Vulnerability index

Browse CVEs

2,859 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Experience Manager HIGH 7.5
CVE-2018-5004

Adobe Experience Manager versions 6.2 and 6.3 have a Server-Side Request Forgery vulnerability. Successful exploitation could lead to sensitive infor…

Fix: 6.4.0+
Fix from $1,950 2018-07-20
Experience Manager HIGH 7.5
CVE-2018-5006EPSS 54%

Adobe Experience Manager versions 6.4 and earlier have a Server-Side Request Forgery vulnerability. Successful exploitation could lead to sensitive i…

Fix: after 6.4.0
Fix from $1,950 2018-07-20
Finesse CRITICAL 9.8
CVE-2018-0398

Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a server-s…

Mitigation only
Fix from $2,300 2018-07-18
Finesse CRITICAL 9.8
CVE-2018-0399

Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to retrieve a clearte…

Mitigation only
Fix from $2,300 2018-07-18
Unified Contact Center Express CRITICAL 9.8
CVE-2018-0403

Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, …

Mitigation only
Fix from $2,300 2018-07-18
Concrete Cms HIGH 7.2
CVE-2018-13790

A Server Side Request Forgery (SSRF) vulnerability in tools/files/importers/remote.php in concrete5 8.2.0 can lead to attacks on the local network an…

No fix yet
Fix from $1,950 2018-07-09
Forefront Unified Access Gateway CRITICAL 9.8
CVE-2018-12571EPSS 30%

uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS queries fo…

No fix yet
Fix from $2,300 2018-07-05
Dotnetnuke HIGH 7.5
CVE-2017-0929EPSS 13%

DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able…

Fix: 9.2.0+
Fix from $1,950 2018-07-03
Urltrigger MEDIUM 6.5
CVE-2018-1000606

A server-side request forgery vulnerability exists in Jenkins URLTrigger Plugin 0.41 and earlier in URLTrigger.java that allows attackers with Overal…

Fix: after 0.41
Fix from $1,600 2018-06-26
Trovebox HIGH 8.8
CVE-2018-1000553

Trovebox version <= 4.0.0-rc6 contains a Server-Side request forgery vulnerability in webhook component that can result in read or update internal re…

Fix: after 3.0.0
Fix from $1,950 2018-06-26
Portainer CRITICAL 9.8
CVE-2018-12678

Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query parameter for the /websocket/exec en…

Fix: 1.18.0+
Fix from $2,300 2018-06-22
Open Xchange Appsuite HIGH 8.8
CVE-2018-5752

The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev…

Fix: after 7.6.3
Fix from $1,950 2018-06-16
Searchblox CRITICAL 9.8
CVE-2018-11586EPSS 15%

XML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote unauthenticated users to read arbitrary files or conduct…

No fix yet
Fix from $2,300 2018-06-05
Git MEDIUM 6.4
CVE-2018-1000182

A server-side request forgery vulnerability exists in Jenkins Git Plugin 3.9.0 and older in AssemblaWeb.java, GitBlitRepositoryBrowser.java, Gitiles.…

Fix: after 3.9.0
Fix from $1,600 2018-06-05
GitHub MEDIUM 5.4
CVE-2018-1000184

A server-side request forgery vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubPluginConfig.java that allows attackers with Ov…

Fix: after 1.29.0
Fix from $1,600 2018-06-05
Cas MEDIUM 5.4
CVE-2018-1000188

A server-side request forgery vulnerability exists in Jenkins CAS Plugin 1.4.1 and older in CasSecurityRealm.java that allows attackers with Overall/…

Fix: after 1.4.1
Fix from $1,600 2018-06-05
Smartforms MEDIUM 6.5
CVE-2018-9920

Server side request forgery exists in the runtime application in K2 smartforms 4.6.11 via a modified hostname in an https://*/Identity/STS/Forms/Scri…

Mitigation only
Fix from $1,600 2018-05-24
Phprap CRITICAL 9.8
CVE-2018-11031

application/home/controller/debug.php in PHPRAP 1.0.4 through 1.0.8 has SSRF via the /debug URI, as demonstrated by an api[url]=file:////etc/passwd&a…

Fix: after 1.0.8
Fix from $2,300 2018-05-14
Tp Shop CRITICAL 9.8
CVE-2018-9919

A web-accessible backdoor, with resultant SSRF, exists in Tp-shop 2.0.5 through 2.0.8, which allows remote attackers to obtain sensitive information,…

Fix: after 2.0.8
Fix from $2,300 2018-05-02
Cockpit CRITICAL 9.1
CVE-2018-9302EPSS 9%

SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary files or send T…

Fix: after 0.5.5
Fix from $2,300 2018-05-02
Whatsup Gold CRITICAL 9.8
CVE-2018-8939

An SSRF issue was discovered in NmAPI.exe in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can submit specially crafted requests via the…

Fix: 18.0+
Fix from $2,300 2018-05-01
GitLab MEDIUM 6.5
CVE-2018-8801

GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component.

Fix: 10.3+
Fix from $1,600 2018-04-25
Management Console MEDIUM 6.5
CVE-2018-10174

Digital Guardian Management Console 7.1.2.0015 has an SSRF issue that allows remote attackers to read arbitrary files via file:// URLs, send TCP traf…

No fix yet
Fix from $1,600 2018-04-20
Glastopf HIGH 8.8
CVE-2018-10220

Glastopf 3.1.3-dev has SSRF, as demonstrated by the abc.php a parameter. NOTE: the vendor indicates that this is intentional behavior because the pro…

No fix yet
Fix from $1,950 2018-04-19
Onethink CRITICAL 9.8
CVE-2017-14323

SSRF (Server Side Request Forgery) in getRemoteImage.php in Ueditor in Onethink V1.0 and V1.1 allows remote attackers to obtain sensitive information…

No fix yet
Fix from $2,300 2018-04-10
Cockpit CRITICAL 9.1
CVE-2017-14611

SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the ur…

No fix yet
Fix from $2,300 2018-04-10
Application Links HIGH 7.2
CVE-2017-18096

The OAuth status rest resource in Atlassian Application Links before version 5.2.7, from 5.3.0 before 5.3.4 and from 5.4.0 before 5.4.3 allows remote…

Fix: 5.2.7 / 5.3.4+
Fix from $1,950 2018-04-04
Tpshop CRITICAL 9.8
CVE-2017-16614

SSRF (Server Side Request Forgery) in tpshop 2.0.5 and 2.0.6 allows remote attackers to obtain sensitive information, attack intranet hosts, or possi…

Mitigation only
Fix from $2,300 2018-03-30
I\, Librarian CRITICAL 9.1
CVE-2018-1000138

I, Librarian version 4.8 and earlier contains a SSRF vulnerability in "url" parameter of getFromWeb in functions.php that can result in the attacker …

Fix: after 4.8
Fix from $2,300 2018-03-23
G Cam\/efd 2250 Firmware HIGH 7.3
CVE-2018-7516

A server-side request forgery vulnerability has been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 I…

Mitigation only
Fix from $1,950 2018-03-22