Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Smokescreen MEDIUM 5.3
CVE-2022-24825

Smokescreen is a simple HTTP proxy that fogs over naughty URLs. The primary use case for Smokescreen is to prevent server-side request forgery (SSRF)…

Fix: 0.0.3+
Fix from $1,600 2022-04-19
Fedora HIGH 7.5
CVE-2022-29153EPSS 9%

HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows re…

Fix: 1.9.17 / 1.10.10+
Fix from $1,950 2022-04-19
Exmage HIGH 7.2
CVE-2022-1037

The EXMAGE WordPress plugin before 1.0.7 does to ensure that images added via URLs are external images, which could lead to a blind SSRF issue by usi…

Fix: 1.0.7+
Fix from $1,950 2022-04-18
Chamilo Lms HIGH 8.8
CVE-2022-27426

A Server-Side Request Forgery (SSRF) in Chamilo LMS v1.11.13 allows attackers to enumerate the internal network and execute arbitrary system commands…

Fix: after 1.11.16
Fix from $1,950 2022-04-15
Debian Linux CRITICAL 9.1
CVE-2022-26499EPSS 8%

An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces s…

Fix: 18.11.2+
Fix from $2,300 2022-04-15
Planning Analytics HIGH 7.3
CVE-2022-22339

IBM Planning Analytics 2.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized request…

Patch available
Fix from $1,950 2022-04-08
Metasys Application And Data Server HIGH 8.8
CVE-2021-36202

Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to inject malicious code into the …

Fix: 10.1.5 / 11.0.2+
Fix from $1,950 2022-04-07
Icheck Connect Bp Monitor Bp Testing 118 Firmware MEDIUM 6.5
CVE-2020-27375

Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Transmitting Write Requests and Chars.

No fix yet
Fix from $1,600 2022-04-07
Live Helper Chat HIGH 8.1
CVE-2022-1213

SSRF filter bypass port 80, 433 in GitHub repository livehelperchat/livehelperchat prior to 3.67v. An attacker could make the application perform arb…

Fix: 3.97+
Fix from $1,950 2022-04-05
GitLab MEDIUM 5.3
CVE-2022-1188

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions starting from 14.8 before 14.8.5, …

Fix: 14.7.7 / 14.8.5+
Fix from $1,600 2022-04-04
Calibre Web CRITICAL 9.1
CVE-2022-0990

Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.

Fix: 0.6.18+
Fix from $2,300 2022-04-04
Calibre Web CRITICAL 9.9
CVE-2022-0939

Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.

Fix: 0.6.18+
Fix from $2,300 2022-04-04
GitLab HIGH 7.6
CVE-2022-0425

A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Se…

Fix: after 14.7.1
Fix from $1,950 2022-04-01
Live Helper Chat HIGH 8.1
CVE-2022-1191

SSRF on index.php/cobrowse/proxycss/ in GitHub repository livehelperchat/livehelperchat prior to 3.96.

Fix: 3.96+
Fix from $1,950 2022-03-31
Mashzone Nextgen HIGH 7.2
CVE-2021-33581

MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP services, by abusing the feature to…

Fix: after 10.7
Fix from $1,950 2022-03-30
C1 Cms HIGH 7.6
CVE-2022-24789

C1 CMS is an open-source, .NET based Content Management System (CMS). Versions prior to 6.12 allow an authenticated user to exploit Server Side Reque…

Fix: 6.12+
Fix from $1,950 2022-03-28
GitLab HIGH 8.1
CVE-2022-0136

A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnerable to a blind SSRF attack th…

Fix: after 14.7.1
Fix from $1,950 2022-03-28
GitLab CRITICAL 9.1
CVE-2022-0249

A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared address spac…

Fix: after 14.7.1
Fix from $2,300 2022-03-28
Sentinel HIGH 7.5
CVE-2021-44139EPSS 6%

Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF).

No fix yet
Fix from $1,950 2022-03-23
Formcraft3 CRITICAL 9.1
CVE-2022-0591EPSS 20%

The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitabl…

Fix: 3.8.28+
Fix from $2,300 2022-03-21
Misp HIGH 8.8
CVE-2022-27245

An issue was discovered in MISP before 2.4.156. app/Model/Server.php does not restrict generateServerSettings to the CLI. This could lead to SSRF.

Fix: 2.4.156+
Fix from $1,950 2022-03-18
Jive HIGH 7.5
CVE-2021-45968EPSS 10%

An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Phone System before 7.20.x (and …

Fix: after 7.19
Fix from $1,950 2022-03-18
Ligeo Basics HIGH 7.5
CVE-2021-46107EPSS 7%

Ligeo Archives Ligeo Basics as of 02_01-2022 is vulnerable to Server Side Request Forgery (SSRF) which allows an attacker to read any documents via t…

No fix yet
Fix from $1,950 2022-03-17
Fuxa HIGH 7.5
CVE-2021-45851

A Server-Side Request Forgery (SSRF) attack in FUXA 1.1.3 can be carried out leading to the obtaining of sensitive information from the server's inte…

No fix yet
Fix from $1,950 2022-03-16
Spectrum Copy Data Management MEDIUM 6.5
CVE-2021-39051

IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to server-side request forgery, caused by improper input of application serv…

Fix: 2.2.15.0+
Fix from $1,600 2022-03-14
Gogs MEDIUM 5.3
CVE-2022-0870

Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.5.

Fix: 0.12.5+
Fix from $1,600 2022-03-11
Alltube MEDIUM 6.1
CVE-2022-24739

alltube is an html front end for youtube-dl. On releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redire…

Fix: 3.0.3+
Fix from $1,600 2022-03-08
Calibre Web CRITICAL 9.8
CVE-2022-0766

Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.

Fix: 0.6.17+
Fix from $2,300 2022-03-07
Calibre Web CRITICAL 9.9
CVE-2022-0767

Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.

Fix: 0.6.17+
Fix from $2,300 2022-03-07
Uppy HIGH 7.5
CVE-2022-0528

Server-Side Request Forgery (SSRF) in GitHub repository transloadit/uppy prior to 3.3.1.

Fix: 3.3.1+
Fix from $1,950 2022-03-03