Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Post Smtp HIGH 7.2
CVE-2022-2352

The Post SMTP Mailer/Email Log WordPress plugin before 2.1.7 does not have proper authorisation in some AJAX actions, which could allow high privileg…

Fix: 2.1.7+
Fix from $1,950 2022-09-26
Discovery HIGH 7.5
CVE-2022-23464

Nepxion Discovery is a solution for Spring Cloud. Discovery is vulnerable to a potential Server-Side Request Forgery (SSRF). RouterResourceImpl uses …

Fix: after 6.16.2
Fix from $1,950 2022-09-24
Netlify Ipx MEDIUM 5.4
CVE-2022-39239

netlify-ipx is an on-Demand image optimization for Netlify using ipx. In versions prior to 1.2.3, an attacker can bypass the source image domain allo…

Fix: 1.2.3+
Fix from $1,600 2022-09-23
Batik MEDIUM 5.3
CVE-2022-38398

Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue a…

Mitigation only
Fix from $1,600 2022-09-22
Batik MEDIUM 5.3
CVE-2022-38648

Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects A…

Mitigation only
Fix from $1,600 2022-09-22
Batik HIGH 7.5
CVE-2022-40146EPSS 6%

Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affec…

Mitigation only
Fix from $1,950 2022-09-22
Z Blogphp CRITICAL 9.8
CVE-2022-40357

A security issue was discovered in Z-BlogPHP <= 1.7.2. A Server-Side Request Forgery (SSRF) vulnerability in the zb_users/plugin/UEditor/php/action_c…

Fix: after 1.7.2
Fix from $2,300 2022-09-20
Baijiacms HIGH 8.8
CVE-2022-38931

A Server-Side Request Forgery (SSRF) in fetch_net_file_upload function of baijiacmsV4 v4.1.4 allows remote attackers to force the application to make…

No fix yet
Fix from $1,950 2022-09-20
Spotfire Analytics Platform HIGH 8.4
CVE-2022-30579

The Web Player component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a difficul…

Mitigation only
Fix from $1,950 2022-09-20
Nextcloud Enterprise Server MEDIUM 5.3
CVE-2022-39211

Nextcloud server is an open source personal cloud platform. In affected versions it was found that locally running webservices can be found and reque…

Fix: 22.2.10.4 / 23.0.8+
Fix from $1,600 2022-09-16
Glpi MEDIUM 5.8
CVE-2022-36112

GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk featu…

Fix: 10.0.3+
Fix from $1,600 2022-09-14
Parse Url CRITICAL 9.1
CVE-2022-2900

Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 8.1.0.

Fix: 8.1.0+
Fix from $2,300 2022-09-14
Appsmith HIGH 8.8
CVE-2022-38298

Appsmith v1.7.11 was discovered to allow attackers to execute an authenticated Server-Side Request Forgery (SSRF) via redirecting incoming requests t…

Patch available
Fix from $1,950 2022-09-12
Senayan Library Management System CRITICAL 9.8
CVE-2022-38292

SLiMS Senayan Library Management System v9.4.2 was discovered to contain multiple Server-Side Request Forgeries via the components /bibliography/marc…

No fix yet
Fix from $2,300 2022-09-12
Seo CRITICAL 9.8
CVE-2022-36376

Server-Side Request Forgery (SSRF) vulnerability in Rank Math SEO plugin <= 1.0.95 at WordPress.

Fix: after 1.0.95
Fix from $2,300 2022-09-09
Canto CRITICAL 9.8
CVE-2022-40305

A Server-Side Request Forgery issue in Canto Cumulus through 11.1.3 allows attackers to enumerate the internal network, overload network resources, a…

Fix: after 11.1.3
Fix from $2,300 2022-09-09
Oxauth CRITICAL 9.8
CVE-2022-36663

Gluu Oxauth before v4.4.1 allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted request_uri parameter.

Fix: 4.4.1+
Fix from $2,300 2022-09-06
Databasir HIGH 7.5
CVE-2022-31196

Databasir is a database metadata management platform. Databasir <= 1.06 has Server-Side Request Forgery (SSRF) vulnerability. The SSRF is triggered b…

Fix: 1.0.7+
Fix from $1,950 2022-09-02
Publiccms CRITICAL 9.8
CVE-2021-27693

Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage.

Fix: 4.0.202011.b+
Fix from $2,300 2022-09-02
Wkhtmltopdf CRITICAL 9.8
CVE-2022-35583EPSS 15%

wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial…

No fix yet
Fix from $2,300 2022-08-22
Portal For Arcgis HIGH 7.5
CVE-2022-38187

Prior to version 10.9.0, the sharing/rest/content/features/analyze endpoint is always accessible to anonymous users, which could allow an unauthentic…

Fix: 10.9+
Fix from $1,950 2022-08-15
Cling HIGH 7.5
CVE-2020-23622

An issue in the UPnP protocol in 4thline cling 2.0.0 through 2.1.2 allows remote attackers to cause a denial of service via an unchecked CALLBACK par…

Fix: after 2.1.2
Fix from $1,950 2022-08-15
Undici CRITICAL 9.8
CVE-2022-35949

undici is an HTTP/1.1 client, written from scratch for Node.js.`undici` is vulnerable to SSRF (Server-side Request Forgery) when an application takes…

Fix: after 5.8.1
Fix from $2,300 2022-08-12
Collaboration HIGH 7.5
CVE-2022-37041

An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. The value of the X-Forwarded-H…

Patch available
Fix from $1,950 2022-08-12
Kavita MEDIUM 6.5
CVE-2022-2756

Server-Side Request Forgery (SSRF) in GitHub repository kareadita/kavita prior to 0.5.4.1.

Fix: 0.5.4.1+
Fix from $1,600 2022-08-10
Mail CRITICAL 9.8
CVE-2022-31132

Nextcloud Mail is an email application for the nextcloud personal cloud product. Affected versions shipped with a CSS minifier on the path `./vendor/…

Fix: 1.12.8 / 1.13.6+
Fix from $2,300 2022-08-04
Computer Vision Annotation Tool CRITICAL 9.8
CVE-2022-31188EPSS 49%

CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were found to be subject to a Server-s…

Fix: 2.0.0+
Fix from $2,300 2022-08-01
Datapower Gateway HIGH 8.8
CVE-2022-31776

IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to server-side…

Fix: 10.5.0.1+
Fix from $1,950 2022-08-01
Flex Appliance HIGH 8.8
CVE-2022-36997

An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and rel…

Patch available
Fix from $1,950 2022-07-28
Jira Service Desk MEDIUM 5.7
CVE-2021-43959

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to access the content of internal …

Fix: 4.13.20 / 4.20.8+
Fix from $1,600 2022-07-26