Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2023-24060
Haven 5d15944 allows Server-Side Request Forgery (SSRF) via the feed[url]= Feeds functionality. Authenticated users with the ability to create new RS…
Haven
No fix yet
MEDIUM 6.5
CVE-2023-24495
A Server Side Request Forgery (SSRF) vulnerability exists in Tenable.sc due to improper validation of session & user-accessible input data. A privile…
Tenable.sc
after 5.23.1
CRITICAL 9.8
CVE-2022-46998
An issue in the website background of taocms v3.0.2 allows attackers to execute a Server-Side Request Forgery (SSRF).
Taocms
No fix yet
CRITICAL 9.8
CVE-2023-23560EPSS 14%
In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.
B2236 Firmware
No fix yet
HIGH 8.1
CVE-2021-43449
ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Server-Side Request Forgery (SSRF). The document editor service can be abused to read and s…
Server
after 7.0.0.49
MEDIUM 6.5
CVE-2021-37498
An SSRF issue was discovered in Reprise License Manager (RLM) web interface through 14.2BL4 that allows remote attackers to trigger outbound requests…
Reprise License Manager
17.0+
HIGH 8.8
CVE-2022-45926EPSS 17%
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The endpoint notify.localizeEmailTemplate allows a low-privilege user…
Opentext Extended Ecm
after 22.3
HIGH 7.5
CVE-2023-22493
RSSHub is an open source RSS feed generator. RSSHub is vulnerable to Server-Side Request Forgery (SSRF) attacks. This vulnerability allows an attacke…
Rsshub
2023-01-10+
HIGH 7.8
CVE-2022-3841
RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Re…
Advanced Cluster Management For Kubernetes
Mitigation only
HIGH 7.5
CVE-2022-25026EPSS 24%
A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on the interna…
Trufusion Enterprise
7.9.5.1+
HIGH 7.5
CVE-2023-21761
Microsoft Exchange Server Information Disclosure Vulnerability
Exchange Server
No fix yet
CRITICAL 9.8
CVE-2022-39039
aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this vulnerability to send arbitr…
A\+hrd
Mitigation only
MEDIUM 5.3
CVE-2022-45027
perfSONAR before 4.4.6, when performing participant discovery, incorrectly uses an HTTP request header value to determine a local address.
Perfsonar
4.4.6+
CRITICAL 9.8
CVE-2017-20157
A vulnerability was found in Ariadne Component Library up to 2.x. It has been classified as critical. Affected is an unknown function of the file src…
Ariadne Component Library
3.0+
HIGH 7.5
CVE-2022-38211
Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.9.1 and below were not fully h…
Portal For Arcgis
after 10.9.1
HIGH 7.5
CVE-2022-38212
Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.8.1 and below were not fully h…
Portal For Arcgis
after 10.8.1
HIGH 7.5
CVE-2022-38203
Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.8.1 and below were not fully h…
Portal For Arcgis
after 10.8.1
MEDIUM 6.1
CVE-2022-23544
MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. V…
Metersphere
2.5.0+
HIGH 7.5
CVE-2022-45429
Some Dahua software products have a vulnerability of server-side request forgery (SSRF). An Attacker can access internal resources by concatenating l…
Dss Express
Patch available
CRITICAL 9.8
CVE-2022-4725
A vulnerability was found in AWS SDK 2.59.0. It has been rated as critical. This issue affects the function XpathUtils of the file aws-android-sdk-co…
Aws Software Development Kit
2.59.1+
MEDIUM 5.3
CVE-2022-37313
OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record.
Open Xchange Appsuite
7.10.5+
MEDIUM 5.3
CVE-2022-3189
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specially crafted PHP script could use parameters from a HTTP …
Iboot Pdu4 N20 Firmware
1.42.06162022+
CRITICAL 9.8
CVE-2022-47635
Wildix WMS 6 before 6.02.20221216, WMS 5 before 5.04.20221214, and WMS4 before 4.04.45396.23 allows Server-side request forgery (SSRF) via ZohoClient…
Wms
4.04.45396.23 / 5.04.20221214+
CRITICAL 9.1
CVE-2022-38708
IBM Cognos Analytics 11.1.7 11.2.0, and 11.2.1 could be vulnerable to a Server-Side Request Forgery Attack (SSRF) attack by constructing URLs from us…
Cognos Analytics
after 11.2.3
MEDIUM 6.5
CVE-2022-42343
Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead…
Campaign
7.3.2 / 8.4.2+
CRITICAL 9.8
CVE-2022-46364
A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attack…
Cxf
3.4.10 / 3.5.5+
MEDIUM 5.3
CVE-2022-46830
In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.
Teamcity
after 2022.10.1
CRITICAL 9.8
CVE-2022-35508
Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF when proxying HTTP requests between pve(pmg)proxy and pve(pmg…
Proxmox Mail Gateway
4.1-3+
HIGH 8.6
CVE-2022-41412
An issue in the graphData.cgi component of perfSONAR v4.4.5 and prior allows attackers to access sensitive data and execute Server-Side Request Forge…
Perfsonar
4.4.5+
CRITICAL 9.1
CVE-2022-45152
A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input …
Moodle
3.9.18 / 3.11.11+