Vulnerability index

Browse CVEs

2,859 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
GitLab CRITICAL 9.8
CVE-2021-22175 KEVEPSS 53%

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting…

Fix: 13.6.7 / 13.7.7+
Fix from $2,300 2021-06-11
Sannav CRITICAL 9.8
CVE-2020-15377

Webtools in Brocade SANnav before version 2.1.1 allows unauthenticated users to make requests to arbitrary hosts due to a misconfiguration; this is c…

Fix: 2.1.1+
Fix from $2,300 2021-06-09
Sharepoint Foundation HIGH 7.6
CVE-2021-31950

Microsoft SharePoint Server Spoofing Vulnerability

Patch available
Fix from $1,950 2021-06-08
Django HIGH 7.5
CVE-2021-33571EPSS 5%

In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit…

Fix: 2.2.24 / 3.1.12+
Fix from $1,950 2021-06-08
GitLab HIGH 8.6
CVE-2021-22214EPSS 28%

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions st…

Fix: 13.10.5 / 13.11.5+
Fix from $1,950 2021-06-08
Yzmcms HIGH 7.5
CVE-2020-35970

An issue was discovered in YzmCMS 5.8. There is a SSRF vulnerability in the background collection management that allows arbitrary file read.

No fix yet
Fix from $1,950 2021-06-03
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2021-20343

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se…

Patch available
Fix from $1,600 2021-06-02
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2021-20345

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se…

Patch available
Fix from $1,600 2021-06-02
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2021-20346

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se…

Patch available
Fix from $1,600 2021-06-02
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2021-20347

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se…

Patch available
Fix from $1,600 2021-06-02
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2021-20348

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se…

Patch available
Fix from $1,600 2021-06-02
Video Station CRITICAL 9.1
CVE-2021-33181

Server-Side Request Forgery (SSRF) vulnerability in webapi component in Synology Video Station before 2.4.10-1632 allows remote authenticated users t…

Fix: 2.4.10-1632+
Fix from $2,300 2021-06-01
Download Station HIGH 7.7
CVE-2021-33184

Server-Side request forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.15-3563 allows remote authentic…

Fix: 3.8.15-3563+
Fix from $1,950 2021-06-01
Dubbo MEDIUM 6.1
CVE-2021-25640

In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or S…

Fix: 2.6.9 / 2.7.9+
Fix from $1,600 2021-06-01
Ansible Tower MEDIUM 5.5
CVE-2020-14327

A Server-side request forgery (SSRF) flaw was found in Ansible Tower in versions before 3.6.5 and before 3.7.2. Functionality on the Tower server is …

Fix: 3.6.5 / 3.7.2+
Fix from $1,600 2021-05-27
Vcenter Server CRITICAL 9.8
CVE-2021-21985 KEVEPSS 100%

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in whi…

Fix: 3.10.2.1 / 4.2.1+
Fix from $2,300 2021-05-26
Feehi Cms CRITICAL 9.1
CVE-2021-30108

Feehi CMS 2.1.1 is affected by a Server-side request forgery (SSRF) vulnerability. When the user modifies the HTTP Referer header to any url, the ser…

No fix yet
Fix from $2,300 2021-05-24
Plone HIGH 7.5
CVE-2021-33511

Plone though 5.2.4 allows SSRF via the lxml parser. This affects Diazo themes, Dexterity TTW schemas, and modeleditors in plone.app.theming, plone.ap…

Fix: after 5.2.4
Fix from $1,950 2021-05-21
Remedy Mid Tier CRITICAL 9.8
CVE-2017-17674

BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be…

Mitigation only
Fix from $2,300 2021-05-19
Jazz Reporting Service MEDIUM 5.4
CVE-2021-20535

IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attack…

Mitigation only
Fix from $1,600 2021-05-13
Teamcity HIGH 7.5
CVE-2021-31910

In JetBrains TeamCity before 2020.2.3, information disclosure via SSRF was possible.

Fix: 2020.2.3+
Fix from $1,950 2021-05-11
Open Distro HIGH 7.1
CVE-2021-31828

An SSRF issue in Open Distro for Elasticsearch (ODFE) before 1.13.1.0 allows an existing privileged user to enumerate listening services or interact …

Fix: 1.13.1.0+
Fix from $1,950 2021-05-06
Jellyfin MEDIUM 5.8
CVE-2021-29490EPSS 70%

Jellyfin is a free software media system that provides media from a dedicated server to end-user devices via multiple apps. Verions prior to 10.7.3 v…

Fix: 10.7.3+
Fix from $1,600 2021-05-06
Open Xchange Appsuite MEDIUM 6.5
CVE-2020-28943

OX App Suite 7.10.4 and earlier allows SSRF via a snippet.

Fix: after 7.10.4
Fix from $1,600 2021-04-30
Smartliving 505 Firmware HIGH 7.5
CVE-2020-22002

An Unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Inim Electronics Smartliving SmartLAN/G/SI <=6.x within the GetImage fu…

No fix yet
Fix from $1,950 2021-04-29
Clearpass CRITICAL 9.8
CVE-2021-29145

A remote server side request forgery (SSRF) remote code execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to …

Fix: 6.7.14 / 6.8.6+
Fix from $2,300 2021-04-29
Yoast Seo MEDIUM 6.4
CVE-2021-31779

The yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows SSRF via a backend user account.

Fix: 7.2.1+
Fix from $1,600 2021-04-28
Hedgedoc CRITICAL 10.0
CVE-2021-29475

HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker is able to receive arbitrary files from the file sys…

Fix: 1.5.0+
Fix from $2,300 2021-04-26
Wondercms CRITICAL 9.8
CVE-2020-35313EPSS 45%

A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attac…

No fix yet
Fix from $2,300 2021-04-20
Sydent MEDIUM 6.5
CVE-2021-29431

Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due to lack of parameter validatio…

Fix: 2.3.0+
Fix from $1,600 2021-04-15