Vulnerability index

Browse CVEs

2,859 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Tealeaf Customer Experience MEDIUM 5.3
CVE-2016-5968

The Replay Server in IBM Tealeaf Customer Experience 8.x before 8.7.1.8847 FP10, 8.8.x before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, …

Fix: after 8.6
Fix from $1,600 2016-11-25
Dokuwiki HIGH 8.6
CVE-2016-7964

The sendRequest method in HTTPClient Class in file /inc/HTTPClient.php in DokuWiki 2016-06-26a and older, when media file fetching is enabled, has no…

Patch available
Fix from $1,950 2016-10-31
Vbulletin HIGH 8.6
CVE-2016-6483EPSS 12%

The media-file upload feature in vBulletin before 3.8.7 Patch Level 6, 3.8.8 before Patch Level 2, 3.8.9 before Patch Level 1, 4.x before 4.2.2 Patch…

Patch available
Fix from $1,950 2016-09-02
Release Control HIGH 7.7
CVE-2016-4374

HPE Release Control (RC) 9.13, 9.20, and 9.21 before 9.21.0005 p4 allows remote authenticated users to conduct server-side request forgery (SSRF) att…

Patch available
Fix from $1,950 2016-08-08
WordPress HIGH 8.6
CVE-2016-4029

WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers t…

Fix: 4.5+
Fix from $1,950 2016-08-07
Enterprise Linux Desktop MEDIUM 5.5
CVE-2016-3718 KEVEPSS 77%

The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (…

Patch available
Fix from $1,600 2016-05-05
Fedora MEDIUM 6.5
CVE-2010-1637

The Mail Fetch plugin in SquirrelMail 1.4.20 and earlier allows remote authenticated users to bypass firewall restrictions and use SquirrelMail as a …

Fix: 10.6.8+
Fix from $1,600 2010-06-22
Risearch CRITICAL 9.8
CVE-2004-2061EPSS 6%

RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting…

No fix yet
Fix from $2,300 2004-07-27
Db4web CRITICAL 9.8
CVE-2002-1484EPSS 14%

DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other s…

Patch available
Fix from $2,300 2003-04-22