Vulnerability index

Browse CVEs

2,859 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Trb245 Firmware MEDIUM 6.5
CVE-2020-5784

Server-Side Request Forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a low privileged user to cause the application to perform HTTP GET request…

No fix yet
Fix from $1,600 2020-10-01
Mbconnect24 MEDIUM 6.5
CVE-2020-24570

An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a CSRF issue (with resultant SSRF) in the com_mb24pr…

Fix: after 2.6.1
Fix from $1,600 2020-09-30
Cyber Backup MEDIUM 6.5
CVE-2020-16171EPSS 6%

An issue was discovered in Acronis Cyber Backup before 12.5 Build 16342. Some API endpoints on port 9877 under /api/ams/ accept an additional custom …

Fix: after 12.5
Fix from $1,600 2020-09-21
GitLab HIGH 8.8
CVE-2020-13309

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a blind SSRF attack through the reposit…

Fix: 13.1.10 / 13.2.8+
Fix from $1,950 2020-09-14
Infosphere Metadata Asset Manager MEDIUM 6.5
CVE-2020-4632

IBM InfoSphere Metadata Asset Manager 11.7 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticat…

Mitigation only
Fix from $1,600 2020-09-04
Open Xchange Appsuite MEDIUM 5.0
CVE-2020-12644

OX App Suite 7.10.3 and earlier allows SSRF, related to the mail account API and the /folder/list API.

Fix: after 7.10.3
Fix from $1,600 2020-08-31
Table Filter And Charts For Confluence Server MEDIUM 6.5
CVE-2020-24898

The Table Filter and Charts for Confluence Server app before 5.3.26 (for Atlassian Confluence) allows SSRF via the "Table from CSV" macro (URL parame…

Fix: 5.3.26+
Fix from $1,600 2020-08-29
Orca HIGH 7.5
CVE-2020-9298

The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an attacker to send requests on beh…

Fix: 8.7.0+
Fix from $1,950 2020-08-28
Access Server MEDIUM 5.3
CVE-2020-24548

Ericom Access Server 9.2.0 (for AccessNow and Ericom Blaze) allows SSRF to make outbound WebSocket connection requests on arbitrary TCP ports, and pr…

No fix yet
Fix from $1,600 2020-08-26
Cellos MEDIUM 6.5
CVE-2020-17386

Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly. With cookie of an authenticated user, attackers can temper with th…

Mitigation only
Fix from $1,600 2020-08-25
Codiad HIGH 7.2
CVE-2020-14044

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Server-Side Request Forgery (SSRF) vulnerability was found in Codiad v1.7.8 and later. A user with admin …

No fix yet
Fix from $1,950 2020-08-24
Canvas Learning Management Service MEDIUM 5.8
CVE-2020-5775EPSS 7%

Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas application to perform HTTP GET re…

Patch available
Fix from $1,600 2020-08-21
Ftp Srv CRITICAL 9.1
CVE-2020-15152

ftp-srv is an npm package which is a modern and extensible FTP server designed to be simple yet configurable. In ftp-srv before versions 2.19.6, 3.1.…

Fix: 2.19.6 / 3.1.2+
Fix from $2,300 2020-08-17
Phpbb MEDIUM 5.8
CVE-2020-8226

A vulnerability exists in phpBB <v3.2.10 and <v3.3.1 which allowed remote image dimensions check to be used to SSRF.

Fix: 3.2.10 / 3.3.1+
Fix from $1,600 2020-08-17
Cloudforms Management Engine HIGH 7.1
CVE-2020-14296

Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible Tower provider, an attacker co…

Mitigation only
Fix from $1,950 2020-08-11
Runner HIGH 8.8
CVE-2020-13295

For GitLab Runner before 13.0.12, 13.1.6, 13.2.3, by replacing dockerd with a malicious server, the Shared Runner is susceptible to SSRF.

Fix: 13.0.12 / 13.1.6+
Fix from $1,950 2020-08-10
Blackbox Exporter MEDIUM 5.8
CVE-2020-16248

Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted …

Fix: after 0.17.0
Fix from $1,600 2020-08-09
Youtrack HIGH 7.5
CVE-2020-15823

JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component.

Fix: 2020.2.8873+
Fix from $1,950 2020-08-08
Youtrack MEDIUM 5.3
CVE-2020-15819

JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports.

Fix: 2020.2.10643+
Fix from $1,600 2020-08-08
Shopware HIGH 8.8
CVE-2020-13970

Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated…

Fix: 6.2.3+
Fix from $1,950 2020-07-28
Server HIGH 7.5
CVE-2020-15879

Bitwarden Server 1.35.1 allows SSRF because it does not consider certain IPv6 addresses (ones beginning with fc, fd, fe, or ff, and the :: address) a…

Patch available
Fix from $1,950 2020-07-21
Uppy HIGH 7.5
CVE-2020-8205

The uppy npm package < 1.13.2 and < 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to sc…

Fix: 1.13.2+
Fix from $1,950 2020-07-20
Netweaver Application Server Java MEDIUM 5.8
CVE-2020-6282

SAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, and SAP NetWeaver AS JAVA (IIOP service) (CORE-…

Mitigation only
Fix from $1,600 2020-07-14
Monsta Ftp CRITICAL 9.8
CVE-2020-14056

Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of the web fetch functionality. Th…

Fix: after 2.10.1
Fix from $2,300 2020-07-01
Jira MEDIUM 5.3
CVE-2019-20408

The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the content of internal network reso…

Fix: 8.7.0+
Fix from $1,600 2020-07-01
Bitrix24 CRITICAL 9.8
CVE-2020-13484

Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview url parameter, if the destinat…

Fix: after 20.0.975
Fix from $2,300 2020-06-24
Mattermost Server MEDIUM 5.5
CVE-2019-20872

An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. SSRF can attack local services.

Fix: 4.10.8 / 5.7.3+
Fix from $1,600 2020-06-19
Open Xchange Appsuite MEDIUM 6.5
CVE-2020-8544

OX App Suite through 7.10.3 allows SSRF.

No fix yet
Fix from $1,600 2020-06-16
Digdash HIGH 7.5
CVE-2020-13650

An issue was discovered in DigDash 2018R2 before p20200210 and 2019R1 before p20200210. The login page is vulnerable to Server-Side Request Forgery (…

Mitigation only
Fix from $1,950 2020-06-15
Ox Guard MEDIUM 5.0
CVE-2020-9427

OX Guard 2.10.3 and earlier allows SSRF.

No fix yet
Fix from $1,600 2020-06-15