Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Smokescreen MEDIUM 6.5
CVE-2022-29188

Smokescreen is an HTTP proxy. The primary use case for Smokescreen is to prevent server-side request forgery (SSRF) attacks in which external attacke…

Fix: 0.0.4+
Fix from $1,600 2022-05-21
Drawio HIGH 7.5
CVE-2022-1784

Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.8.

Fix: 18.0.8+
Fix from $1,950 2022-05-20
Drawio HIGH 7.5
CVE-2022-1767

Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.7.

Fix: 18.0.7+
Fix from $1,950 2022-05-18
Oneview CRITICAL 9.8
CVE-2022-28616

A remote server-side request forgery (ssrf) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update …

Fix: 7.0+
Fix from $2,300 2022-05-17
Flyte Console HIGH 7.5
CVE-2022-24856EPSS 10%

FlyteConsole is the web user interface for the Flyte platform. FlyteConsole prior to version 0.52.0 is vulnerable to server-side request forgery (SSR…

Fix: 0.52.0+
Fix from $1,950 2022-05-17
Drawio HIGH 7.5
CVE-2022-1711EPSS 6%

Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.5.

Fix: 18.0.5+
Fix from $1,950 2022-05-17
Drawio HIGH 7.5
CVE-2022-1723

Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.6.

Fix: 18.0.6+
Fix from $1,950 2022-05-17
Drawio HIGH 7.5
CVE-2022-1713EPSS 10%

SSRF on /proxy in GitHub repository jgraph/drawio prior to 18.0.4. An attacker can make a request as the server and read its contents. This can lead …

Fix: 18.0.4+
Fix from $1,950 2022-05-16
Fusion Builder CRITICAL 9.8
CVE-2022-1386EPSS 72%

The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate…

Fix: 3.6.2 / 7.6.2+
Fix from $2,300 2022-05-16
External Media Without Import MEDIUM 6.5
CVE-2022-1398

The External Media without Import WordPress plugin through 1.1.2 does not have any authorisation and does to ensure that medias added via URLs are ex…

Fix: after 1.1.2
Fix from $1,600 2022-05-16
Rebuild HIGH 7.5
CVE-2022-30049

A Server-Side Request Forgery (SSRF) in Rebuild v2.8.3 allows attackers to obtain the real IP address and scan Intranet information via the fileurl p…

No fix yet
Fix from $1,950 2022-05-15
Fedora CRITICAL 9.1
CVE-2022-1379

URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are impo…

Fix: 1.2022.5+
Fix from $2,300 2022-05-14
Microstrategy Web HIGH 8.1
CVE-2020-22983

A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers to condu…

Fix: after 11.1
Fix from $1,950 2022-05-13
Whatsup Gold HIGH 7.5
CVE-2022-29847EPSS 57%

In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to invoke an API transaction that…

Fix: after 21.1.1
Fix from $1,950 2022-05-11
Whatsup Gold MEDIUM 6.5
CVE-2022-29848

In Progress Ipswitch WhatsUp Gold 17.0.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke an API transaction that would…

Fix: after 21.1.1
Fix from $1,600 2022-05-11
Charm CRITICAL 9.8
CVE-2022-29180

A vulnerability in which attackers could forge HTTP requests to manipulate the `charm` data directory to access or delete anything on the server. Thi…

Fix: 0.12.1+
Fix from $2,300 2022-05-07
Scout HIGH 8.2
CVE-2022-1592

Server-Side Request Forgery in scout in GitHub repository clinical-genomics/scout prior to v4.42. An attacker could make the application perform arbi…

Fix: 4.42+
Fix from $1,950 2022-05-05
Administration Center MEDIUM 6.5
CVE-2022-29942

Talend Administration Center has a vulnerability that allows an authenticated user to use the Service Registry 'Add' functionality to perform SSRF HT…

Mitigation only
Fix from $1,600 2022-05-04
Jspxcms MEDIUM 6.5
CVE-2022-28090

Jspxcms v10.2.0 allows attackers to execute a Server-Side Request Forgery (SSRF) via /cmscp/ext/collect/fetch_url.do?url=.

No fix yet
Fix from $1,600 2022-05-04
Hubspot HIGH 8.8
CVE-2022-1239

The HubSpot WordPress plugin before 8.8.15 does not validate the proxy URL given to the proxy REST endpoint, which could allow users with the edit_po…

Fix: 8.8.15+
Fix from $1,950 2022-05-02
Geoserver HIGH 7.5
CVE-2021-40822EPSS 19%

GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.

Fix: 2.19.3+
Fix from $1,950 2022-05-02
Proxyscotch HIGH 7.5
CVE-2022-25850

The package github.com/hoppscotch/proxyscotch before 1.0.0 are vulnerable to Server-side Request Forgery (SSRF) when interceptor mode is set to proxy…

Fix: 1.0.0+
Fix from $1,950 2022-05-01
Solar Appscreener CRITICAL 9.8
CVE-2022-24449

Solar appScreener through 3.10.4, when a valid license is not present, allows XXE and SSRF attacks via a crafted XML document.

Fix: after 3.10.4
Fix from $2,300 2022-04-28
Mender CRITICAL 9.8
CVE-2022-29556

The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub integration provides several…

Mitigation only
Fix from $2,300 2022-04-28
Monsta Ftp CRITICAL 9.8
CVE-2022-27469

Monstaftp v2.10.3 was discovered to allow attackers to execute Server-Side Request Forgery (SSRF).

No fix yet
Fix from $2,300 2022-04-26
Gibbon CRITICAL 9.8
CVE-2022-27311

Gibbon v3.4.4 and below allows attackers to execute a Server-Side Request Forgery (SSRF) via a crafted URL.

Fix: 3.4.4+
Fix from $2,300 2022-04-25
Jizhicms CRITICAL 9.8
CVE-2022-27429

Jizhicms v1.9.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via /admin.php/Plugins/update.html.

No fix yet
Fix from $2,300 2022-04-25
Metasys System Configuration Tool CRITICAL 9.1
CVE-2021-36203

The affected product may allow an attacker to identify and forge requests to internal systems by way of a specially crafted request.

Fix: 14.2.2+
Fix from $2,300 2022-04-22
Shopware MEDIUM 5.5
CVE-2022-24871

Shopware is an open commerce platform based on Symfony Framework and Vue. In affected versions an attacker can abuse the Admin SDK functionality on t…

Fix: 6.4.10.1+
Fix from $1,600 2022-04-20
Databasir HIGH 7.7
CVE-2022-24862

Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has Server-Side Request Forgery vulnerability. Du…

No fix yet
Fix from $1,950 2022-04-20