Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Haven MEDIUM 5.0
CVE-2023-24060

Haven 5d15944 allows Server-Side Request Forgery (SSRF) via the feed[url]= Feeds functionality. Authenticated users with the ability to create new RS…

No fix yet
Fix from $1,600 2023-01-27
Tenable.sc MEDIUM 6.5
CVE-2023-24495

A Server Side Request Forgery (SSRF) vulnerability exists in Tenable.sc due to improper validation of session & user-accessible input data. A privile…

Fix: after 5.23.1
Fix from $1,600 2023-01-26
Taocms CRITICAL 9.8
CVE-2022-46998

An issue in the website background of taocms v3.0.2 allows attackers to execute a Server-Side Request Forgery (SSRF).

No fix yet
Fix from $2,300 2023-01-26
B2236 Firmware CRITICAL 9.8
CVE-2023-23560EPSS 14%

In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.

No fix yet
Fix from $2,300 2023-01-23
Server HIGH 8.1
CVE-2021-43449

ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Server-Side Request Forgery (SSRF). The document editor service can be abused to read and s…

Fix: after 7.0.0.49
Fix from $1,950 2023-01-23
Reprise License Manager MEDIUM 6.5
CVE-2021-37498

An SSRF issue was discovered in Reprise License Manager (RLM) web interface through 14.2BL4 that allows remote attackers to trigger outbound requests…

Fix: 17.0+
Fix from $1,600 2023-01-20
Opentext Extended Ecm HIGH 8.8
CVE-2022-45926EPSS 17%

An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The endpoint notify.localizeEmailTemplate allows a low-privilege user…

Fix: after 22.3
Fix from $1,950 2023-01-18
Rsshub HIGH 7.5
CVE-2023-22493

RSSHub is an open source RSS feed generator. RSSHub is vulnerable to Server-Side Request Forgery (SSRF) attacks. This vulnerability allows an attacke…

Fix: 2023-01-10+
Fix from $1,950 2023-01-13
Advanced Cluster Management For Kubernetes HIGH 7.8
CVE-2022-3841

RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Re…

Mitigation only
Fix from $1,950 2023-01-13
Trufusion Enterprise HIGH 7.5
CVE-2022-25026EPSS 24%

A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on the interna…

Fix: 7.9.5.1+
Fix from $1,950 2023-01-12
Exchange Server HIGH 7.5
CVE-2023-21761

Microsoft Exchange Server Information Disclosure Vulnerability

No fix yet
Fix from $1,950 2023-01-10
A\+hrd CRITICAL 9.8
CVE-2022-39039

aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this vulnerability to send arbitr…

Mitigation only
Fix from $2,300 2023-01-03
Perfsonar MEDIUM 5.3
CVE-2022-45027

perfSONAR before 4.4.6, when performing participant discovery, incorrectly uses an HTTP request header value to determine a local address.

Fix: 4.4.6+
Fix from $1,600 2023-01-01
Ariadne Component Library CRITICAL 9.8
CVE-2017-20157

A vulnerability was found in Ariadne Component Library up to 2.x. It has been classified as critical. Affected is an unknown function of the file src…

Fix: 3.0+
Fix from $2,300 2022-12-31
Portal For Arcgis HIGH 7.5
CVE-2022-38211

Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.9.1 and below were not fully h…

Fix: after 10.9.1
Fix from $1,950 2022-12-29
Portal For Arcgis HIGH 7.5
CVE-2022-38212

Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.8.1 and below were not fully h…

Fix: after 10.8.1
Fix from $1,950 2022-12-29
Portal For Arcgis HIGH 7.5
CVE-2022-38203

Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.8.1 and below were not fully h…

Fix: after 10.8.1
Fix from $1,950 2022-12-29
Metersphere MEDIUM 6.1
CVE-2022-23544

MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. V…

Fix: 2.5.0+
Fix from $1,600 2022-12-28
Dss Express HIGH 7.5
CVE-2022-45429

Some Dahua software products have a vulnerability of server-side request forgery (SSRF). An Attacker can access internal resources by concatenating l…

Patch available
Fix from $1,950 2022-12-27
Aws Software Development Kit CRITICAL 9.8
CVE-2022-4725

A vulnerability was found in AWS SDK 2.59.0. It has been rated as critical. This issue affects the function XpathUtils of the file aws-android-sdk-co…

Fix: 2.59.1+
Fix from $2,300 2022-12-27
Open Xchange Appsuite MEDIUM 5.3
CVE-2022-37313

OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record.

Fix: 7.10.5+
Fix from $1,600 2022-12-26
Iboot Pdu4 N20 Firmware MEDIUM 5.3
CVE-2022-3189

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specially crafted PHP script could use parameters from a HTTP …

Fix: 1.42.06162022+
Fix from $1,600 2022-12-21
Wms CRITICAL 9.8
CVE-2022-47635

Wildix WMS 6 before 6.02.20221216, WMS 5 before 5.04.20221214, and WMS4 before 4.04.45396.23 allows Server-side request forgery (SSRF) via ZohoClient…

Fix: 4.04.45396.23 / 5.04.20221214+
Fix from $2,300 2022-12-21
Cognos Analytics CRITICAL 9.1
CVE-2022-38708

IBM Cognos Analytics 11.1.7 11.2.0, and 11.2.1 could be vulnerable to a Server-Side Request Forgery Attack (SSRF) attack by constructing URLs from us…

Fix: after 11.2.3
Fix from $2,300 2022-12-19
Campaign MEDIUM 6.5
CVE-2022-42343

Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead…

Fix: 7.3.2 / 8.4.2+
Fix from $1,600 2022-12-16
Cxf CRITICAL 9.8
CVE-2022-46364

A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attack…

Fix: 3.4.10 / 3.5.5+
Fix from $2,300 2022-12-13
Teamcity MEDIUM 5.3
CVE-2022-46830

In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.

Fix: after 2022.10.1
Fix from $1,600 2022-12-08
Proxmox Mail Gateway CRITICAL 9.8
CVE-2022-35508

Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF when proxying HTTP requests between pve(pmg)proxy and pve(pmg…

Fix: 4.1-3+
Fix from $2,300 2022-12-04
Perfsonar HIGH 8.6
CVE-2022-41412

An issue in the graphData.cgi component of perfSONAR v4.4.5 and prior allows attackers to access sensitive data and execute Server-Side Request Forge…

Fix: 4.4.5+
Fix from $1,950 2022-11-30
Moodle CRITICAL 9.1
CVE-2022-45152

A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input …

Fix: 3.9.18 / 3.11.11+
Fix from $2,300 2022-11-25