Vulnerability index

Browse CVEs

2,859 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Group Office MEDIUM 5.3
CVE-2021-28060

A Server-Side Request Forgery (SSRF) vulnerability in Group Office 6.4.196 allows a remote attacker to forge GET requests to arbitrary URLs via the u…

No fix yet
Fix from $1,600 2021-04-14
Solr CRITICAL 9.8
CVE-2021-27905EPSS 93%

The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter …

Fix: 8.8.2+
Fix from $2,300 2021-04-13
Lifetime Management Console HIGH 8.6
CVE-2021-29357

The ECT Provider component in OutSystems Platform Server 10 before 10.0.1104.0 and 11 before 11.9.0 (and LifeTime management console before 11.7.0) a…

Fix: 10.0.1104.0 / 11.7.0+
Fix from $1,950 2021-04-12
Websphere Application Server MEDIUM 6.5
CVE-2021-20480

IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a rem…

Fix: after 8.5.5.19
Fix from $1,600 2021-04-08
Wcms HIGH 8.3
CVE-2020-24139

Server-side request forgery in Wcms 0.3.2 lets an attacker send crafted requests from the back-end server of a vulnerable web application via the pat…

No fix yet
Fix from $1,950 2021-04-07
Wcms HIGH 8.3
CVE-2020-24140

Server-side request forgery in Wcms 0.3.2 let an attacker send crafted requests from the back-end server of a vulnerable web application via the page…

No fix yet
Fix from $1,950 2021-04-07
Likebtn Like Button HIGH 7.5
CVE-2021-24150

The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request For…

Fix: 2.6.32+
Fix from $1,950 2021-04-05
Magpierss MEDIUM 5.3
CVE-2021-28941

Because of no validation on a curl command in MagpieRSS 0.72 in the /extlib/Snoopy.class.inc file, when you send a request to the /scripts/magpie_deb…

No fix yet
Fix from $1,600 2021-04-02
Cxf HIGH 7.5
CVE-2021-22696EPSS 7%

CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization F…

Fix: 3.3.10 / 3.4.3+
Fix from $1,950 2021-04-02
Flycms HIGH 7.5
CVE-2020-19613

Server Side Request Forgery (SSRF) vulnerability in saveUrlAs function in ImagesService.java in sunkaifei FlyCMS version 20190503.

No fix yet
Fix from $1,950 2021-04-01
Cloud Foundation HIGH 7.5
CVE-2021-21975 KEVEPSS 78%

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the v…

Mitigation only
Fix from $1,950 2021-03-31
Big Ip Access Policy Manager CRITICAL 9.8
CVE-2021-22986 KEVEPSS 100%

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-I…

Fix: 12.1.5.3 / 13.1.3.6+
Fix from $2,300 2021-03-31
Mule CRITICAL 9.8
CVE-2021-1627

MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub…

Fix: after 4.2.2
Fix from $2,300 2021-03-26
Connect CRITICAL 9.1
CVE-2021-26715

The OpenID Connect server implementation for MITREid Connect through 1.3.3 contains a Server Side Request Forgery (SSRF) vulnerability. The vulnerabi…

Fix: after 1.3.3
Fix from $2,300 2021-03-25
Dsos MEDIUM 6.5
CVE-2020-15809

spxmanage on certain SpinetiX devices allows requests that access unintended resources because of SSRF and Path Traversal. This affects HMP350, HMP30…

Fix: after 4.5.2-1.0.36229
Fix from $1,600 2021-03-24
GitLab MEDIUM 5.0
CVE-2021-22178

An issue has been discovered in GitLab affecting all versions starting from 13.2. Gitlab was vulnerable to SRRF attack through the Prometheus integra…

Fix: 13.6.7 / 13.7.7+
Fix from $1,600 2021-03-24
GitLab MEDIUM 5.4
CVE-2021-22179

A vulnerability was discovered in GitLab versions before 12.2. GitLab was vulnerable to a SSRF attack through the Outbound Requests feature.

Fix: 13.6.6 / 13.7.6+
Fix from $1,600 2021-03-24
Activemq HIGH 8.6
CVE-2021-21349EPSS 47%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $1,950 2021-03-23
Activemq CRITICAL 9.1
CVE-2021-21342EPSS 50%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed …

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Planning Analytics MEDIUM 6.1
CVE-2020-4882

IBM Planning Analytics 2.0 could be vulnerable to a Server-Side Request Forgery (SSRF) attack by constucting URLs from user-controlled data . This co…

Mitigation only
Fix from $1,600 2021-03-22
Datapower Gateway MEDIUM 6.7
CVE-2020-5014

IBM DataPower Gateway V10 and V2018 could allow a local attacker with administrative privileges to execute arbitrary code on the system using a serve…

Fix: after 2018.4.1.14
Fix from $1,600 2021-03-08
Exchange Server CRITICAL 9.1
CVE-2021-26855 KEVEPSS 100%

Microsoft Exchange Server Remote Code Execution Vulnerability

Patch available
Fix from $2,300 2021-03-03
Mbconnect24 MEDIUM 5.3
CVE-2020-12529

An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2 There is a SSRF in the LDAP access c…

Fix: after 2.6.2
Fix from $1,600 2021-03-02
Gotenberg MEDIUM 5.3
CVE-2021-23345

All versions of package github.com/thecodingmachine/gotenberg are vulnerable to Server-side Request Forgery (SSRF) via the /convert/html endpoint whe…

No fix yet
Fix from $1,600 2021-02-26
Masterlab CRITICAL 9.8
CVE-2020-23534

A server-side request forgery (SSRF) vulnerability in Upgrade.php of gopeak masterlab 2.1.5, via the 'source' parameter.

No fix yet
Fix from $2,300 2021-02-25
Appspace CRITICAL 9.8
CVE-2021-27670EPSS 61%

Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.

No fix yet
Fix from $2,300 2021-02-25
Batik HIGH 8.2
CVE-2020-11987EPSS 14%

Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-craf…

Fix: after 1.13
Fix from $1,950 2021-02-24
Xmlgraphics Commons HIGH 8.2
CVE-2020-11988EPSS 7%

Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By usi…

Fix: after 2.4
Fix from $1,950 2021-02-24
Cloud Foundation MEDIUM 5.3
CVE-2021-21973 KEVEPSS 88%

The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin…

Fix: 3.10.1.2 / 4.2+
Fix from $1,600 2021-02-24
Atlassian Gadgets MEDIUM 5.0
CVE-2020-36232

The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, f…

Fix: 4.2.37 / 4.3.2.4+
Fix from $1,600 2021-02-22