Vulnerability index

Browse CVEs

2,859 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Pixie Image Editor CRITICAL 10.0
CVE-2017-12905

Server Side Request Forgery vulnerability in Vebto Pixie Image Editor 1.4 and 1.7 allows remote attackers to disclose information or execute arbitrar…

Mitigation only
Fix from $2,300 2017-09-25
Photo Station MEDIUM 6.5
CVE-2017-12071

Server-side request forgery (SSRF) vulnerability in file_upload.php in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authentica…

Fix: after 6.7.3-3432
Fix from $1,600 2017-09-08
Pan Os CRITICAL 9.8
CVE-2017-9458

XML external entity (XXE) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.…

Fix: after 6.1.17
Fix from $2,300 2017-09-07
Oauth MEDIUM 6.1
CVE-2017-9506EPSS 72%

The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote a…

No fix yet
Fix from $1,600 2017-08-23
Download Station MEDIUM 6.5
CVE-2017-11149

Server-side request forgery (SSRF) vulnerability in Downloader in Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 allows re…

Mitigation only
Fix from $1,600 2017-08-14
Chat MEDIUM 6.5
CVE-2017-11148

Server-side request forgery (SSRF) vulnerability in link preview in Synology Chat before 1.1.0-0806 allows remote authenticated users to access intra…

Fix: after 1.0.2-0159
Fix from $1,600 2017-08-11
phpMyAdmin HIGH 8.8
CVE-2017-1000017

phpMyAdmin 4.0, 4.4 and 4.6 are vulnerable to a weakness where a user with appropriate permissions is able to connect to an arbitrary MySQL server

Fix: 4.0.10.19+
Fix from $1,950 2017-07-17
Finecms MEDIUM 6.5
CVE-2017-10973

In FineCMS before 2017-07-06, application/lib/ajax/get_image_data.php has SSRF, related to requests for non-image files with a modified HTTP Host hea…

Fix: after 2017-05-12
Fix from $1,600 2017-07-06
Gecko Lite Managed Switch Firmware MEDIUM 6.5
CVE-2017-6036

A Server-Side Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web server …

Fix: after 2.0.00
Fix from $1,600 2017-06-30
Subsonic HIGH 7.4
CVE-2017-9355EPSS 27%

XML external entity (XXE) vulnerability in the import playlist feature in Subsonic 6.1.1 might allow remote attackers to conduct server-side request …

No fix yet
Fix from $1,950 2017-06-07
Allen Disk MEDIUM 6.5
CVE-2017-9307

SSRF vulnerability in remotedownload.php in Allen Disk 1.6 allows remote authenticated users to conduct port scans and access intranet servers via a …

Mitigation only
Fix from $1,600 2017-05-31
WordPress HIGH 8.6
CVE-2017-9066

In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.

Fix: after 4.7.4
Fix from $1,950 2017-05-18
File Transfer Appliance CRITICAL 10.0
CVE-2017-8794

An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because a regular expression (intended to match local https URLs) lacks an init…

Fix: after 9_12_40
Fix from $2,300 2017-05-05
Peoplesoft Enterprise Peopletools MEDIUM 6.5
CVE-2017-3546EPSS 10%

Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: MultiChannel Framework). Supported vers…

Patch available
Fix from $1,600 2017-04-24
Yeager Cms HIGH 7.2
CVE-2015-7570EPSS 6%

Multiple server-side request forgery (SSRF) vulnerabilities in Yeager CMS 1.2.1 allow remote attackers to trigger outbound requests and enumerate ope…

Patch available
Fix from $1,950 2017-04-24
Jackson Dataformat Xml HIGH 8.6
CVE-2016-7051

XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct…

Fix: 2.7.8+
Fix from $1,950 2017-04-14
Vbulletin HIGH 8.6
CVE-2017-7569

In vBulletin before 5.3.0, remote attackers can bypass the CVE-2016-6483 patch and conduct SSRF attacks by leveraging the behavior of the PHP parse_u…

Fix: after 5.2.6
Fix from $1,950 2017-04-06
Mybb HIGH 7.7
CVE-2017-7566

MyBB before 1.8.11 allows remote attackers to bypass an SSRF protection mechanism.

Fix: after 1.8.10
Fix from $1,950 2017-04-06
Ssl Intercept Iapp HIGH 7.4
CVE-2017-6130

F5 SSL Intercept iApp 1.5.0 - 1.5.7 and SSL Orchestrator 2.0 is vulnerable to a Server-Side Request Forgery (SSRF) attack when deployed using the Dyn…

Mitigation only
Fix from $1,950 2017-04-06
PHP HIGH 7.4
CVE-2017-7272

PHP through 7.1.11 enables potential SSRF in applications that accept an fsockopen or pfsockopen hostname argument with an expectation that the port …

Fix: after 7.1.3
Fix from $1,950 2017-03-27
Glance MEDIUM 5.8
CVE-2017-7200

An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform ma…

Mitigation only
Fix from $1,600 2017-03-21
Debian Linux HIGH 7.4
CVE-2017-5617

The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attackers to conduct server-side request forgery (SSRF)…

Patch available
Fix from $1,950 2017-03-16
Camel HIGH 7.4
CVE-2017-5643EPSS 6%

Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.

Fix: after 2.16.0
Fix from $1,950 2017-03-16
Umbraco HIGH 8.2
CVE-2015-8813EPSS 11%

The Page_Load function in Umbraco.Web/umbraco.presentation/umbraco/dashboard/FeedProxy.aspx.cs in Umbraco before 7.4.0 allows remote attackers to con…

Fix: after 7.3.8
Fix from $1,950 2017-03-03
Merge System HIGH 7.4
CVE-2016-9417

The fetch_remote_file function in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to conduct serve…

Fix: after 1.8.7
Fix from $1,950 2017-01-31
phpMyAdmin HIGH 8.6
CVE-2016-6621

The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15.10, and 4.6.x before 4.6.6 allows remote attackers to conduct server-side reque…

Fix: after 4.0.10.18
Fix from $1,950 2017-01-31
Spip HIGH 7.4
CVE-2016-7999

ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to conduct server side request forgery (SSRF) attacks via a URL in the …

Fix: after 3.1.2
Fix from $1,950 2017-01-18
Genixcms HIGH 7.4
CVE-2017-5518

The media-file upload feature in GeniXCMS through 0.0.8 allows remote attackers to conduct SSRF attacks via a URL, as demonstrated by a URL with an i…

Fix: after 0.0.8
Fix from $1,950 2017-01-17
Open Xchange Appsuite MEDIUM 5.8
CVE-2016-4046

An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. The API to configure external mail accounts can be abused to map and access …

Fix: after 7.8.1
Fix from $1,600 2016-12-15
Serendipity HIGH 8.6
CVE-2016-9752

In Serendipity before 2.0.5, an attacker can bypass SSRF protection by using a malformed IP address (e.g., http://127.1) or a 30x (aka Redirection) H…

Fix: after 2.0.4
Fix from $1,950 2016-12-01