Vulnerability index

Browse CVEs

2,859 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Opencart CRITICAL 9.8
CVE-2014-3990EPSS 7%

The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to conduct server-side request forger…

Fix: after 1.5.6.4
Fix from $2,300 2018-03-20
I\, Librarian CRITICAL 10.0
CVE-2018-1000124

I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_s…

Fix: after 4.8
Fix from $2,300 2018-03-13
Adminer CRITICAL 9.8
CVE-2018-7667

Adminer through 4.3.1 has SSRF via the server parameter.

Fix: after 4.3.1
Fix from $2,300 2018-03-05
Jenkins MEDIUM 5.3
CVE-2018-1000067

An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to have Jen…

Fix: after 2.106
Fix from $1,600 2018-02-16
Roomwizard Firmware HIGH 7.5
CVE-2018-7055

GroupViewProxyServlet in RoomWizard before 4.4.x allows SSRF via the url parameter.

Fix: 4.4.0+
Fix from $1,950 2018-02-15
Bi Launchpad MEDIUM 5.3
CVE-2018-2370

Server Side Request Forgery (SSRF) vulnerability in SAP Central Management Console, BI Launchpad and Fiori BI Launchpad, 4.10, from 4.20, from 4.30, …

Mitigation only
Fix from $1,600 2018-02-14
Junit HIGH 8.3
CVE-2018-1000056

Jenkins JUnit Plugin 1.23 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user p…

Fix: after 1.23
Fix from $1,950 2018-02-09
Ccm HIGH 8.3
CVE-2018-1000054

Jenkins CCM Plugin 3.1 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user perm…

Fix: after 3.1
Fix from $1,950 2018-02-09
Android Lint HIGH 8.3
CVE-2018-1000055

Jenkins Android Lint Plugin 2.5 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with …

Fix: after 2.5
Fix from $1,950 2018-02-09
Sandstorm HIGH 8.1
CVE-2017-6201

A Server Side Request Forgery vulnerability exists in the install app process in Sandstorm before build 0.203. A remote attacker may exploit this iss…

Fix: 0.203+
Fix from $1,950 2018-02-06
Netscaler HIGH 8.8
CVE-2018-6186

Citrix NetScaler VPX through NS12.0 53.13.nc allows an SSRF attack via the /rapi/read_url URI by an authenticated attacker who has a webapp account. …

Mitigation only
Fix from $1,950 2018-02-01
Nonecms HIGH 7.5
CVE-2018-6029

The copy function in application/admin/controller/Article.php in NoneCms 1.3.0 allows remote attackers to access the content of internal and external…

No fix yet
Fix from $1,950 2018-01-23
Moodle MEDIUM 6.5
CVE-2018-1042EPSS 16%

Moodle 3.x has Server Side Request Forgery in the filepicker.

Fix: after 3.1.9
Fix from $1,600 2018-01-22
Jira MEDIUM 5.3
CVE-2017-16865

The Trello importer in Atlassian Jira before version 7.6.1 allows remote attackers to access the content of internal network resources via a Server S…

Fix: 7.6.1+
Fix from $1,600 2018-01-17
Phpbb HIGH 7.5
CVE-2017-1000419

phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting internal …

No fix yet
Fix from $1,950 2018-01-02
Chat MEDIUM 6.5
CVE-2017-15886

Server-side request forgery (SSRF) vulnerability in Link Preview in Synology Chat before 2.0.0-1124 allows remote authenticated users to download arb…

Fix: 2.0.0-1124+
Fix from $1,600 2017-12-28
Harbor HIGH 8.6
CVE-2017-17697

The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/ping.

Fix: 1.3.0+
Fix from $1,950 2017-12-15
Pan Os MEDIUM 5.3
CVE-2017-15943

The configuration file import for applications, spyware and vulnerability objects functionality in the web interface in Palo Alto Networks PAN-OS bef…

Fix: 6.1.19 / 7.0.19+
Fix from $1,600 2017-12-11
Connect CRITICAL 10.0
CVE-2017-11291EPSS 6%

An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A Server-Side Request Forgery (SSRF) vulnerability exists that could be abused t…

Fix: after 9.6.2
Fix from $2,300 2017-12-09
Hipchat Data Center HIGH 7.2
CVE-2017-14585

A Server Side Request Forgery (SSRF) vulnerability could lead to remote code execution for authenticated administrators. This issue was introduced in…

Fix: 2.2.6 / 3.1.0+
Fix from $1,950 2017-11-27
Vcenter Server HIGH 7.5
CVE-2017-4928

The flash-based vSphere Web Client (6.0 prior to 6.0 U3c and 5.5 prior to 5.5 U3f) i.e. not the new HTML5-based vSphere Client, contains SSRF and CRL…

Patch available
Fix from $1,950 2017-11-17
Updraftplus HIGH 8.1
CVE-2017-16870

The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugins/updraftplus/admin.php via a…

Fix: after 1.13.12
Fix from $1,950 2017-11-17
I\, Librarian CRITICAL 9.8
CVE-2017-1000237

I, Librarian version <=4.6 & 4.7 is vulnerable to Server-Side Request Forgery in the ajaxsupplement.php resulting in the attacker being able to reset…

Fix: after 4.6
Fix from $2,300 2017-11-17
Paperclip CRITICAL 9.8
CVE-2017-0889

Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter class. Attack…

Fix: 5.2.0+
Fix from $2,300 2017-11-13
Recurly Client Ruby CRITICAL 9.8
CVE-2017-0905

The Recurly Client Ruby Library before 2.0.13, 2.1.11, 2.2.5, 2.3.10, 2.4.11, 2.5.4, 2.6.3, 2.7.8, 2.8.2, 2.9.2, 2.10.4, 2.11.3 is vulnerable to a Se…

Patch available
Fix from $2,300 2017-11-13
Recurly Client Python CRITICAL 9.8
CVE-2017-0906

The Recurly Client Python Library before 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1, 2.6.2 is vulnerable to a Server-Side Request Forgery vulnerabili…

Fix: after 2.4.4
Fix from $2,300 2017-11-13
Recurly Client .net CRITICAL 9.8
CVE-2017-0907

The Recurly Client .NET Library before 1.0.1, 1.1.10, 1.2.8, 1.3.2, 1.4.14, 1.5.3, 1.6.2, 1.7.1, 1.8.1 is vulnerable to a Server-Side Request Forgery…

Patch available
Fix from $2,300 2017-11-13
Mahara HIGH 8.0
CVE-2017-1000139

Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to server-side request forgery attacks as…

Patch available
Fix from $1,950 2017-11-03
Webmin HIGH 8.6
CVE-2017-15644EPSS 9%

SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:8000.

Fix: after 1.850
Fix from $1,950 2017-10-19
Mobile Application Platform MEDIUM 6.3
CVE-2017-7553

The external_request api call in App Studio (millicore) allows server side request forgery (SSRF). An attacker could use this flaw to probe the netwo…

Fix: after 4.4.3
Fix from $1,600 2017-09-29