Vulnerability index

Browse CVEs

2,859 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Karaf MEDIUM 6.3
CVE-2020-11980

In Karaf, JMX authentication takes place using JAAS and authorization takes place using ACL files. By default, only an "admin" can actually invoke on…

Fix: 4.2.9+
Fix from $1,600 2020-06-12
Experience Manager HIGH 7.5
CVE-2020-9643

Adobe Experience Manager versions 6.5 and earlier have a server-side request forgery (ssrf) vulnerability. Successful exploitation could lead to sens…

Fix: 6.4.8.1 / 6.5.5.0+
Fix from $1,950 2020-06-12
Experience Manager HIGH 7.5
CVE-2020-9645

Adobe Experience Manager versions 6.5 and earlier have a blind server-side request forgery (ssrf) vulnerability. Successful exploitation could lead t…

Fix: 6.4.8.1 / 6.5.5.0+
Fix from $1,950 2020-06-12
Redash HIGH 7.2
CVE-2020-12725

Havoc Research discovered an authenticated Server-Side Request Forgery (SSRF) via the "JSON" data source of Redash open-source 8.0.0 and prior. Possi…

Fix: after 8.0.0
Fix from $1,950 2020-06-11
Hcl Digital Experience CRITICAL 9.8
CVE-2020-4101

"HCL Digital Experience is susceptible to Server Side Request Forgery."

Mitigation only
Fix from $2,300 2020-06-11
Netweaver Application Server Abap CRITICAL 9.8
CVE-2020-6275

SAP Netweaver AS ABAP, versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, are vulnerable for Server Side Request Forgery Attac…

Mitigation only
Fix from $2,300 2020-06-10
Maximo Asset Management HIGH 7.4
CVE-2020-4529

IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send una…

Patch available
Fix from $1,950 2020-06-08
Kubernetes MEDIUM 6.3
CVE-2020-8555

The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a S…

Fix: 1.15.11 / 1.16.9+
Fix from $1,600 2020-06-05
Grafana HIGH 8.2
CVE-2020-13379EPSS 100%

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/clie…

Fix: after 7.0.1
Fix from $1,950 2020-06-03
Lexiglot HIGH 8.8
CVE-2014-8943

Lexiglot through 2014-11-20 allows SSRF via the admin.php?page=projects svn_url parameter.

Fix: after 2014-11-20
Fix from $1,950 2020-06-01
Api Manager CRITICAL 9.8
CVE-2020-13226

WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this node's en…

Mitigation only
Fix from $2,300 2020-05-20
Ruckus Zoneflex R500 Firmware HIGH 8.8
CVE-2020-8830

CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other analysis via the SUBCA-1 field …

No fix yet
Fix from $1,950 2020-05-05
Enterprise Integrator HIGH 7.2
CVE-2020-11885

WSO2 Enterprise Integrator through 6.6.0 has an XXE vulnerability where a user (with admin console access) can use the XML validator to make unintend…

Fix: after 6.6.0
Fix from $1,950 2020-04-17
Qradar Security Information And Event Manager MEDIUM 6.3
CVE-2020-4294

IBM QRadar 7.3.0 to 7.3.3 Patch 2 is vulnerable to Server Side Request Forgery (SSRF). This may allow an authenticated attacker to send unauthorized …

Fix: 7.3.3+
Fix from $1,600 2020-04-15
GitLab CRITICAL 9.8
CVE-2020-10980

GitLab EE/CE 8.0.rc1 to 12.9 is vulnerable to a blind SSRF in the FogBugz integration.

Fix: after 12.9
Fix from $2,300 2020-04-08
Microstrategy Web MEDIUM 5.3
CVE-2020-11453

Microstrategy Web 10.4 is vulnerable to Server-Side Request Forgery in the Test Web Service functionality exposed through the path /MicroStrategyWS/.…

Patch available
Fix from $1,600 2020-04-02
GitLab CRITICAL 9.8
CVE-2020-10956

GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature.

Fix: 12.9.1+
Fix from $2,300 2020-03-27
Experience Manager HIGH 7.5
CVE-2020-3769

Adobe Experience Manager versions 6.5 and earlier have a server-side request forgery (ssrf) vulnerability. Successful exploitation could lead to sens…

Fix: after 6.5.0
Fix from $1,950 2020-03-25
Openitcockpit MEDIUM 6.5
CVE-2020-10791

app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger out…

Fix: 3.7.3+
Fix from $1,600 2020-03-25
Simple Machine Forum CRITICAL 9.8
CVE-2019-11574

An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php and Subs.php because user-sup…

Fix: 2.0.17+
Fix from $2,300 2020-03-20
Nextcloud Server MEDIUM 6.5
CVE-2020-8138

A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulner…

Fix: 15.0.14 / 16.0.7+
Fix from $1,600 2020-03-20
Ghost HIGH 8.1
CVE-2020-8134

Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network or otherwise interact wit…

Fix: 3.10.0+
Fix from $1,950 2020-03-20
Uppy CRITICAL 9.8
CVE-2020-8135

The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external …

Fix: 1.9.3+
Fix from $2,300 2020-03-20
GitLab CRITICAL 9.8
CVE-2020-10077

GitLab EE 3.0 through 12.8.1 allows SSRF. An internal investigation revealed that a particular deprecated service was creating a server side request …

Fix: after 12.8.1
Fix from $2,300 2020-03-13
Manageengine Desktop Central CRITICAL 9.8
CVE-2020-8540EPSS 13%

An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to …

Fix: 2020-03-07+
Fix from $2,300 2020-03-11
GitLab HIGH 7.5
CVE-2019-13121

An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability whic…

Fix: after 12.0.2
Fix from $1,950 2020-03-10
GitLab CRITICAL 9.8
CVE-2019-12443

An issue was discovered in GitLab Community and Enterprise Edition 10.2 through 11.11. Multiple features contained Server-Side Request Forgery (SSRF)…

Fix: after 11.11.0
Fix from $2,300 2020-03-10
Responsive Filemanager CRITICAL 9.8
CVE-2020-10212

upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishandled and because it…

No fix yet
Fix from $2,300 2020-03-07
Open Xchange Appsuite MEDIUM 5.0
CVE-2019-18846

OX App Suite through 7.10.2 allows SSRF.

Fix: after 7.10.2
Fix from $1,600 2020-02-21
Zimbra Collaboration Suite CRITICAL 9.8
CVE-2020-7796 KEVEPSS 84%

Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.

Fix: 8.8.15+
Fix from $2,300 2020-02-18