Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 5.0 CVE-2023-24060 Haven 5d15944 allows Server-Side Request Forgery (SSRF) via the feed[url]= Feeds functionality. Authenticated users with the ability to create new RS… Haven No fix yet Fix from $1,6002023-01-27 MEDIUM 6.5 CVE-2023-24495 A Server Side Request Forgery (SSRF) vulnerability exists in Tenable.sc due to improper validation of session & user-accessible input data. A privile… Tenable.sc after 5.23.1 Fix from $1,6002023-01-26 CRITICAL 9.8 CVE-2022-46998 An issue in the website background of taocms v3.0.2 allows attackers to execute a Server-Side Request Forgery (SSRF). Taocms No fix yet Fix from $2,3002023-01-26 CRITICAL 9.8 CVE-2023-23560EPSS 14% In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation. B2236 Firmware No fix yet Fix from $2,3002023-01-23 HIGH 8.1 CVE-2021-43449 ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Server-Side Request Forgery (SSRF). The document editor service can be abused to read and s… Server after 7.0.0.49 Fix from $1,9502023-01-23 MEDIUM 6.5 CVE-2021-37498 An SSRF issue was discovered in Reprise License Manager (RLM) web interface through 14.2BL4 that allows remote attackers to trigger outbound requests… Reprise License Manager 17.0+ Fix from $1,6002023-01-20 HIGH 8.8 CVE-2022-45926EPSS 17% An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The endpoint notify.localizeEmailTemplate allows a low-privilege user… Opentext Extended Ecm after 22.3 Fix from $1,9502023-01-18 HIGH 7.5 CVE-2023-22493 RSSHub is an open source RSS feed generator. RSSHub is vulnerable to Server-Side Request Forgery (SSRF) attacks. This vulnerability allows an attacke… Rsshub 2023-01-10+ Fix from $1,9502023-01-13 HIGH 7.8 CVE-2022-3841 RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Re… Advanced Cluster Management For Kubernetes Mitigation only Fix from $1,9502023-01-13 HIGH 7.5 CVE-2022-25026EPSS 24% A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on the interna… Trufusion Enterprise 7.9.5.1+ Fix from $1,9502023-01-12 HIGH 7.5 CVE-2023-21761 Microsoft Exchange Server Information Disclosure Vulnerability Exchange Server No fix yet Fix from $1,9502023-01-10 CRITICAL 9.8 CVE-2022-39039 aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this vulnerability to send arbitr… A\+hrd Mitigation only Fix from $2,3002023-01-03 MEDIUM 5.3 CVE-2022-45027 perfSONAR before 4.4.6, when performing participant discovery, incorrectly uses an HTTP request header value to determine a local address. Perfsonar 4.4.6+ Fix from $1,6002023-01-01 CRITICAL 9.8 CVE-2017-20157 A vulnerability was found in Ariadne Component Library up to 2.x. It has been classified as critical. Affected is an unknown function of the file src… Ariadne Component Library 3.0+ Fix from $2,3002022-12-31 HIGH 7.5 CVE-2022-38211 Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.9.1 and below were not fully h… Portal For Arcgis after 10.9.1 Fix from $1,9502022-12-29 HIGH 7.5 CVE-2022-38212 Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.8.1 and below were not fully h… Portal For Arcgis after 10.8.1 Fix from $1,9502022-12-29 HIGH 7.5 CVE-2022-38203 Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.8.1 and below were not fully h… Portal For Arcgis after 10.8.1 Fix from $1,9502022-12-29 MEDIUM 6.1 CVE-2022-23544 MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. V… Metersphere 2.5.0+ Fix from $1,6002022-12-28 HIGH 7.5 CVE-2022-45429 Some Dahua software products have a vulnerability of server-side request forgery (SSRF). An Attacker can access internal resources by concatenating l… Dss Express Patch available Fix from $1,9502022-12-27 CRITICAL 9.8 CVE-2022-4725 A vulnerability was found in AWS SDK 2.59.0. It has been rated as critical. This issue affects the function XpathUtils of the file aws-android-sdk-co… Aws Software Development Kit 2.59.1+ Fix from $2,3002022-12-27 MEDIUM 5.3 CVE-2022-37313 OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record. Open Xchange Appsuite 7.10.5+ Fix from $1,6002022-12-26 MEDIUM 5.3 CVE-2022-3189 Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specially crafted PHP script could use parameters from a HTTP … Iboot Pdu4 N20 Firmware 1.42.06162022+ Fix from $1,6002022-12-21 CRITICAL 9.8 CVE-2022-47635 Wildix WMS 6 before 6.02.20221216, WMS 5 before 5.04.20221214, and WMS4 before 4.04.45396.23 allows Server-side request forgery (SSRF) via ZohoClient… Wms 4.04.45396.23 / 5.04.20221214+ Fix from $2,3002022-12-21 CRITICAL 9.1 CVE-2022-38708 IBM Cognos Analytics 11.1.7 11.2.0, and 11.2.1 could be vulnerable to a Server-Side Request Forgery Attack (SSRF) attack by constructing URLs from us… Cognos Analytics after 11.2.3 Fix from $2,3002022-12-19 MEDIUM 6.5 CVE-2022-42343 Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead… Campaign 7.3.2 / 8.4.2+ Fix from $1,6002022-12-16 CRITICAL 9.8 CVE-2022-46364 A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attack… Cxf 3.4.10 / 3.5.5+ Fix from $2,3002022-12-13 MEDIUM 5.3 CVE-2022-46830 In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning. Teamcity after 2022.10.1 Fix from $1,6002022-12-08 CRITICAL 9.8 CVE-2022-35508 Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF when proxying HTTP requests between pve(pmg)proxy and pve(pmg… Proxmox Mail Gateway 4.1-3+ Fix from $2,3002022-12-04 HIGH 8.6 CVE-2022-41412 An issue in the graphData.cgi component of perfSONAR v4.4.5 and prior allows attackers to access sensitive data and execute Server-Side Request Forge… Perfsonar 4.4.5+ Fix from $1,9502022-11-30 CRITICAL 9.1 CVE-2022-45152 A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input … Moodle 3.9.18 / 3.11.11+ Fix from $2,3002022-11-25