Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Project Management System CRITICAL 9.8
CVE-2023-1725

Server-Side Request Forgery (SSRF) vulnerability in Infoline Project Management System allows Server Side Request Forgery. This issue affects Projec…

Fix: 4.09.31.125+
Fix from $2,300 2023-03-30
Fineract HIGH 8.1
CVE-2023-25195

Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache Fineract. Authorized users with limited permissions can gain ac…

Fix: after 1.8.3
Fix from $1,950 2023-03-28
Designer HIGH 7.5
CVE-2023-25262

Stimulsoft GmbH Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Server Side Request Forgery (SSRF). TThe Reporting Designer (Web) offers the poss…

No fix yet
Fix from $1,950 2023-03-28
Otcms CRITICAL 9.8
CVE-2023-1634

A vulnerability was found in OTCMS 6.72. It has been classified as critical. Affected is the function UseCurl of the file /admin/info_deal.php of the…

No fix yet
Fix from $2,300 2023-03-25
Cairosvg HIGH 7.1
CVE-2023-27586

CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to external hosts when processing…

Fix: 2.7.0+
Fix from $1,950 2023-03-20
Discourse HIGH 8.1
CVE-2023-28112

Discourse is an open-source discussion platform. Prior to version 3.1.0.beta3 of the `beta` and `tests-passed` branches, some user provided URLs were…

Fix: 3.1.0+
Fix from $1,950 2023-03-17
Discourse HIGH 7.5
CVE-2023-28111

Discourse is an open-source discussion platform. Prior to version 3.1.0.beta3 of the `beta` and `tests-passed` branches, attackers are able to bypass…

Fix: 3.1.0+
Fix from $1,950 2023-03-17
Request MEDIUM 6.1
CVE-2023-28155

The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redir…

Fix: after 2.88.1
Fix from $1,600 2023-03-16
Businessobjects Business Intelligence HIGH 7.5
CVE-2023-27896

In SAP BusinessObjects Business Intelligence Platform - version 420, 430, an attacker can control a malicious BOE server, forcing the application ser…

Mitigation only
Fix from $1,950 2023-03-14
Businessobjects Business Intelligence Platform HIGH 7.5
CVE-2023-27271

In SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, an attacker can control a malicious BOE server, forcing the…

Mitigation only
Fix from $1,950 2023-03-14
Netweaver Application Server Abap HIGH 7.4
CVE-2023-26459

Due to improper input controls In SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, …

Mitigation only
Fix from $1,950 2023-03-14
Jellyfin HIGH 7.5
CVE-2023-27161

Jellyfin up to v10.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /Repositories. This vulnerability allows atta…

Fix: after 10.7.7
Fix from $1,950 2023-03-10
Moodle HIGH 7.5
CVE-2021-36396

In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF…

Fix: 3.9.8 / 3.10.5+
Fix from $1,950 2023-03-06
Aj Report CRITICAL 9.8
CVE-2022-46973

Report v0.9.8.6 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability.

No fix yet
Fix from $2,300 2023-03-03
Directus HIGH 7.5
CVE-2023-26492

Directus is a real-time API and App dashboard for managing SQL database content. Directus is vulnerable to Server-Side Request Forgery (SSRF) when im…

Fix: 9.23.0+
Fix from $1,950 2023-03-03
Serviceguard For Linux CRITICAL 9.8
CVE-2022-37938

Unauthenticated server side request forgery in HPE Serviceguard Manager

Mitigation only
Fix from $2,300 2023-03-01
Muyucms HIGH 8.8
CVE-2023-1046

A vulnerability classified as critical has been found in MuYuCMS 2.2. This affects an unknown part of the file /admin.php/update/getFile.html. The ma…

No fix yet
Fix from $1,950 2023-02-26
Build Of Quarkus HIGH 7.5
CVE-2022-4492

The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least…

Mitigation only
Fix from $1,950 2023-02-23
Plone HIGH 8.8
CVE-2021-33926

An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1, 5.1.7, 5.1.6, 5.1.5, 5.1.4, 5.1.2, 5.1…

No fix yet
Fix from $1,950 2023-02-17
Computer Vision Annotation Tool MEDIUM 6.5
CVE-2022-27234

Server-side request forgery in the CVAT software maintained by Intel(R) before version 2.0.1 may allow an authenticated user to potentially enable in…

Fix: 2.0.1+
Fix from $1,600 2023-02-16
Splunk MEDIUM 6.3
CVE-2023-22936

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘search_listener’ parameter in a search allows for a blind server-side request for…

Fix: 8.1.13 / 8.2.10+
Fix from $1,600 2023-02-14
Nextcloud Server MEDIUM 5.3
CVE-2023-25162

Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server prior to 24.0.8 and 23.0.12 and Nex…

Fix: 23.0.12 / 24.0.8+
Fix from $1,600 2023-02-13
Smartpower Web MEDIUM 6.5
CVE-2022-45085

Server-Side Request Forgery (SSRF) vulnerability in Group Arge Energy and Control Systems Smartpower Web allows : Server Side Request Forgery. This …

Fix: 23.01.01+
Fix from $1,600 2023-02-12
Datahub CRITICAL 9.1
CVE-2023-25557

DataHub is an open-source metadata platform. The DataHub frontend acts as a proxy able to forward any REST or GraphQL requests to the backend. The go…

Fix: 0.8.45+
Fix from $2,300 2023-02-11
Yugabytedb Managed CRITICAL 9.8
CVE-2023-0574

Server-Side Request Forgery (SSRF), Improperly Controlled Modification of Dynamically-Determined Object Attributes, Improper Restriction of Excessive…

Fix: after 2.13
Fix from $2,300 2023-02-09
Dotcms MEDIUM 6.5
CVE-2022-37033

In dotCMS 5.x-22.06, TempFileAPI allows a user to create a temporary file based on a passed in URL, while attempting to block any SSRF access to loca…

Fix: 21.06.12 / 22.03.4+
Fix from $1,600 2023-02-01
Maccms HIGH 8.8
CVE-2022-47872

A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a crafted p…

No fix yet
Fix from $1,950 2023-02-01
Safeurl Python MEDIUM 5.3
CVE-2023-24622

isInList in the safeurl-python package before 1.2 for Python has an insufficiently restrictive regular expression for external domains, leading to SS…

No fix yet
Fix from $1,600 2023-01-30
Paranoidhttp HIGH 7.5
CVE-2023-24623

Paranoidhttp before 0.3.0 allows SSRF because [::] is equivalent to the 127.0.0.1 address, but does not match the filter for private addresses.

Fix: 0.3.0+
Fix from $1,950 2023-01-30
GitLab MEDIUM 5.3
CVE-2022-4201

A blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 allows an attacker to connect to…

Fix: 15.4.6 / 15.5.5+
Fix from $1,600 2023-01-27