Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Enterprise Search MEDIUM 6.8
CVE-2021-37940

An information disclosure via GET request server-side request forgery vulnerability was discovered with the Workplace Search Github Enterprise Server…

Fix: 7.16.0+
Fix from $1,600 2021-12-07
Squaredup CRITICAL 9.8
CVE-2021-40091

An SSRF issue was discovered in SquaredUp for SCOM 5.2.1.6654.

Fix: 5.3.1+
Fix from $2,300 2021-12-06
Snipe It HIGH 7.2
CVE-2021-4075

snipe-it is vulnerable to Server-Side Request Forgery (SSRF)

Patch available
Fix from $1,950 2021-12-06
Jamf HIGH 8.8
CVE-2021-40809

An issue was discovered in Jamf Pro before 10.32.0, aka PI-009921. An account can be granted incorrect privileges in response to authentication that …

Fix: 10.32.0+
Fix from $1,950 2021-12-01
Emc Streaming Data Platform MEDIUM 5.3
CVE-2021-36327

Dell EMC Streaming Data Platform versions before 1.3 contain a Server Side Request Forgery Vulnerability. A remote unauthenticated attacker may poten…

Fix: 1.3+
Fix from $1,600 2021-11-30
Manageengine Supportcenter Plus HIGH 7.5
CVE-2021-43296

Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to an SSRF attack in ActionExecutor.

Mitigation only
Fix from $1,950 2021-11-30
Vcenter Server CRITICAL 9.8
CVE-2021-22049

The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A maliciou…

Patch available
Fix from $2,300 2021-11-24
Redash HIGH 8.8
CVE-2021-43780

Redash is a package for data visualization and sharing. In versions 10.0 and priorm the implementation of URL-loading data sources like JSON, CSV, or…

Fix: 10.0.1+
Fix from $1,950 2021-11-24
Endpoint Security Tools HIGH 7.5
CVE-2021-3552

A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security Tools allows an attacker to pro…

Fix: 6.2.21.160 / 6.6.27.390+
Fix from $1,950 2021-11-24
Endpoint Security Tools HIGH 7.5
CVE-2021-3553

A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService of Bitdefender Endpoint Security Tools allows an attacker to use the Endpo…

Fix: 6.2.21.160 / 6.6.27.390+
Fix from $1,950 2021-11-24
Ssrf Agent HIGH 7.5
CVE-2021-23718

The package ssrf-agent before 1.0.5 are vulnerable to Server-side Request Forgery (SSRF) via the defaultIpChecker function. It fails to properly vali…

Fix: 1.0.5+
Fix from $1,950 2021-11-22
Concrete Cms MEDIUM 5.3
CVE-2021-22969

Concrete CMS (formerly concrete5) versions below 8.5.7 has a SSRF mitigation bypass using DNS Rebind attack giving an attacker the ability to fetch c…

Fix: 8.5.7+
Fix from $1,600 2021-11-19
Concrete Cms HIGH 7.5
CVE-2021-22970

Concrete CMS (formerly concrete5) versions 8.5.6 and below and version 9.0.0 allow local IP importing causing the system to be vulnerable toa. SSRF a…

Fix: after 8.5.6
Fix from $1,950 2021-11-19
Jamf CRITICAL 9.8
CVE-2021-39303

The server in Jamf Pro before 10.32.0 has an SSRF vulnerability, aka PI-006352. NOTE: Jamf Nation will also publish an article about this vulnerabili…

Fix: 10.32.0+
Fix from $2,300 2021-11-12
Pixx.io HIGH 8.8
CVE-2021-43562

An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The extension fails to restrict the image do…

Fix: 1.0.6+
Fix from $1,950 2021-11-10
Infosphere Information Server MEDIUM 5.4
CVE-2021-29738

IBM InfoSphere Data Flow Designer (IBM InfoSphere Information Server 11.7 ) is vulnerable to server-side request forgery (SSRF). This may allow an au…

Patch available
Fix from $1,600 2021-11-02
Engineering Lifecycle Optimization HIGH 8.8
CVE-2021-29844

IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requ…

Patch available
Fix from $1,950 2021-10-27
Manageengine Applications Manager MEDIUM 6.5
CVE-2021-35512

An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200.

No fix yet
Fix from $1,600 2021-10-21
Alfresco Content Services MEDIUM 5.3
CVE-2021-41792

An issue was discovered in Hyland org.alfresco:alfresco-content-services through 6.2.2.18 and org.alfresco:alfresco-transform-services through 1.3. A…

Fix: after 6.2.2.18
Fix from $1,600 2021-10-21
Itop HIGH 7.5
CVE-2021-32663

iTop is an open source web based IT Service Management tool. In affected versions an attacker can call the system setup without authentication. Given…

Fix: 2.6.5 / 2.7.5+
Fix from $1,950 2021-10-19
Zammad CRITICAL 9.1
CVE-2021-42091

An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration.

Fix: 4.1.1+
Fix from $2,300 2021-10-07
Concrete Cms CRITICAL 9.8
CVE-2021-22958

A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP address to bypass the limitatio…

Fix: 8.5.5+
Fix from $2,300 2021-10-07
Myucms HIGH 8.1
CVE-2020-21649

Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploited via the sql() method.

No fix yet
Fix from $1,950 2021-10-06
Myucms CRITICAL 9.1
CVE-2020-21653

Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploited via the sj() method.

No fix yet
Fix from $2,300 2021-10-06
GitLab MEDIUM 5.4
CVE-2021-39894

In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit…

Fix: 14.1.7 / 14.2.5+
Fix from $1,600 2021-10-05
GitLab HIGH 8.1
CVE-2021-39867

In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server…

Fix: 14.1.7 / 14.2.5+
Fix from $1,950 2021-10-05
Nagios Xi MEDIUM 6.5
CVE-2021-37223

Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php. Any authenticated user can cr…

Fix: after 5.8.4
Fix from $1,600 2021-10-05
P40 Firmware HIGH 7.5
CVE-2021-37104

There is a server-side request forgery vulnerability in HUAWEI P40 versions 10.1.0.118(C00E116R3P3). This vulnerability is due to insufficient valida…

Mitigation only
Fix from $1,950 2021-09-28
Concrete Cms MEDIUM 6.4
CVE-2021-40109

A SSRF issue was discovered in Concrete CMS through 8.5.5. Users can access forbidden files on their local network. A user with permissions to upload…

Fix: 8.5.6+
Fix from $1,600 2021-09-27
Snypr MEDIUM 6.5
CVE-2021-41385

The third party intelligence connector in Securonix SNYPR 6.3.1 Build 184295_0302 allows an authenticated user to obtain access to server configurati…

Mitigation only
Fix from $1,600 2021-09-27