Vulnerability index

Browse CVEs

2,859 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Qibosoft HIGH 7.5
CVE-2019-5725

qibosoft through V7 allows remote attackers to read arbitrary files via the member/index.php main parameter, as demonstrated by SSRF to a URL on the …

Fix: after 7.0
Fix from $1,950 2019-01-08
Rhymix CRITICAL 9.1
CVE-2018-19601

Rhymix CMS 1.9.8.1 allows SSRF via an index.php?module=admin&act=dispModuleAdminFileBox SVG upload.

Patch available
Fix from $2,300 2019-01-03
Manageengine Adselfservice Plus CRITICAL 10.0
CVE-2019-3905

Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF.

Mitigation only
Fix from $2,300 2019-01-03
Debian Linux CRITICAL 10.0
CVE-2018-14721EPSS 10%

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure …

Fix: 2.6.7.2 / 2.7.9.5+
Fix from $2,300 2019-01-02
Jspxcms CRITICAL 9.8
CVE-2018-20596

Jspxcms v9.0.0 allows SSRF.

Mitigation only
Fix from $2,300 2018-12-30
Jeecms MEDIUM 6.5
CVE-2018-20528

JEECMS 9 has SSRF via the ueditor/getRemoteImage.jspx upfile parameter.

Mitigation only
Fix from $1,600 2018-12-28
Telegram HIGH 8.1
CVE-2018-20436

The "secret chat" feature in Telegram 4.9.1 for Android has a "side channel" in which Telegram servers send GET requests for URLs typed while composi…

No fix yet
Fix from $1,950 2018-12-24
Subsonic HIGH 8.0
CVE-2018-20228

Subsonic V6.1.5 allows internetRadioSettings.view streamUrl CSRF, with resultant SSRF.

No fix yet
Fix from $1,950 2018-12-19
GitLab HIGH 8.8
CVE-2018-18646

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows SSRF.

Fix: 11.2.7 / 11.3.8+
Fix from $1,950 2018-12-04
GitLab CRITICAL 10.0
CVE-2018-18843

The Kubernetes integration in GitLab Enterprise Edition 11.x before 11.2.8, 11.3.x before 11.3.9, and 11.4.x before 11.4.4 has SSRF.

Fix: 11.2.8 / 11.3.9+
Fix from $2,300 2018-12-04
Email Marketer MEDIUM 6.5
CVE-2018-19651

admin/functions/remote.php in Interspire Email Marketer through 6.1.6 has Server Side Request Forgery (SSRF) via a what=importurl&url= request with a…

Fix: after 6.1.6
Fix from $1,600 2018-11-28
Mpdf CRITICAL 10.0
CVE-2018-19047

mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '<img src="http://192.168' substr…

Fix: after 7.1.6
Fix from $2,300 2018-11-07
Responsive Filemanager HIGH 8.6
CVE-2018-18867

An SSRF issue was discovered in tecrail Responsive FileManager 9.13.4 via the upload.php url parameter. NOTE: this issue exists because of an incompl…

No fix yet
Fix from $1,950 2018-10-31
Typecho CRITICAL 9.8
CVE-2018-18753

Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF.

No fix yet
Fix from $2,300 2018-10-29
Exchange Server HIGH 8.6
CVE-2018-16793EPSS 11%

Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parameter in /owa/auth/logon.aspx i…

No fix yet
Fix from $1,950 2018-09-21
Active Directory Federation Services HIGH 8.6
CVE-2018-16794EPSS 8%

Microsoft ADFS 4.0 Windows Server 2016 and previous (Active Directory Federation Services) has an SSRF vulnerability via the txtBoxEmail parameter in…

Fix: after 4.0
Fix from $1,950 2018-09-18
Hybris HIGH 8.6
CVE-2018-2463

The Omni Commerce Connect API (OCC) of SAP Hybris Commerce, versions 6.*, is vulnerable to server-side request forgery (SSRF) attacks. This is due to…

Fix: after 6.7
Fix from $1,950 2018-09-11
Api Connect CRITICAL 9.9
CVE-2018-1789

IBM API Connect v2018.1.0 through v2018.3.4 could allow an attacker to send a specially crafted request to conduct a server side request forgery atta…

Fix: after 2018.3.4
Fix from $2,300 2018-09-07
Seacms CRITICAL 9.1
CVE-2018-16444

An issue was discovered in SeaCMS 6.61. adm1n/admin_reslib.php has SSRF via the url parameter.

No fix yet
Fix from $2,300 2018-09-04
Gogs HIGH 8.6
CVE-2018-16409

In Gogs 0.11.53, an attacker can use migrate to send arbitrary HTTP GET requests, leading to SSRF.

Mitigation only
Fix from $1,950 2018-09-03
Icms HIGH 7.5
CVE-2018-15895

An SSRF vulnerability was discovered in idreamsoft iCMS 7.0.11 because the remote function in app/spider/spider_tools.class.php does not block DNS ho…

Fix: 7.0.11+
Fix from $1,950 2018-08-27
Control Manager CRITICAL 10.0
CVE-2018-10511

A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to conduct a server-side request forgery (SSRF) attack …

Patch available
Fix from $2,300 2018-08-15
Businessobjects Business Intelligence CRITICAL 9.6
CVE-2018-2445

AdminTools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allows an attacker to manipulate the vulnerable application to send craft…

Mitigation only
Fix from $2,300 2018-08-14
Url Parse CRITICAL 10.0
CVE-2018-3774

Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authenticati…

Fix: 1.4.3+
Fix from $2,300 2018-08-12
Gitea HIGH 8.6
CVE-2018-15192

An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.

Fix: 1.5.0+
Fix from $1,950 2018-08-08
Responsive Filemanager CRITICAL 9.8
CVE-2018-14728EPSS 77%

upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.

No fix yet
Fix from $2,300 2018-08-03
Icms HIGH 7.5
CVE-2018-14858

An SSRF vulnerability was discovered in idreamsoft iCMS before V7.0.11 because the remote function in app/spider/spider_tools.class.php does not bloc…

Fix: 7.0.11+
Fix from $1,950 2018-08-02
Tracetronic Ecu Test MEDIUM 6.5
CVE-2018-1999026

A server-side request forgery vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublisher.java that allows attackers …

Fix: after 2.3
Fix from $1,600 2018-08-01
Icms CRITICAL 9.8
CVE-2018-14514

An SSRF vulnerability was discovered in idreamsoft iCMS V7.0.9 that allows attackers to read sensitive files, access an intranet, or possibly have un…

No fix yet
Fix from $2,300 2018-07-23
Experience Manager HIGH 7.5
CVE-2018-12809

Adobe Experience Manager versions 6.4 and earlier have a Server-Side Request Forgery vulnerability. Successful exploitation could lead to sensitive i…

Fix: after 6.4.0
Fix from $1,950 2018-07-20