Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Alltube CRITICAL 9.1
CVE-2022-0768

Server-Side Request Forgery (SSRF) in GitHub repository rudloff/alltube prior to 3.0.2.

Fix: 3.0.2+
Fix from $2,300 2022-02-28
Hub CRITICAL 9.1
CVE-2022-25260

JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF).

Fix: 2021.1.14276+
Fix from $2,300 2022-02-25
Teamcity MEDIUM 6.5
CVE-2022-24333

In JetBrains TeamCity before 2021.2, blind SSRF via an XML-RPC call was possible.

Fix: 2021.2+
Fix from $1,600 2022-02-25
Kitodo.presentation HIGH 7.5
CVE-2022-24980

An issue was discovered in the Kitodo.Presentation (aka dif) extension before 2.3.2, 3.x before 3.2.3, and 3.3.x before 3.3.4 for TYPO3. A missing ac…

Fix: 2.3.2 / 3.2.3+
Fix from $1,950 2022-02-19
Mimosa Management Platform CRITICAL 9.8
CVE-2022-21215

This vulnerability could allow an attacker to force the server to create and execute a web request granting access to backend APIs that are only acce…

Fix: 1.0.3 / 2.5.4.1+
Fix from $2,300 2022-02-18
Vscode Xml CRITICAL 9.1
CVE-2022-0671

A flaw was found in vscode-xml in versions prior to 0.19.0. Schema download could lead to blind SSRF or DoS via a large file.

Fix: 0.19.0+
Fix from $2,300 2022-02-18
Enterprise Linux CRITICAL 9.8
CVE-2021-20325

Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regress…

Mitigation only
Fix from $2,300 2022-02-18
Bookwyrm HIGH 8.8
CVE-2022-23644

BookWyrm is a decentralized social network for tracking reading habits and reviewing books. The functionality to load a cover via url is vulnerable t…

Fix: 0.3.0+
Fix from $1,950 2022-02-16
Novel Plus CRITICAL 9.8
CVE-2022-24568

Novel-plus v3.6.0 was discovered to be vulnerable to Server-Side Request Forgery (SSRF) via user-supplied crafted input.

No fix yet
Fix from $2,300 2022-02-10
Gitea HIGH 7.5
CVE-2021-45325

Server Side Request Forgery (SSRF) vulneraility exists in Gitea before 1.7.0 using the OpenID URL.

Fix: 1.7.0+
Fix from $1,950 2022-02-08
Peertube MEDIUM 5.3
CVE-2022-0508

Server-Side Request Forgery (SSRF) in GitHub repository chocobozzz/peertube prior to f33e515991a32885622b217bf2ed1d1b0d9d6832

Fix: 2021-12-13+
Fix from $1,600 2022-02-08
Traffic Control HIGH 7.5
CVE-2022-23206

In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted…

Fix: 5.1.6 / 6.1.0+
Fix from $1,950 2022-02-06
Oidc Op HIGH 8.2
CVE-2022-24129EPSS 6%

The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insufficient restriction of the req…

Fix: 3.0.4+
Fix from $1,950 2022-02-04
Web Stack CRITICAL 9.8
CVE-2021-42637

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server Side Request Forgery (SSRF) v…

Fix: 19.1.1.13+
Fix from $2,300 2022-02-02
Calibre Web CRITICAL 9.8
CVE-2022-0339

Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16.

Fix: 0.6.16+
Fix from $2,300 2022-01-30
My Cloud Os HIGH 8.8
CVE-2022-22993

A limited SSRF vulnerability was discovered on Western Digital My Cloud devices that could allow an attacker to impersonate a server and reach any pa…

Fix: 5.19.117+
Fix from $1,950 2022-01-28
Evlink City Evc1s22p4 Firmware HIGH 8.6
CVE-2021-22821

A CWE-918 Server-Side Request Forgery (SSRF) vulnerability exists that could cause the station web server to forward requests to unintended network t…

Fix: 3.4.0.2+
Fix from $1,950 2022-01-28
Jupyter Server Proxy HIGH 7.1
CVE-2022-21697

Jupyter Server Proxy is a Jupyter notebook server extension to proxy web services. Versions of Jupyter Server Proxy prior to 3.2.1 are vulnerable to …

Fix: 3.2.1+
Fix from $1,950 2022-01-25
Cors Proxy HIGH 7.5
CVE-2021-23664

The package @isomorphic-git/cors-proxy before 2.7.1 are vulnerable to Server-side Request Forgery (SSRF) due to missing sanitization and validation o…

Fix: 2.7.1+
Fix from $1,950 2022-01-21
Html2pdf HIGH 8.8
CVE-2021-45394

An issue was discovered in Spipu HTML2PDF before 5.2.4. Attackers can trigger deserialization of arbitrary data via the injection of a malicious <lin…

Fix: 5.2.4+
Fix from $1,950 2022-01-18
Peertube HIGH 7.5
CVE-2022-0132

peertube is vulnerable to Server-Side Request Forgery (SSRF)

Patch available
Fix from $1,950 2022-01-10
Kylin HIGH 7.5
CVE-2021-27738

All request mappings in `StreamingCoordinatorController.java` handling `/kylin/api/streaming_coordinator/*` REST API endpoints did not include any se…

Fix: 3.1.2+
Fix from $1,950 2022-01-06
Uppy CRITICAL 9.8
CVE-2022-0086

uppy is vulnerable to Server-Side Request Forgery (SSRF)

Fix: 2.3.3+
Fix from $2,300 2022-01-04
Gocd CRITICAL 9.8
CVE-2021-44659

Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve a Server…

No fix yet
Fix from $2,300 2021-12-22
Identity Manager HIGH 7.5
CVE-2021-22056

VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor…

Fix: after 8.6
Fix from $1,950 2021-12-20
Workspace One Uem Console HIGH 7.5
CVE-2021-22054 KEVEPSS 97%

VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 con…

Fix: 20.0.8.36 / 20.11.0.40+
Fix from $1,950 2021-12-17
Gravityzone HIGH 7.5
CVE-2021-3959

A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security Tools allows an attacker to pro…

Fix: 3.3.8.272+
Fix from $1,950 2021-12-16
Meetings MEDIUM 6.1
CVE-2021-34425

The Zoom Client for Meetings before version 5.7.3 (for Android, iOS, Linux, macOS, and Windows) contain a server side request forgery vulnerability i…

Fix: 5.7.3+
Fix from $1,600 2021-12-14
Spectrum Protect Plus HIGH 8.1
CVE-2021-39057

IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to …

Fix: 10.1.9+
Fix from $1,950 2021-12-13
GitLab HIGH 7.5
CVE-2021-39935 KEVEPSS 36%

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, …

Fix: 14.3.6 / 14.4.4+
Fix from $1,950 2021-12-13