Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Gradle HIGH 7.5
CVE-2021-41586

In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially reset the system user password.

Fix: 2021.1.3+
Fix from $1,950 2021-09-24
Gradle HIGH 7.5
CVE-2021-41587

In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially discover credentials for other resources.

Fix: 2021.1.3+
Fix from $1,950 2021-09-24
Discourse MEDIUM 5.3
CVE-2020-24327

Server Side Request Forgery (SSRF) vulnerability exists in Discourse 2.3.2 and 2.6 via the email function. When writing an email in an editor, you ca…

Patch available
Fix from $1,600 2021-09-23
Cloud Foundation MEDIUM 6.5
CVE-2021-21993

The vCenter Server contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in vCenter Server Content Library.…

Fix: 5.0+
Fix from $1,600 2021-09-23
Telefication MEDIUM 5.3
CVE-2021-39339

The Telefication WordPress plugin is vulnerable to Open Proxy and Server-Side Request Forgery via the ~/bypass.php file due to a user-supplied URL re…

Fix: after 1.8.0
Fix from $1,600 2021-09-22
Manageengine Admanager Plus HIGH 7.5
CVE-2021-37419

Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to SSRF.

Fix: 6.1+
Fix from $1,950 2021-09-21
Enterprise Linux CRITICAL 9.0
CVE-2021-40438 KEVEPSS 100%

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP …

Patch available
Fix from $2,300 2021-09-16
Netweaver Development Infrastructure CRITICAL 9.9
CVE-2021-33690EPSS 69%

Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions -…

Patch available
Fix from $2,300 2021-09-15
Netweaver Portal HIGH 8.1
CVE-2021-33705

The SAP NetWeaver Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, component Iviews Editor contains a Server-Side Request Forgery (SSRF) …

Patch available
Fix from $1,950 2021-09-15
Ureport MEDIUM 5.3
CVE-2020-21122

UReport v2.2.9 contains a Server-Side Request Forgery (SSRF) in the designer page which allows attackers to detect intranet device ports.

No fix yet
Fix from $1,600 2021-09-15
Big Ip Advanced Web Application Firewall HIGH 8.8
CVE-2021-23029

On version 16.0.x before 16.0.1.2, insufficient permission checks may allow authenticated users with guest privileges to perform Server-Side Request …

Fix: 16.0.1.2+
Fix from $1,950 2021-09-14
Eibport Firmware HIGH 7.5
CVE-2021-28910

BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 contains basic SSRF vulnerability. It allow unauthenticated attackers to request to any internal …

Fix: 3.9.1+
Fix from $1,950 2021-09-09
Eyoucms CRITICAL 9.8
CVE-2021-39497

eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function.

No fix yet
Fix from $2,300 2021-09-07
Misskey MEDIUM 6.5
CVE-2021-39195

Misskey is an open source, decentralized microblogging platform. In affected versions a Server-Side Request Forgery vulnerability exists in "Upload f…

Fix: 12.90.0+
Fix from $1,600 2021-09-07
Bookstack MEDIUM 6.5
CVE-2021-3758

bookstack is vulnerable to Server-Side Request Forgery (SSRF)

Fix: 21.08+
Fix from $1,600 2021-09-02
Yzmcms HIGH 7.5
CVE-2020-20341

YzmCMS v5.5 contains a server-side request forgery (SSRF) in the grab_image() function.

No fix yet
Fix from $1,950 2021-09-01
Adobe Commerce MEDIUM 6.6
CVE-2021-36043

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a blind SSRF vulnerability in the bundl…

Fix: after 2.4.2
Fix from $1,600 2021-09-01
Cloud Foundation HIGH 7.5
CVE-2021-22026

The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor wit…

Fix: 8.5.0+
Fix from $1,950 2021-08-30
Cloud Foundation HIGH 7.5
CVE-2021-22027

The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor wit…

Fix: 8.5.0+
Fix from $1,950 2021-08-30
Gotenberg HIGH 7.5
CVE-2020-14160

An SSRF vulnerability in Gotenberg through 6.2.1 exists in the remote URL to PDF conversion, which results in a remote attacker being able to read lo…

Fix: after 6.2.1
Fix from $1,950 2021-08-26
Experience Manager HIGH 8.8
CVE-2021-28627

Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by a Server-side Request Forgery. An authenticat…

Fix: after 6.5.8.0
Fix from $1,950 2021-08-24
Fedora HIGH 8.5
CVE-2021-39152EPSS 11%

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to reques…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Fedora HIGH 8.5
CVE-2021-39150

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to reques…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Rconfig MEDIUM 6.5
CVE-2020-25353

A server-side request forgery (SSRF) vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability allowed remote authenticated attacke…

No fix yet
Fix from $1,600 2021-08-20
Baserow MEDIUM 6.5
CVE-2021-22255

SSRF in URL file upload in Baserow <1.1.0 allows remote authenticated users to retrieve files from the internal server network exposed over HTTP by i…

Fix: 1.1.0+
Fix from $1,600 2021-08-20
Shopware HIGH 8.8
CVE-2021-37711

Versions prior to 6.4.3.1 contain an authenticated server-side request forgery vulnerability in file upload via URL. Version 6.4.3.1 contains a patch…

Fix: 6.4.3.1+
Fix from $1,950 2021-08-16
Nagios Xi Docker Wizard CRITICAL 9.8
CVE-2021-37353

Nagios XI Docker Wizard before version 1.1.3 is vulnerable to SSRF due to improper sanitation in table_population.php.

Fix: 1.1.3+
Fix from $2,300 2021-08-13
Fortianalyzer MEDIUM 6.5
CVE-2021-32603

A server-side request forgery (SSRF) (CWE-918) vulnerability in FortiManager and FortiAnalyser GUI 7.0.0, 6.4.5 and below, 6.2.7 and below, 6.0.11 an…

Fix: 6.2.8 / 6.4.6+
Fix from $1,600 2021-08-05
Kentharadio CRITICAL 9.8
CVE-2021-24472EPSS 57%

The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users,…

Fix: 2.0.2 / 3.9.9.2+
Fix from $2,300 2021-08-02
Engineering Lifecycle Optimization Engineering Insights MEDIUM 6.3
CVE-2020-4974

IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requ…

No fix yet
Fix from $1,600 2021-07-28