Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 7.2 CVE-2022-2352 The Post SMTP Mailer/Email Log WordPress plugin before 2.1.7 does not have proper authorisation in some AJAX actions, which could allow high privileg… Post Smtp 2.1.7+ Fix from $1,9502022-09-26 HIGH 7.5 CVE-2022-23464 Nepxion Discovery is a solution for Spring Cloud. Discovery is vulnerable to a potential Server-Side Request Forgery (SSRF). RouterResourceImpl uses … Discovery after 6.16.2 Fix from $1,9502022-09-24 MEDIUM 5.4 CVE-2022-39239 netlify-ipx is an on-Demand image optimization for Netlify using ipx. In versions prior to 1.2.3, an attacker can bypass the source image domain allo… Netlify Ipx 1.2.3+ Fix from $1,6002022-09-23 MEDIUM 5.3 CVE-2022-38398 Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue a… Batik Mitigation only Fix from $1,6002022-09-22 MEDIUM 5.3 CVE-2022-38648 Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects A… Batik Mitigation only Fix from $1,6002022-09-22 HIGH 7.5 CVE-2022-40146EPSS 6% Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affec… Batik Mitigation only Fix from $1,9502022-09-22 CRITICAL 9.8 CVE-2022-40357 A security issue was discovered in Z-BlogPHP <= 1.7.2. A Server-Side Request Forgery (SSRF) vulnerability in the zb_users/plugin/UEditor/php/action_c… Z Blogphp after 1.7.2 Fix from $2,3002022-09-20 HIGH 8.8 CVE-2022-38931 A Server-Side Request Forgery (SSRF) in fetch_net_file_upload function of baijiacmsV4 v4.1.4 allows remote attackers to force the application to make… Baijiacms No fix yet Fix from $1,9502022-09-20 HIGH 8.4 CVE-2022-30579 The Web Player component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a difficul… Spotfire Analytics Platform Mitigation only Fix from $1,9502022-09-20 MEDIUM 5.3 CVE-2022-39211 Nextcloud server is an open source personal cloud platform. In affected versions it was found that locally running webservices can be found and reque… Nextcloud Enterprise Server 22.2.10.4 / 23.0.8+ Fix from $1,6002022-09-16 MEDIUM 5.8 CVE-2022-36112 GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk featu… Glpi 10.0.3+ Fix from $1,6002022-09-14 CRITICAL 9.1 CVE-2022-2900 Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 8.1.0. Parse Url 8.1.0+ Fix from $2,3002022-09-14 HIGH 8.8 CVE-2022-38298 Appsmith v1.7.11 was discovered to allow attackers to execute an authenticated Server-Side Request Forgery (SSRF) via redirecting incoming requests t… Appsmith Patch available Fix from $1,9502022-09-12 CRITICAL 9.8 CVE-2022-38292 SLiMS Senayan Library Management System v9.4.2 was discovered to contain multiple Server-Side Request Forgeries via the components /bibliography/marc… Senayan Library Management System No fix yet Fix from $2,3002022-09-12 CRITICAL 9.8 CVE-2022-36376 Server-Side Request Forgery (SSRF) vulnerability in Rank Math SEO plugin <= 1.0.95 at WordPress. Seo after 1.0.95 Fix from $2,3002022-09-09 CRITICAL 9.8 CVE-2022-40305 A Server-Side Request Forgery issue in Canto Cumulus through 11.1.3 allows attackers to enumerate the internal network, overload network resources, a… Canto after 11.1.3 Fix from $2,3002022-09-09 CRITICAL 9.8 CVE-2022-36663 Gluu Oxauth before v4.4.1 allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted request_uri parameter. Oxauth 4.4.1+ Fix from $2,3002022-09-06 HIGH 7.5 CVE-2022-31196 Databasir is a database metadata management platform. Databasir <= 1.06 has Server-Side Request Forgery (SSRF) vulnerability. The SSRF is triggered b… Databasir 1.0.7+ Fix from $1,9502022-09-02 CRITICAL 9.8 CVE-2021-27693 Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage. Publiccms 4.0.202011.b+ Fix from $2,3002022-09-02 CRITICAL 9.8 CVE-2022-35583EPSS 15% wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial… Wkhtmltopdf No fix yet Fix from $2,3002022-08-22 HIGH 7.5 CVE-2022-38187 Prior to version 10.9.0, the sharing/rest/content/features/analyze endpoint is always accessible to anonymous users, which could allow an unauthentic… Portal For Arcgis 10.9+ Fix from $1,9502022-08-15 HIGH 7.5 CVE-2020-23622 An issue in the UPnP protocol in 4thline cling 2.0.0 through 2.1.2 allows remote attackers to cause a denial of service via an unchecked CALLBACK par… Cling after 2.1.2 Fix from $1,9502022-08-15 CRITICAL 9.8 CVE-2022-35949 undici is an HTTP/1.1 client, written from scratch for Node.js.`undici` is vulnerable to SSRF (Server-side Request Forgery) when an application takes… Undici after 5.8.1 Fix from $2,3002022-08-12 HIGH 7.5 CVE-2022-37041 An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. The value of the X-Forwarded-H… Collaboration Patch available Fix from $1,9502022-08-12 MEDIUM 6.5 CVE-2022-2756 Server-Side Request Forgery (SSRF) in GitHub repository kareadita/kavita prior to 0.5.4.1. Kavita 0.5.4.1+ Fix from $1,6002022-08-10 CRITICAL 9.8 CVE-2022-31132 Nextcloud Mail is an email application for the nextcloud personal cloud product. Affected versions shipped with a CSS minifier on the path `./vendor/… Mail 1.12.8 / 1.13.6+ Fix from $2,3002022-08-04 CRITICAL 9.8 CVE-2022-31188EPSS 49% CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were found to be subject to a Server-s… Computer Vision Annotation Tool 2.0.0+ Fix from $2,3002022-08-01 HIGH 8.8 CVE-2022-31776 IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to server-side… Datapower Gateway 10.5.0.1+ Fix from $1,9502022-08-01 HIGH 8.8 CVE-2022-36997 An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and rel… Flex Appliance Patch available Fix from $1,9502022-07-28 MEDIUM 5.7 CVE-2021-43959 Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to access the content of internal … Jira Service Desk 4.13.20 / 4.20.8+ Fix from $1,6002022-07-26