MEDIUM 6.5
CVE-2022-41401

OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, potentially…

Fix: after 3.5.2
Fix from $1,600 2023-08-04
Rconfig HIGH 8.8
CVE-2023-39108

rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_b parameter in the doDiff Function of /classes/compareClas…

No fix yet
Fix from $1,950 2023-08-01
Rconfig HIGH 8.8
CVE-2023-39109

rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_a parameter in the doDiff Function of /classes/compareClas…

No fix yet
Fix from $1,950 2023-08-01
Rconfig HIGH 8.8
CVE-2023-39110

rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path parameter at /ajaxGetFileByPath.php. This vulnerability al…

No fix yet
Fix from $1,950 2023-08-01
Spectrum Spatial Analyst CRITICAL 9.1
CVE-2022-42183

Precisely Spectrum Spatial Analyst 20.01 is vulnerable to Server-Side Request Forgery (SSRF).

Patch available
Fix from $2,300 2023-07-31
Deskpro HIGH 7.2
CVE-2021-35391

Server Side Request Forgery vulnerability found in Deskpro Support Desk v2021.21.6 allows attackers to execute arbitrary code via a crafted URL.

No fix yet
Fix from $1,950 2023-07-21
Document On Line Submission And Approval System HIGH 7.5
CVE-2023-37290

InfoDoc Document On-line Submission and Approval System lacks sufficient restrictions on the available tags within its HTML to PDF conversion functio…

Mitigation only
Fix from $1,950 2023-07-20
Sterling Connect\ MEDIUM 5.4
CVE-2023-29260

IBM Sterling Connect:Express for UNIX 1.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unaut…

Patch available
Fix from $1,600 2023-07-19
Power Apps MEDIUM 5.4
CVE-2023-32052

Microsoft Power Apps (online) Spoofing Vulnerability

Fix: 9.2.23042+
Fix from $1,600 2023-07-11
Solution Manager HIGH 7.2
CVE-2023-36925

SAP Solution Manager (Diagnostics agent) - version 7.20, allows an unauthenticated attacker to blindly execute HTTP requests. On successful exploitat…

Mitigation only
Fix from $1,950 2023-07-11
Dedecms CRITICAL 9.8
CVE-2023-3578

A vulnerability classified as critical was found in DedeCMS 5.7.109. Affected by this vulnerability is an unknown functionality of the file co_do.php…

No fix yet
Fix from $2,300 2023-07-10
Opencomputers HIGH 8.8
CVE-2023-37261

OpenComputers is a Minecraft mod that adds programmable computers and robots to the game. This issue affects every version of OpenComputers with the …

Fix: 1.8.3+
Fix from $1,950 2023-07-07
Cc Tweaked HIGH 8.8
CVE-2023-37262

CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to versions 1.20.1-1.106.0, 1.19.4-1.106.0…

Fix: 1.16.5-1.101.3 / 1.18.2-1.101.3+
Fix from $1,950 2023-07-07
W1a75a Firmware CRITICAL 9.8
CVE-2023-35175

Certain HP LaserJet Pro print products are potentially vulnerable to Potential Remote Code Execution and/or Elevation of Privilege via Server-Side Re…

Fix: 002_2322c+
Fix from $2,300 2023-06-30
Fedora CRITICAL 10.0
CVE-2023-3432

Server-Side Request Forgery (SSRF) in GitHub repository plantuml/plantuml prior to 1.2023.9.

Fix: 1.2023.9+
Fix from $2,300 2023-06-27
Bigbluebutton MEDIUM 6.5
CVE-2023-33176

BigBlueButton is an open source virtual classroom designed to help teachers teach and learners learn. In affected versions are affected by a Server-S…

Fix: 2.5.18 / 2.6.9+
Fix from $1,600 2023-06-26
Debian Linux HIGH 7.5
CVE-2023-36661

Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed in…

Fix: 3.2.4+
Fix from $1,950 2023-06-25
Moodle HIGH 7.5
CVE-2023-35133

An issue in the logic used to check 0.0.0.0 against the cURL blocked hosts lists resulted in an SSRF risk. This flaw affects Moodle versions 4.2, 4.1…

Fix: 3.9.22 / 3.11.15+
Fix from $1,950 2023-06-22
Open Xchange Appsuite Backend MEDIUM 5.0
CVE-2023-26435

It was possible to call filesystem and network references using the local LibreOffice instance using manipulated ODT documents. Attackers could disco…

Fix: 7.10.6+
Fix from $1,600 2023-06-20
Arc HIGH 7.5
CVE-2023-24243

CData RSB Connect v22.0.8336 was discovered to contain a Server-Side Request Forgery (SSRF).

Fix: 22.0.8473+
Fix from $1,950 2023-06-16
Android MEDIUM 5.5
CVE-2023-21105

In multiple functions of ChooserActivity.java, there is a possible cross-user media read due to a confused deputy. This could lead to local informati…

Patch available
Fix from $1,600 2023-06-15
Otcms CRITICAL 9.8
CVE-2023-3238

A vulnerability, which was classified as critical, has been found in OTCMS up to 6.62. This issue affects some unknown processing of the file /admin/…

Fix: after 6.62
Fix from $2,300 2023-06-14
Crmeb HIGH 8.8
CVE-2023-3233

A vulnerability was found in Zhong Bang CRMEB up to 4.6.0. It has been classified as critical. Affected is the function get_image_base64 of the file …

Fix: after 4.6.0
Fix from $1,950 2023-06-14
Mccms HIGH 8.8
CVE-2023-3235

A vulnerability was found in mccms up to 2.6.5. It has been rated as critical. Affected by this issue is the function pic_api of the file sys/apps/co…

Fix: after 2.6.5
Fix from $1,950 2023-06-14
Mccms HIGH 8.8
CVE-2023-3236

A vulnerability classified as critical has been found in mccms up to 2.6.5. This affects the function pic_save of the file sys/apps/controllers/admin…

Fix: after 2.6.5
Fix from $1,950 2023-06-14
Fortianalyzer MEDIUM 6.5
CVE-2023-25609

A server-side request forgery (SSRF) vulnerability [CWE-918] in FortiManager and FortiAnalyzer GUI 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.8 th…

Fix: after 7.0.6
Fix from $1,600 2023-06-13