Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Business Process Management MEDIUM 5.3
CVE-2022-32457

Digiwin BPM has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network…

Fix: 5.8.8.1+
Fix from $1,600 2022-07-20
Partner Engagement Manager MEDIUM 5.4
CVE-2022-22416

IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to server-side request forgery (SSRF). This may allow an authen…

Fix: 6.1.2.5 / 6.2.0.3+
Fix from $1,600 2022-07-19
Request Tracker For Incident Response CRITICAL 9.1
CVE-2022-25800

Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool.

Fix: 4.0.3 / 5.0.3+
Fix from $2,300 2022-07-14
Request Tracker For Incident Response CRITICAL 9.1
CVE-2022-25801

Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools.

Fix: 4.0.3 / 5.0.3+
Fix from $2,300 2022-07-14
Cloud Foundation HIGH 7.5
CVE-2022-22982

The vCenter Server contains a server-side request forgery (SSRF) vulnerability. A malicious actor with network access to 443 on the vCenter Server ma…

Fix: after 4.3.1
Fix from $1,950 2022-07-13
Nocodb HIGH 7.5
CVE-2022-2339

With this SSRF vulnerability, an attacker can reach internal addresses to make a request as the server and read it's contents. This attack can lead t…

Fix: 0.92.0+
Fix from $1,950 2022-07-07
Link Preview Js MEDIUM 5.5
CVE-2022-25876

The package link-preview-js before 2.1.16 are vulnerable to Server-side Request Forgery (SSRF) which allows attackers to send arbitrary requests to t…

Fix: 2.1.16+
Fix from $1,600 2022-07-01
Jira Data Center MEDIUM 6.5
CVE-2022-26135EPSS 71%

A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up fea…

Fix: 4.13.22 / 4.20.10+
Fix from $1,600 2022-06-30
Dompdf MEDIUM 5.3
CVE-2022-0085

Server-Side Request Forgery (SSRF) in GitHub repository dompdf/dompdf prior to 2.0.0.

Fix: 2.0.0+
Fix from $1,600 2022-06-28
Halo CRITICAL 9.8
CVE-2022-32995EPSS 16%

Halo CMS v1.5.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the template remote download function.

No fix yet
Fix from $2,300 2022-06-27
Parse Url CRITICAL 9.8
CVE-2022-2216

Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 7.0.0.

Fix: 7.0.0+
Fix from $2,300 2022-06-27
Import All Pages\, Post Types\, Products\, Orders\, And Users As Xml \& Csv HIGH 7.2
CVE-2022-1977

The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL b…

Fix: 6.5.3+
Fix from $1,950 2022-06-27
Directus MEDIUM 5.0
CVE-2022-23080

In directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media upload functionality which allows …

Fix: after 9.6.0
Fix from $1,600 2022-06-22
Qlik Sense MEDIUM 5.3
CVE-2021-36761

The GeoAnalytics feature in Qlik Sense April 2020 patch 4 allows SSRF.

Mitigation only
Fix from $1,600 2022-06-21
Recipes MEDIUM 6.5
CVE-2022-23071

In Recipes, versions 0.9.1 through 1.2.5 are vulnerable to Server Side Request Forgery (SSRF), in the “Import Recipe” functionality. When an attacker…

Fix: after 1.2.5
Fix from $1,600 2022-06-19
Flatcore Cms CRITICAL 9.8
CVE-2021-41403EPSS 19%

flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities.

Patch available
Fix from $2,300 2022-06-15
Ips Community Suite CRITICAL 9.1
CVE-2021-40604

A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users to request arbitrary URLs or…

Fix: 4.6.2+
Fix from $2,300 2022-06-13
Netweaver MEDIUM 6.5
CVE-2022-28217

Some part of SAP NetWeaver (EP Web Page Composer) does not sufficiently validate an XML document accepted from an untrusted source, which allows an a…

No fix yet
Fix from $1,600 2022-06-13
Dubbo MEDIUM 6.1
CVE-2022-24969

bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check whic…

Fix: 2.6.12 / 2.7.15+
Fix from $1,600 2022-06-09
Nbnbk CRITICAL 9.1
CVE-2022-31386

A Server-Side Request Forgery (SSRF) in the getFileBinary function of nbnbk cms 3 allows attackers to force the application to make arbitrary request…

No fix yet
Fix from $2,300 2022-06-09
Jizhicms CRITICAL 9.1
CVE-2022-31390

Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Update function in app/admin/c/TemplateControlle…

No fix yet
Fix from $2,300 2022-06-09
Jizhicms CRITICAL 9.1
CVE-2022-31393

Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Index function in app/admin/c/PluginsController.…

No fix yet
Fix from $2,300 2022-06-09
Monstaftp CRITICAL 9.1
CVE-2022-31827EPSS 21%

MonstaFTP v2.10.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the function performFetchRequest at HTTPFetcher.php.

No fix yet
Fix from $2,300 2022-06-09
Kity Minder CRITICAL 9.1
CVE-2022-31830EPSS 16%

Kity Minder v1.3.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the init function at ImageCapture.class.php.

No fix yet
Fix from $2,300 2022-06-09
Curl HIGH 7.5
CVE-2022-27780

The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usi…

Fix: 7.83.1+
Fix from $1,950 2022-06-02
Dotnetnuke HIGH 7.5
CVE-2021-40186

The AppCheck research team identified a Server-Side Request Forgery (SSRF) vulnerability within the DNN CMS platform, formerly known as DotNetNuke. S…

Fix: after 9.10.2
Fix from $1,950 2022-06-02
Gogs MEDIUM 6.5
CVE-2022-1285

Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.8.

Fix: 0.12.8+
Fix from $1,600 2022-06-01
Drawio HIGH 7.5
CVE-2022-1815EPSS 6%

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2.

Fix: 18.1.2+
Fix from $1,950 2022-05-25
Mysiteforme HIGH 7.5
CVE-2022-29309

mysiteforme v2.2.1 was discovered to contain a Server-Side Request Forgery.

No fix yet
Fix from $1,950 2022-05-24
Cszcms HIGH 7.5
CVE-2022-28997

CSZCMS v1.3.0 allows attackers to execute a Server-Side Request Forgery (SSRF) which can be leveraged to leak sensitive data via a local file inclusi…

No fix yet
Fix from $1,950 2022-05-23