Vulnerability index

Browse CVEs

2,859 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Pydio HIGH 7.7
CVE-2019-15033

Pydio 6.0.8 allows Authenticated SSRF during a Remote Link Feature download. An attacker can specify an intranet address in the file parameter to ind…

No fix yet
Fix from $1,950 2019-09-19
Meg6501 0001 Firmware CRITICAL 9.1
CVE-2019-6837

A Server-Side Request Forgery (SSRF): CWE-918 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KN…

Fix: 1.3.7+
Fix from $2,300 2019-09-17
GitLab MEDIUM 5.3
CVE-2019-15731

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Non-members were able to comment on merge requests despite th…

Fix: 12.0.8 / 12.1.8+
Fix from $1,600 2019-09-16
GitLab HIGH 7.5
CVE-2019-15728

An issue was discovered in GitLab Community and Enterprise Edition 10.1 through 12.2.1. Protections against SSRF attacks on the Kubernetes integratio…

Fix: 12.0.8 / 12.1.8+
Fix from $1,950 2019-09-16
GitLab HIGH 7.5
CVE-2019-15730

An issue was discovered in GitLab Community and Enterprise Edition 8.14 through 12.2.1. The Jira integration contains a SSRF vulnerability as a resul…

Fix: 12.0.8 / 12.1.8+
Fix from $1,950 2019-09-16
Jira Server MEDIUM 6.5
CVE-2019-8451EPSS 94%

The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network reso…

Fix: 8.4.0+
Fix from $1,600 2019-09-11
Mendix MEDIUM 5.3
CVE-2019-12996

In Mendix 7.23.5 and earlier, issue in XML import mappings allow DOCTYPE declarations in the XML input that is potentially unsafe.

Fix: after 7.23.5
Fix from $1,600 2019-09-10
GitLab HIGH 7.0
CVE-2019-6793

An issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The Jira integration feature is v…

Fix: 11.5.8 / 11.6.6+
Fix from $1,950 2019-09-09
Finesse HIGH 7.5
CVE-2019-12632

A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery …

Mitigation only
Fix from $1,950 2019-09-05
Unified Contact Center Express HIGH 7.5
CVE-2019-12633

A vulnerability in Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to bypass access controls and c…

Fix: 11.6+
Fix from $1,950 2019-09-05
Tightrope Media Carousel CRITICAL 10.0
CVE-2019-13020

The fetch API in Tightrope Media Carousel before 7.1.3 has CarouselAPI/v0/fetch?url= SSRF. This has two potential areas for abuse. First, a specially…

Fix: 7.1.3+
Fix from $2,300 2019-08-26
Openitcockpit CRITICAL 9.8
CVE-2019-15494

openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21.

Fix: 3.7.1+
Fix from $2,300 2019-08-23
Nelio Ab Testing CRITICAL 10.0
CVE-2016-10926

The nelio-ab-testing plugin before 4.5.9 for WordPress has SSRF in ajax/iesupport.php.

Fix: 4.5.9+
Fix from $2,300 2019-08-22
Nelio Ab Testing CRITICAL 10.0
CVE-2016-10927

The nelio-ab-testing plugin before 4.5.11 for WordPress has SSRF in ajax/iesupport.php.

Fix: 4.5.11+
Fix from $2,300 2019-08-22
Iot Gateway Software HIGH 8.6
CVE-2019-11897

A Server-Side Request Forgery (SSRF) vulnerability in the backup & restore functionality in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT…

Fix: 8.2.6 / 9.3.0+
Fix from $1,950 2019-08-21
Netweaver Application Server Java CRITICAL 9.8
CVE-2019-0345

A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Java (Administrator System Overview), versions 7.30…

Mitigation only
Fix from $2,300 2019-08-14
Manageengine Assetexplorer HIGH 8.8
CVE-2019-12959

Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer 6.2.0 and before for the ClientUtilServlet servlet via a URL in a parame…

Fix: 6.2.0+
Fix from $1,950 2019-08-08
Manageengine Assetexplorer CRITICAL 9.1
CVE-2019-12994

Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet via a parameter in a URL.

Mitigation only
Fix from $2,300 2019-08-08
Go Camo CRITICAL 9.8
CVE-2019-14255

A Server Side Request Forgery (SSRF) vulnerability in go-camo up to version 1.1.4 allows a remote attacker to perform HTTP requests to internal endpo…

Fix: after 1.1.4
Fix from $2,300 2019-08-08
Mdc N4090 Firmware CRITICAL 9.8
CVE-2019-14704

An SSRF issue was discovered in HTTPD on MicroDigital N-series cameras with firmware through 6400.0.8.5 via FTP commands following a newline characte…

Fix: after 6400.0.8.5
Fix from $2,300 2019-08-06
Magento HIGH 7.2
CVE-2019-7923

A server-side request forgery (SSRF) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Thi…

Fix: 2.1.18 / 2.2.9+
Fix from $1,950 2019-08-02
Magento HIGH 7.2
CVE-2019-7892

A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated…

Fix: 2.1.18 / 2.2.9+
Fix from $1,950 2019-08-02
Magento HIGH 7.2
CVE-2019-7911

A server-side request forgery (SSRF) vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.…

Fix: 2.1.18 / 2.2.9+
Fix from $1,950 2019-08-02
Magento HIGH 7.2
CVE-2019-7913

A server-side request forgery (SSRF) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Thi…

Fix: 2.1.18 / 2.2.9+
Fix from $1,950 2019-08-02
GitLab HIGH 7.7
CVE-2018-19571EPSS 28%

GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an SSRF vulnerability in webhook…

Fix: 11.3.11 / 11.4.8+
Fix from $1,950 2019-07-10
GitLab MEDIUM 6.5
CVE-2018-19495

An issue was discovered in GitLab Community and Enterprise Edition before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an SSRF v…

Fix: 11.3.11 / 11.4.8+
Fix from $1,600 2019-07-10
Hawtio CRITICAL 9.8
CVE-2019-9827EPSS 27%

Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host v…

Fix: after 2.5.0
Fix from $2,300 2019-07-03
Youtrack CRITICAL 9.8
CVE-2019-12852

An SSRF attack was possible on a JetBrains YouTrack server. The issue (1 of 2) was fixed in JetBrains YouTrack 2018.4.49168.

Fix: 2018.4.49168+
Fix from $2,300 2019-07-03
Pdfreactor CRITICAL 10.0
CVE-2019-12153

Lack of validation in the HTML parser in RealObjects PDFreactor before 10.1.10722 leads to SSRF, allowing attackers to access network or file resourc…

Fix: 10.1.10722+
Fix from $2,300 2019-06-11
Ikiwiki HIGH 7.5
CVE-2019-9187

ikiwiki before 3.20170111.1 and 3.2018x and 3.2019x before 3.20190228 allows SSRF via the aggregate plugin. The impact also includes reading local fi…

Fix: 3.20170111.1 / 3.20190226+
Fix from $1,950 2019-06-05