Vulnerability index

Browse CVEs

2,859 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Manageengine Adselfservice Plus MEDIUM 6.1
CVE-2021-27214

A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote …

No fix yet
Fix from $1,600 2021-02-19
Webdesktop MEDIUM 6.5
CVE-2021-3204

SSRF in the document conversion component of Webware Webdesktop 5.1.15 allows an attacker to read all files from the server.

No fix yet
Fix from $1,600 2021-02-19
Owncloud HIGH 8.3
CVE-2020-10252

An issue was discovered in ownCloud before 10.4. Because of an SSRF issue (via the apps/files_sharing/external remote parameter), an authenticated at…

Fix: 10.4.0+
Fix from $1,950 2021-02-19
Frendica CRITICAL 10.0
CVE-2021-27329

Friendica 2021.01 allows SSRF via parse_url?binurl= for DNS lookups or HTTP requests to arbitrary domain names.

Mitigation only
Fix from $2,300 2021-02-18
Fedora MEDIUM 6.5
CVE-2020-28463

All versions of package reportlab are vulnerable to Server-side Request Forgery (SSRF) via img tags. In order to reduce risk, use trustedSchemes & tr…

No fix yet
Fix from $1,600 2021-02-18
Fta CRITICAL 9.8
CVE-2021-27103 KEVEPSS 11%

Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later.

Fix: 9_12_416+
Fix from $2,300 2021-02-16
Mbconnect24 HIGH 7.5
CVE-2020-35558

An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. There is an SSRF in th…

Fix: after 2.11.2
Fix from $1,950 2021-02-16
Mbconnect24 MEDIUM 5.3
CVE-2020-35561

An issue was discovered MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. There is…

Fix: after 2.11.2
Fix from $1,600 2021-02-16
Debian Linux HIGH 7.2
CVE-2021-21311 KEVEPSS 90%

Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request for…

Fix: 4.7.9+
Fix from $1,950 2021-02-11
Apex One MEDIUM 5.3
CVE-2021-25241

A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 could all…

Patch available
Fix from $1,600 2021-02-04
Officescan MEDIUM 5.3
CVE-2021-25236

A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro OfficeScan XG SP1 and Worry-Free Business Security 10.0 SP1 …

Patch available
Fix from $1,600 2021-02-04
Teamcity HIGH 7.5
CVE-2020-35667

JetBrains TeamCity Plugin before 2020.2.85695 SSRF. Vulnerability that could potentially expose user credentials.

Fix: 2020.2.85695+
Fix from $1,950 2021-02-03
Minio HIGH 7.7
CVE-2021-21287EPSS 25%

MinIO is a High Performance Object Storage released under Apache License v2.0. In MinIO before version RELEASE.2021-01-30T00-20-58Z there is a server…

Fix: 2021-01-30t00-20-58z+
Fix from $1,950 2021-02-01
Winmail HIGH 7.5
CVE-2020-23776

A SSRF vulnerability exists in Winmail 6.5 in app.php in the key parameter when HTTPS is on. An attacker can use this vulnerability to cause the serv…

No fix yet
Fix from $1,950 2021-01-26
Tinycheck MEDIUM 6.5
CVE-2020-36200

TinyCheck before commits 9fd360d and ea53de8 allowed an authenticated attacker to send an HTTP GET request to the crafted URLs.

Fix: 2020-12-18+
Fix from $1,600 2021-01-26
Data Center Network Manager HIGH 8.8
CVE-2021-1272

A vulnerability in the session validation feature of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypa…

Fix: 11.5+
Fix from $1,950 2021-01-20
Airwave Glass HIGH 7.5
CVE-2020-24641

In Aruba AirWave Glass before 1.3.3, there is a Server-Side Request Forgery vulnerability through an unauthenticated endpoint that if successfully ex…

Fix: 1.3.3+
Fix from $1,950 2021-01-15
Campaign Classic HIGH 8.6
CVE-2021-21009

Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier), 19.2.3 (and earlier) and 19.…

Fix: after 20.3.1
Fix from $1,950 2021-01-13
Open Xchange Appsuite MEDIUM 6.4
CVE-2021-23927

OX App Suite through 7.10.4 allows SSRF via a URL with an @ character in an appsuite/api/oauth/proxy PUT request.

Fix: after 7.10.4
Fix from $1,600 2021-01-12
Open Xchange Appsuite MEDIUM 5.4
CVE-2020-24700

OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconfig. substring.

Fix: after 7.10.3
Fix from $1,600 2021-01-12
Policy Authority For Unified Communications CRITICAL 9.8
CVE-2020-35205

Server Side Request Forgery (SSRF) in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to scan internal ports and …

No fix yet
Fix from $2,300 2021-01-11
Plone HIGH 8.8
CVE-2020-28735

Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).

Fix: 5.2.3+
Fix from $1,950 2020-12-30
Cockpit MEDIUM 6.5
CVE-2020-35850

An SSRF issue was discovered in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product. NOTE: the vendor states "I …

No fix yet
Fix from $1,600 2020-12-30
Zammad HIGH 7.5
CVE-2020-26032

An SSRF issue was discovered in Zammad before 3.4.1. The SMS configuration interface for Massenversand is implemented in a way that renders the resul…

Fix: 3.4.1+
Fix from $1,950 2020-12-28
Arcgis Server CRITICAL 9.8
CVE-2020-35712

Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations.

Fix: 10.8+
Fix from $2,300 2020-12-26
Interscan Web Security Virtual Appliance HIGH 7.5
CVE-2020-8464EPSS 6%

A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to send requests that appear to come from the…

No fix yet
Fix from $1,950 2020-12-17
Netcrunch MEDIUM 6.5
CVE-2019-14476

AdRem NetCrunch 10.6.0.4587 has a Server-Side Request Forgery (SSRF) vulnerability in the NetCrunch server. Every user can trick the server into perf…

No fix yet
Fix from $1,600 2020-12-16
Struts HIGH 7.7
CVE-2020-26258EPSS 82%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability c…

Fix: 1.4.15 / 6.0.0+
Fix from $1,950 2020-12-16
Keycloak MEDIUM 5.3
CVE-2020-10770EPSS 70%

A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_u…

Fix: 12.0.2+
Fix from $1,600 2020-12-15
Airflow MEDIUM 5.3
CVE-2020-17513

In Apache Airflow versions prior to 1.10.13, the Charts and Query View of the old (Flask-admin based) UI were vulnerable for SSRF attack.

Fix: 1.10.13+
Fix from $1,600 2020-12-14