Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
CRITICAL 9.8 CVE-2023-1725 Server-Side Request Forgery (SSRF) vulnerability in Infoline Project Management System allows Server Side Request Forgery. This issue affects Projec… Project Management System 4.09.31.125+ Fix from $2,3002023-03-30 HIGH 8.1 CVE-2023-25195 Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache Fineract. Authorized users with limited permissions can gain ac… Fineract after 1.8.3 Fix from $1,9502023-03-28 HIGH 7.5 CVE-2023-25262 Stimulsoft GmbH Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Server Side Request Forgery (SSRF). TThe Reporting Designer (Web) offers the poss… Designer No fix yet Fix from $1,9502023-03-28 CRITICAL 9.8 CVE-2023-1634 A vulnerability was found in OTCMS 6.72. It has been classified as critical. Affected is the function UseCurl of the file /admin/info_deal.php of the… Otcms No fix yet Fix from $2,3002023-03-25 HIGH 7.1 CVE-2023-27586 CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to external hosts when processing… Cairosvg 2.7.0+ Fix from $1,9502023-03-20 HIGH 8.1 CVE-2023-28112 Discourse is an open-source discussion platform. Prior to version 3.1.0.beta3 of the `beta` and `tests-passed` branches, some user provided URLs were… Discourse 3.1.0+ Fix from $1,9502023-03-17 HIGH 7.5 CVE-2023-28111 Discourse is an open-source discussion platform. Prior to version 3.1.0.beta3 of the `beta` and `tests-passed` branches, attackers are able to bypass… Discourse 3.1.0+ Fix from $1,9502023-03-17 MEDIUM 6.1 CVE-2023-28155 The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redir… Request after 2.88.1 Fix from $1,6002023-03-16 HIGH 7.5 CVE-2023-27896 In SAP BusinessObjects Business Intelligence Platform - version 420, 430, an attacker can control a malicious BOE server, forcing the application ser… Businessobjects Business Intelligence Mitigation only Fix from $1,9502023-03-14 HIGH 7.5 CVE-2023-27271 In SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, an attacker can control a malicious BOE server, forcing the… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502023-03-14 HIGH 7.4 CVE-2023-26459 Due to improper input controls In SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, … Netweaver Application Server Abap Mitigation only Fix from $1,9502023-03-14 HIGH 7.5 CVE-2023-27161 Jellyfin up to v10.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /Repositories. This vulnerability allows atta… Jellyfin after 10.7.7 Fix from $1,9502023-03-10 HIGH 7.5 CVE-2021-36396 In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF… Moodle 3.9.8 / 3.10.5+ Fix from $1,9502023-03-06 CRITICAL 9.8 CVE-2022-46973 Report v0.9.8.6 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability. Aj Report No fix yet Fix from $2,3002023-03-03 HIGH 7.5 CVE-2023-26492 Directus is a real-time API and App dashboard for managing SQL database content. Directus is vulnerable to Server-Side Request Forgery (SSRF) when im… Directus 9.23.0+ Fix from $1,9502023-03-03 CRITICAL 9.8 CVE-2022-37938 Unauthenticated server side request forgery in HPE Serviceguard Manager Serviceguard For Linux Mitigation only Fix from $2,3002023-03-01 HIGH 8.8 CVE-2023-1046 A vulnerability classified as critical has been found in MuYuCMS 2.2. This affects an unknown part of the file /admin.php/update/getFile.html. The ma… Muyucms No fix yet Fix from $1,9502023-02-26 HIGH 7.5 CVE-2022-4492 The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least… Build Of Quarkus Mitigation only Fix from $1,9502023-02-23 HIGH 8.8 CVE-2021-33926 An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1, 5.1.7, 5.1.6, 5.1.5, 5.1.4, 5.1.2, 5.1… Plone No fix yet Fix from $1,9502023-02-17 MEDIUM 6.5 CVE-2022-27234 Server-side request forgery in the CVAT software maintained by Intel(R) before version 2.0.1 may allow an authenticated user to potentially enable in… Computer Vision Annotation Tool 2.0.1+ Fix from $1,6002023-02-16 MEDIUM 6.3 CVE-2023-22936 In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘search_listener’ parameter in a search allows for a blind server-side request for… Splunk 8.1.13 / 8.2.10+ Fix from $1,6002023-02-14 MEDIUM 5.3 CVE-2023-25162 Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server prior to 24.0.8 and 23.0.12 and Nex… Nextcloud Server 23.0.12 / 24.0.8+ Fix from $1,6002023-02-13 MEDIUM 6.5 CVE-2022-45085 Server-Side Request Forgery (SSRF) vulnerability in Group Arge Energy and Control Systems Smartpower Web allows : Server Side Request Forgery. This … Smartpower Web 23.01.01+ Fix from $1,6002023-02-12 CRITICAL 9.1 CVE-2023-25557 DataHub is an open-source metadata platform. The DataHub frontend acts as a proxy able to forward any REST or GraphQL requests to the backend. The go… Datahub 0.8.45+ Fix from $2,3002023-02-11 CRITICAL 9.8 CVE-2023-0574 Server-Side Request Forgery (SSRF), Improperly Controlled Modification of Dynamically-Determined Object Attributes, Improper Restriction of Excessive… Yugabytedb Managed after 2.13 Fix from $2,3002023-02-09 MEDIUM 6.5 CVE-2022-37033 In dotCMS 5.x-22.06, TempFileAPI allows a user to create a temporary file based on a passed in URL, while attempting to block any SSRF access to loca… Dotcms 21.06.12 / 22.03.4+ Fix from $1,6002023-02-01 HIGH 8.8 CVE-2022-47872 A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a crafted p… Maccms No fix yet Fix from $1,9502023-02-01 MEDIUM 5.3 CVE-2023-24622 isInList in the safeurl-python package before 1.2 for Python has an insufficiently restrictive regular expression for external domains, leading to SS… Safeurl Python No fix yet Fix from $1,6002023-01-30 HIGH 7.5 CVE-2023-24623 Paranoidhttp before 0.3.0 allows SSRF because [::] is equivalent to the 127.0.0.1 address, but does not match the filter for private addresses. Paranoidhttp 0.3.0+ Fix from $1,9502023-01-30 MEDIUM 5.3 CVE-2022-4201 A blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 allows an attacker to connect to… GitLab 15.4.6 / 15.5.5+ Fix from $1,6002023-01-27