Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Open Xchange Appsuite MEDIUM 5.4
CVE-2021-26699

OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled by the imageconverter componen…

No fix yet
Fix from $1,600 2021-07-22
Evlink City Evc1s22p4 Firmware HIGH 8.1
CVE-2021-22726

A CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Pa…

Mitigation only
Fix from $1,950 2021-07-21
Investigate HIGH 8.1
CVE-2021-31216

Siren Investigate before 11.1.1 contains a server side request forgery (SSRF) defect in the built-in image proxy route (which is enabled by default).…

Fix: 11.1.1+
Fix from $1,950 2021-07-19
Secure External Authentication Server MEDIUM 5.4
CVE-2021-29749

IBM Secure External Authentication Server 6.0.2 and IBM Secure Proxy 6.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an aut…

Patch available
Fix from $1,600 2021-07-15
Exchange Server CRITICAL 9.1
CVE-2021-34473 KEVEPSS 100%

Microsoft Exchange Server Remote Code Execution Vulnerability

Patch available
Fix from $2,300 2021-07-14
Http Commander MEDIUM 6.5
CVE-2021-33213

An SSRF vulnerability in the "Upload from URL" feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated users to retrieve HTTP and FTP…

No fix yet
Fix from $1,600 2021-07-14
Halo HIGH 7.5
CVE-2020-23079

SSRF vulnerability in Halo <=1.3.2 exists in the SMTP configuration, which can detect the server intranet.

Fix: after 1.3.2
Fix from $1,950 2021-07-12
Arcgis Server CRITICAL 9.1
CVE-2021-29102

A Server-Side Request Forgery (SSRF) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote, unauthenticated attacker to …

Fix: 10.9.0+
Fix from $2,300 2021-07-11
Mipcms HIGH 7.5
CVE-2020-20582

A server side request forgery (SSRF) vulnerability in /ApiAdminDomainSettings.php of MipCMS 5.0.1 allows attackers to access sensitive information.

No fix yet
Fix from $1,950 2021-07-08
Wp Downloadmanager MEDIUM 5.3
CVE-2020-24141

Server-side request forgery in the WP-DownloadManager plugin 1.68.4 for WordPress lets an attacker send crafted requests from the back-end server of …

Mitigation only
Fix from $1,600 2021-07-07
Video Downloader For Tiktok CRITICAL 9.8
CVE-2020-24142

Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker send crafted request…

Mitigation only
Fix from $2,300 2021-07-07
Wp Smart Import CRITICAL 9.1
CVE-2020-24147

Server-side request forgery (SSR) vulnerability in the WP Smart Import (wp-smart-import) plugin 1.0.0 for WordPress via the file field.

Mitigation only
Fix from $2,300 2021-07-07
Import Xml And Rss Feeds CRITICAL 9.1
CVE-2020-24148EPSS 15%

Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the data parameter in a moove_rea…

Mitigation only
Fix from $2,300 2021-07-07
Podcast Importer Secondline HIGH 7.5
CVE-2020-24149

Server-side request forgery (SSRF) in the Podcast Importer SecondLine (podcast-importer-secondline) plugin 1.1.4 for WordPress via the podcast_feed p…

No fix yet
Fix from $1,950 2021-07-07
Collaboration CRITICAL 9.8
CVE-2021-35209

An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.x before 9.0.0 Patc…

Fix: 8.8.15+
Fix from $2,300 2021-07-02
Emissary CRITICAL 9.9
CVE-2021-32639

Emissary is a P2P-based, data-driven workflow engine. Emissary version 6.4.0 is vulnerable to Server-Side Request Forgery (SSRF). In particular, the …

Fix: after 6.4.0
Fix from $2,300 2021-07-02
Manageengine Servicedesk Plus Msp CRITICAL 9.8
CVE-2021-31531

Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF).

Fix: 10.5+
Fix from $2,300 2021-06-29
Media Server MEDIUM 5.3
CVE-2021-34808

Server-Side Request Forgery (SSRF) vulnerability in cgi component in Synology Media Server before 1.8.3-2881 allows remote attackers to access intran…

Fix: 1.8.3-2881+
Fix from $1,600 2021-06-18
Security Identity Manager MEDIUM 6.5
CVE-2021-20483

IBM Security Identity Manager 6.0.2 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticat…

Patch available
Fix from $1,600 2021-06-16
Elfinder CRITICAL 9.8
CVE-2021-32682EPSS 70%

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnera…

Fix: 2.1.59+
Fix from $2,300 2021-06-14
GitLab CRITICAL 9.8
CVE-2021-22175 KEVEPSS 53%

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting…

Fix: 13.6.7 / 13.7.7+
Fix from $2,300 2021-06-11
Sannav CRITICAL 9.8
CVE-2020-15377

Webtools in Brocade SANnav before version 2.1.1 allows unauthenticated users to make requests to arbitrary hosts due to a misconfiguration; this is c…

Fix: 2.1.1+
Fix from $2,300 2021-06-09
Sharepoint Foundation HIGH 7.6
CVE-2021-31950

Microsoft SharePoint Server Spoofing Vulnerability

Patch available
Fix from $1,950 2021-06-08
Django HIGH 7.5
CVE-2021-33571EPSS 5%

In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit…

Fix: 2.2.24 / 3.1.12+
Fix from $1,950 2021-06-08
GitLab HIGH 8.6
CVE-2021-22214EPSS 28%

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions st…

Fix: 13.10.5 / 13.11.5+
Fix from $1,950 2021-06-08
Yzmcms HIGH 7.5
CVE-2020-35970

An issue was discovered in YzmCMS 5.8. There is a SSRF vulnerability in the background collection management that allows arbitrary file read.

No fix yet
Fix from $1,950 2021-06-03
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2021-20343

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se…

Patch available
Fix from $1,600 2021-06-02
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2021-20345

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se…

Patch available
Fix from $1,600 2021-06-02
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2021-20346

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se…

Patch available
Fix from $1,600 2021-06-02
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2021-20347

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se…

Patch available
Fix from $1,600 2021-06-02