Vulnerability index

Browse CVEs

2,859 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Jsreport CRITICAL 9.8
CVE-2020-8128

An unintended require and server-side request forgery vulnerabilities in jsreport version 2.5.0 and earlier allow attackers to execute arbitrary code.

Fix: after 2.5.0
Fix from $2,300 2020-02-14
Content Navigator MEDIUM 5.3
CVE-2019-4741

IBM Content Navigator 3.0CD is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requ…

Mitigation only
Fix from $1,600 2020-02-12
Nextcloud Server MEDIUM 5.0
CVE-2020-8118

An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in…

Fix: 15.0.9 / 16.0.2+
Fix from $1,600 2020-02-04
Syuan Gu Da Shin HIGH 7.5
CVE-2020-3938

SysJust Syuan-Gu-Da-Shih, versions before 20191223, contain vulnerability of Request Forgery, allowing attackers to launch inquiries into network arc…

Fix: 20191223+
Fix from $1,950 2020-02-04
Veralite Firmware CRITICAL 9.8
CVE-2013-4864EPSS 6%

MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url parameter to cgi-bin/cmh/pro…

No fix yet
Fix from $2,300 2020-01-28
GitLab CRITICAL 9.8
CVE-2019-5464

A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF where the li…

Fix: 11.11.7+
Fix from $2,300 2020-01-28
Ext Js HIGH 7.5
CVE-2007-6758

Server-side request forgery (SSRF) vulnerability in feed-proxy.php in extjs 5.0.0.

No fix yet
Fix from $1,950 2020-01-23
Unleashed HIGH 7.5
CVE-2019-19835

SSRF in AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote denial of service via the server attribute …

Fix: 9.10.2.0.84 / 9.12.3.0.136+
Fix from $1,950 2020-01-23
Olingo HIGH 7.5
CVE-2020-1925

Apache Olingo versions 4.0.0 to 4.7.0 provide the AsyncRequestWrapperImpl class which reads a URL from the Location header, and then sends a GET or D…

Fix: after 4.7.0
Fix from $1,950 2020-01-09
GitLab HIGH 8.8
CVE-2019-19261

GitLab Enterprise Edition (EE) 6.7 and later through 12.5 allows SSRF.

Fix: 12.5.1+
Fix from $1,950 2020-01-03
GitLab MEDIUM 5.0
CVE-2018-20497

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF.

Fix: 11.4.13 / 11.5.6+
Fix from $1,600 2019-12-30
GitLab HIGH 7.2
CVE-2018-20499

An issue was discovered in GitLab Community and Enterprise Edition before 11.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It all…

Fix: 11.4.13 / 11.5.6+
Fix from $1,950 2019-12-30
Liquifire Os MEDIUM 6.5
CVE-2019-20055

LuquidPixels LiquiFire OS 4.8.0 allows SSRF via the call%3Durl substring followed by a URL in square brackets.

No fix yet
Fix from $1,600 2019-12-29
Halo HIGH 7.2
CVE-2019-19999

Halo before 1.2.0-beta.1 allows Server Side Template Injection (SSTI) because TemplateClassResolver.SAFER_RESOLVER is not used in the FreeMarker conf…

Fix: after 1.1.1
Fix from $1,950 2019-12-26
Messaging Gateway HIGH 7.3
CVE-2019-18379

Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a server-side request forgery (SSRF) exploit, which is a type of issue that can le…

Fix: 10.7.3+
Fix from $1,950 2019-12-11
Web Chat CRITICAL 9.8
CVE-2019-16948

An SSRF issue was discovered in Enghouse Web Chat 6.1.300.31. In any POST request, one can replace the port number at WebServiceLocation=http://local…

No fix yet
Fix from $2,300 2019-11-13
Magento HIGH 7.2
CVE-2019-8156

A server-side request forgery (SSRF) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated us…

Fix: 2.2.10 / 2.3.2+
Fix from $1,950 2019-11-06
Magento HIGH 7.2
CVE-2019-8151

A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with admin…

Fix: 2.2.10 / 2.3.2+
Fix from $1,950 2019-11-06
Openfire CRITICAL 9.8
CVE-2019-18394EPSS 32%

A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrar…

Fix: after 4.4.2
Fix from $2,300 2019-10-24
Secret Server CRITICAL 9.8
CVE-2019-18355

An SSRF issue was discovered in the legacy Web launcher in Thycotic Secret Server before 10.7.

Fix: 10.7.000000+
Fix from $2,300 2019-10-23
Universal Office Converter HIGH 7.5
CVE-2019-17400

The unoconv package before 0.9 mishandles untrusted pathnames, leading to SSRF and local file inclusion.

Fix: 0.9+
Fix from $1,950 2019-10-21
WordPress CRITICAL 9.8
CVE-2019-17669EPSS 5%

WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name a…

Fix: 5.2.4+
Fix from $2,300 2019-10-17
WordPress CRITICAL 9.8
CVE-2019-17670

WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relat…

Fix: 5.2.4+
Fix from $2,300 2019-10-17
Open Xchange Appsuite MEDIUM 5.4
CVE-2019-14225

OX App Suite 7.10.1 and 7.10.2 allows SSRF.

No fix yet
Fix from $1,600 2019-10-14
Graphite HIGH 7.5
CVE-2017-18638EPSS 15%

send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF. The vulnerable SSRF endpoint can be use…

Fix: after 1.1.5
Fix from $1,950 2019-10-11
Inspector MEDIUM 5.3
CVE-2019-15021

A security vulnerability exists in the Zingbox Inspector versions 1.294 and earlier, that can allow an attacker to easily identify instances of Zingb…

Fix: after 1.294
Fix from $1,600 2019-10-09
Libpcap MEDIUM 5.3
CVE-2019-15164

rpcapd/daemon.c in libpcap before 1.9.1 allows SSRF because a URL may be provided as a capture source.

Fix: 1.9.1+
Fix from $1,600 2019-10-03
Suitecrm CRITICAL 9.8
CVE-2019-13335

SalesAgility SuiteCRM 7.10.x 7.10.19 and 7.11.x before and 7.11.7 has SSRF.

Fix: 7.10.19 / 7.11.7+
Fix from $2,300 2019-10-02
Visualizer CRITICAL 10.0
CVE-2019-16932EPSS 39%

A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.

Fix: 3.3.1+
Fix from $2,300 2019-09-30
Qradar Security Information And Event Manager MEDIUM 5.3
CVE-2019-4262

IBM QRadar SIEM 7.2 and 7.3 is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requ…

Fix: 7.2.8 / 7.3.2+
Fix from $1,600 2019-09-26