Vulnerability index

Browse CVEs

2,859 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Experience Manager Forms Add On MEDIUM 5.8
CVE-2020-24444

AEM Forms SP6 add-on for AEM 6.5.6.0 and Forms add-on package for AEM 6.4 Service Pack 8 Cumulative Fix Pack 2 (6.4.8.2) have a blind Server-Side Req…

Mitigation only
Fix from $1,600 2020-12-10
Canto MEDIUM 5.3
CVE-2020-28976EPSS 28%

The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal an…

No fix yet
Fix from $1,600 2020-11-30
Canto MEDIUM 5.3
CVE-2020-28977EPSS 15%

The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and …

No fix yet
Fix from $1,600 2020-11-30
Canto MEDIUM 5.3
CVE-2020-28978EPSS 15%

The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and …

No fix yet
Fix from $1,600 2020-11-30
Microstrategy MEDIUM 6.5
CVE-2020-24815

A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2 allows authen…

No fix yet
Fix from $1,600 2020-11-24
Private Ip CRITICAL 9.8
CVE-2020-28360

Insufficient RegEx in private-ip npm package v1.0.5 and below insufficiently filters reserved IP ranges resulting in indeterminate SSRF. An attacker …

Fix: after 1.0.5
Fix from $2,300 2020-11-23
Youtrack MEDIUM 5.3
CVE-2020-27624

JetBrains YouTrack before 2020.3.888 was vulnerable to SSRF.

Fix: 2020.3.888+
Fix from $1,600 2020-11-16
Youtrack MEDIUM 5.3
CVE-2020-27626

JetBrains YouTrack before 2020.3.5333 was vulnerable to SSRF.

Fix: 2020.3.5333+
Fix from $1,600 2020-11-16
Batik HIGH 7.5
CVE-2019-17566EPSS 11%

Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-c…

Fix: 1.13+
Fix from $1,950 2020-11-12
Mvision Endpoint HIGH 7.2
CVE-2020-7329

Server-side request forgery vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers trigger server-side …

Fix: 20.11+
Fix from $1,950 2020-11-11
Mvision Endpoint HIGH 7.2
CVE-2020-7328

External entity attack vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers to gain control of a reso…

Fix: 20.11+
Fix from $1,950 2020-11-11
Canto HIGH 7.2
CVE-2020-24063

The Canto plugin 1.3.0 for WordPress allows includes/lib/download.php?subdomain= SSRF.

Mitigation only
Fix from $1,950 2020-11-10
Commerce Cloud \(accelerator Payment Mock\) MEDIUM 5.3
CVE-2020-26811

SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over…

No fix yet
Fix from $1,600 2020-11-10
Fiori Launchpad \(news Tile Application\) HIGH 8.6
CVE-2020-26815

SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send a crafted request to a vulne…

Mitigation only
Fix from $1,950 2020-11-10
Interscan Messaging Security Virtual Appliance MEDIUM 5.5
CVE-2020-27018

Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a server side request forgery vulnerability which could allow…

Fix: after 9.1
Fix from $1,600 2020-11-09
Update Server CRITICAL 9.1
CVE-2020-15297

Insufficient validation in the Bitdefender Update Server and BEST Relay components of Bitdefender Endpoint Security Tools versions prior to 6.6.20.29…

Fix: 6.6.20.294+
Fix from $2,300 2020-11-09
Axios MEDIUM 5.9
CVE-2020-28168

Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL t…

Fix: 1.0+
Fix from $1,600 2020-11-06
Misp HIGH 7.5
CVE-2020-28043

MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL.

Fix: after 2.4.133
Fix from $1,950 2020-11-02
Osticket CRITICAL 9.8
CVE-2020-24881EPSS 73%

SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.

Fix: 1.14.3+
Fix from $2,300 2020-11-02
Gophish MEDIUM 5.3
CVE-2020-24710

Gophish before 0.11.0 allows SSRF attacks.

Fix: 0.11.0+
Fix from $1,600 2020-10-28
Airwave Glass MEDIUM 5.8
CVE-2020-7126

A remote server-side request forgery (ssrf) vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.

Fix: 1.3.2+
Fix from $1,600 2020-10-26
Crmeb CRITICAL 9.8
CVE-2020-25466

A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execu…

Mitigation only
Fix from $2,300 2020-10-23
Open Xchange Appsuite MEDIUM 5.0
CVE-2020-15002

OX App Suite through 7.10.3 allows SSRF via the the /ajax/messaging/message message API.

Fix: after 7.10.3
Fix from $1,600 2020-10-23
Bigbluebutton MEDIUM 6.5
CVE-2020-25820EPSS 10%

BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document that has a …

Fix: 2.2.27+
Fix from $1,600 2020-10-21
Businessobjects Business Intelligence Platform MEDIUM 5.3
CVE-2020-6308EPSS 62%

SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary va…

Mitigation only
Fix from $1,600 2020-10-20
Youtrack HIGH 7.3
CVE-2020-15822

In JetBrains YouTrack before 2020.2.10514, SSRF is possible because URL filtering can be escaped.

Fix: 2020.2.10514+
Fix from $1,950 2020-10-19
Opentaxii CRITICAL 9.8
CVE-2020-27197

TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the…

Fix: after 1.1.117
Fix from $2,300 2020-10-17
Emby CRITICAL 9.8
CVE-2020-26948EPSS 87%

Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.

Fix: 4.5.0+
Fix from $2,300 2020-10-10
Node Pdf Generator HIGH 8.2
CVE-2020-7740

This affects all versions of package node-pdf-generator. Due to lack of user input validation and sanitization done to the content given to node-pdf-…

Mitigation only
Fix from $1,950 2020-10-06
Phantomjs Seo HIGH 8.2
CVE-2020-7739

This affects all versions of package phantomjs-seo. It is possible for an attacker to craft a url that will be passed to a PhantomJS instance allowin…

Patch available
Fix from $1,950 2020-10-06