Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Ndkadvancedcustomizationfields CRITICAL 9.1
CVE-2022-40842

ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side request forgery (SSRF) via rotateimg.php.

Fix: after 3.5.0
Fix from $2,300 2022-11-22
Appsmith MEDIUM 6.5
CVE-2022-4096

Server-Side Request Forgery (SSRF) in GitHub repository appsmithorg/appsmith prior to 1.8.2.

Fix: 1.8.2+
Fix from $1,600 2022-11-21
Better Messages HIGH 8.8
CVE-2022-41609

Auth. (subscriber+) Server-Side Request Forgery (SSRF) vulnerability in Better Messages plugin 1.9.10.68 on WordPress.

Fix: 1.9.10.69+
Fix from $1,950 2022-11-19
Xxl Job HIGH 8.8
CVE-2022-43183

XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.

Fix: after 2.3.1
Fix from $1,950 2022-11-17
Syngo Dynamics Cardiovascular Imaging And Information System HIGH 7.5
CVE-2022-42894

A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). An unauthenticated Server-Side Request Forgery (SSRF) vulnerabilit…

Mitigation only
Fix from $1,950 2022-11-17
Kkfileview HIGH 7.5
CVE-2022-43140

kkFileView v4.1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component cn.keking.web.controller.OnlinePreviewController#g…

No fix yet
Fix from $1,950 2022-11-17
Kubevela MEDIUM 6.5
CVE-2022-39383

KubeVela is an open source application delivery platform. Users using the VelaUX APIServer could be affected by this vulnerability. When using Helm C…

Fix: 1.5.9 / 1.6.2+
Fix from $1,600 2022-11-16
Opensearch Notifications HIGH 8.7
CVE-2022-41906

OpenSearch Notifications is a notifications plugin for OpenSearch that enables other plugins to send notifications via Email, Slack, Amazon Chime, Cu…

Fix: 2.2.1.0+
Fix from $1,950 2022-11-11
All In One Seo MEDIUM 6.5
CVE-2022-42494

Server Side Request Forgery (SSRF) vulnerability in All in One SEO Pro plugin <= 4.2.5.1 on WordPress.

Fix: after 4.2.5.1
Fix from $1,600 2022-11-08
Broadworks Messaging Server MEDIUM 6.5
CVE-2022-20951

A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an authenticated, remote attacker to perf…

Fix: 23.0+
Fix from $1,600 2022-11-04
Broadworks Commpilot Application HIGH 8.8
CVE-2022-20958

A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an unauthenticated, remote attacker to pe…

Fix: 23.0+
Fix from $1,950 2022-11-04
Glpi MEDIUM 5.3
CVE-2022-39276

GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk feat…

Fix: 10.0.4+
Fix from $1,600 2022-11-03
Infrastructure Analytics Advisor CRITICAL 9.8
CVE-2022-41552

Server-Side Request Forgery (SSRF) vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Data Center Analytics, Analytics probe compone…

Fix: 10.9.0-00+
Fix from $2,300 2022-11-01
Php Point Of Sale CRITICAL 9.8
CVE-2022-40296

The application was vulnerable to a Server-Side Request Forgery attacks, allowing the backend server to interact with unexpected endpoints, potential…

Mitigation only
Fix from $2,300 2022-10-31
Web Stories HIGH 8.1
CVE-2022-3708

The Web Stories plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including 1.24.0 due to insufficient validat…

Fix: 1.25.0+
Fix from $1,950 2022-10-28
Metabase MEDIUM 6.5
CVE-2022-43776

The url parameter of the /api/geojson endpoint in Metabase versions <44.5 can be used to perform Server Side Request Forgery attacks. Previously impl…

Fix: 0.44.5+
Fix from $1,600 2022-10-26
Micollab HIGH 8.8
CVE-2022-36451

A vulnerability in the MiCollab Client server component of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to conduct a Server…

Fix: after 9.5.0.101
Fix from $1,950 2022-10-25
Batik HIGH 7.5
CVE-2022-41704

A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics pri…

Fix: 1.16+
Fix from $1,950 2022-10-25
Batik HIGH 7.5
CVE-2022-42890

A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML …

Fix: 1.16+
Fix from $1,950 2022-10-25
Blog2social MEDIUM 6.5
CVE-2022-3247

The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not have authorisation in an AJAX action, and does not ensure…

Fix: 6.9.10+
Fix from $1,600 2022-10-25
Skipper CRITICAL 9.8
CVE-2022-38580EPSS 11%

Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).

Fix: 0.13.237+
Fix from $2,300 2022-10-25
Rava Certificate Validation System MEDIUM 5.3
CVE-2022-39055

RAVA certificate validation system has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform SSRF attack to discover…

Mitigation only
Fix from $1,600 2022-10-18
Kkfileview CRITICAL 9.8
CVE-2022-42149

kkFileView 4.0 is vulnerable to Server-side request forgery (SSRF) via controller\OnlinePreviewController.java.

Mitigation only
Fix from $2,300 2022-10-17
Webid CRITICAL 9.1
CVE-2022-41477

A security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.php file allows remote attack…

Fix: after 1.2.2
Fix from $2,300 2022-10-14
Icms CRITICAL 9.8
CVE-2022-41496

iCMS v7.0.16 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php.

No fix yet
Fix from $2,300 2022-10-13
Clippercms CRITICAL 9.8
CVE-2022-41497

ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the pkg_url parameter at /manager/index.php.

No fix yet
Fix from $2,300 2022-10-13
Clippercms CRITICAL 9.8
CVE-2022-41495

ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the rss_url_news parameter at /manager/index.php.

No fix yet
Fix from $2,300 2022-10-13
Label Studio MEDIUM 6.5
CVE-2022-36551EPSS 5%

A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier allows an authe…

Fix: after 1.5.0
Fix from $1,600 2022-10-03
Exchange Server HIGH 8.8
CVE-2022-41040 KEVEPSS 100%

Microsoft Exchange Server Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2022-10-03
Websphere Application Server MEDIUM 6.5
CVE-2022-35282

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, …

Fix: 7.0.0.45 / 8.0.0.15+
Fix from $1,600 2022-09-28