Vulnerability index

Browse CVEs

2,859 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Telepresence Video Communication Server MEDIUM 5.3
CVE-2019-1872

A vulnerability in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway Series software could allow an unauthenticated, remote at…

Mitigation only
Fix from $1,600 2019-06-05
Zimbra Collaboration Suite MEDIUM 6.5
CVE-2019-6981

Zimbra Collaboration Suite 8.7.x through 8.8.11 allows Blind SSRF in the Feed component.

Fix: 8.7.11 / 8.8.9+
Fix from $1,600 2019-05-29
Roller CRITICAL 9.8
CVE-2018-17198

Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java S…

Fix: after 5.1.2
Fix from $2,300 2019-05-28
Open Xchange Appsuite CRITICAL 9.9
CVE-2017-13667

OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF.

Fix: after 7.8.4
Fix from $2,300 2019-05-23
Webpagetest HIGH 8.8
CVE-2019-12161

WPO WebPageTest 19.04 allows SSRF because ValidateURL in www/runtest.php does not consider octal encoding of IP addresses (such as 0300.0250 as a rep…

Mitigation only
Fix from $1,950 2019-05-17
Dashboard Server MEDIUM 5.8
CVE-2019-6516

An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to force the application to perform requests to the internal workstation (port…

Mitigation only
Fix from $1,600 2019-05-14
Lightopenid CRITICAL 9.8
CVE-2019-11066

openid.php in LightOpenID through 1.3.1 allows SSRF via a crafted OpenID 2.0 assertion request using the HTTP GET method.

Fix: after 1.3.1
Fix from $2,300 2019-05-10
Cortex Analyzers HIGH 7.7
CVE-2019-7652EPSS 5%

TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. To exploit the vulnerability, an attacker mu…

Fix: 1.15.2+
Fix from $1,950 2019-05-09
Phpbb MEDIUM 5.8
CVE-2019-11767

Server side request forgery (SSRF) in phpBB before 3.2.6 allows checking for the existence of files and services on the local network of the host thr…

Fix: 3.2.6+
Fix from $1,600 2019-05-05
Axis HIGH 7.5
CVE-2019-0227EPSS 92%

A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits…

Patch available
Fix from $1,950 2019-05-01
Zimbra Collaboration Suite HIGH 7.5
CVE-2019-9621 KEVEPSS 81%

Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows S…

Fix: 8.6.0 / 8.7.11+
Fix from $1,950 2019-04-30
Print My Blog CRITICAL 9.8
CVE-2019-11565

Server Side Request Forgery (SSRF) exists in the Print My Blog plugin before 1.6.7 for WordPress via the site parameter.

Fix: 1.6.7+
Fix from $2,300 2019-04-27
GitLab CRITICAL 10.0
CVE-2019-9174

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows SSRF.

Fix: 11.6.10 / 11.7.6+
Fix from $2,300 2019-04-17
Api Connect CRITICAL 9.8
CVE-2019-4203

IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal can be exploited by app developers to download arbitrary files from the host OS and potentially …

Fix: after 5.0.8.6
Fix from $2,300 2019-04-15
Apollo CRITICAL 10.0
CVE-2019-10686

An SSRF vulnerability was found in an API from Ctrip Apollo through 1.4.0-SNAPSHOT. An attacker may use it to do an intranet port scan or raise a GET…

Fix: after 1.3.0
Fix from $2,300 2019-04-01
Confluence CRITICAL 9.8
CVE-2019-3395EPSS 7%

The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), from version 6.7.0 before 6.8.…

Fix: 6.6.12 / 6.12.3+
Fix from $2,300 2019-03-25
Moodle CRITICAL 10.0
CVE-2019-3809

A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, w…

Fix: after 3.1.15
Fix from $2,300 2019-03-25
Moodle HIGH 7.5
CVE-2019-6970

Moodle 3.5.x before 3.5.4 allows SSRF.

Fix: 3.5.4+
Fix from $1,950 2019-03-21
Open Xchange Appsuite MEDIUM 5.4
CVE-2018-13103

OX App Suite 7.8.4 and earlier allows SSRF.

Fix: after 7.8.4
Fix from $1,600 2019-03-21
Solr HIGH 7.5
CVE-2017-3164EPSS 19%

Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist …

Fix: after 7.6.0
Fix from $1,950 2019-03-08
Wavemarker Studio CRITICAL 9.6
CVE-2019-8982EPSS 28%

com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disc…

No fix yet
Fix from $2,300 2019-02-21
Dundas Bi HIGH 8.6
CVE-2018-18569

The Dundas BI server before 5.0.1.1010 is vulnerable to a Server-Side Request Forgery attack, allowing an attacker to forge arbitrary requests (with …

No fix yet
Fix from $1,950 2019-02-11
Telepresence Video Communication Server MEDIUM 5.0
CVE-2019-1679

A vulnerability in the web interface of Cisco TelePresence Conductor, Cisco Expressway Series, and Cisco TelePresence Video Communication Server (VCS…

Mitigation only
Fix from $1,600 2019-02-07
Suremdm HIGH 7.3
CVE-2018-15657

An SSRF issue was discovered in 42Gears SureMDM before 2018-11-27 via the /api/DownloadUrlResponse.ashx "url" parameter.

Fix: 2018-11-27+
Fix from $1,950 2019-02-05
Central Wifimanager MEDIUM 5.8
CVE-2018-15516

The FTP service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices allows remote attackers to conduct a PORT command bounce scan via port 8000,…

No fix yet
Fix from $1,600 2019-01-31
Central Wifimanager HIGH 8.6
CVE-2018-15517EPSS 44%

The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually all…

No fix yet
Fix from $1,950 2019-01-31
Open Xchange Appsuite MEDIUM 6.5
CVE-2018-12609

OX App Suite 7.8.4 and earlier allows Server-Side Request Forgery.

Fix: after 7.8.4
Fix from $1,600 2019-01-30
Elfinder HIGH 7.7
CVE-2019-6257

A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal network r…

Fix: 2.1.46+
Fix from $1,950 2019-01-14
Mesos MEDIUM 6.5
CVE-2018-1000421

An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read …

Fix: after 0.17.1
Fix from $1,600 2019-01-09
Crowd2 MEDIUM 6.5
CVE-2018-1000422

An improper authorization vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java that allows attacke…

Fix: after 2.0.0
Fix from $1,600 2019-01-09