Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2022-2352
The Post SMTP Mailer/Email Log WordPress plugin before 2.1.7 does not have proper authorisation in some AJAX actions, which could allow high privileg…
Post Smtp
2.1.7+
HIGH 7.5
CVE-2022-23464
Nepxion Discovery is a solution for Spring Cloud. Discovery is vulnerable to a potential Server-Side Request Forgery (SSRF). RouterResourceImpl uses …
Discovery
after 6.16.2
MEDIUM 5.4
CVE-2022-39239
netlify-ipx is an on-Demand image optimization for Netlify using ipx. In versions prior to 1.2.3, an attacker can bypass the source image domain allo…
Netlify Ipx
1.2.3+
MEDIUM 5.3
CVE-2022-38398
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue a…
Batik
Mitigation only
MEDIUM 5.3
CVE-2022-38648
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects A…
Batik
Mitigation only
HIGH 7.5
CVE-2022-40146EPSS 6%
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affec…
Batik
Mitigation only
CRITICAL 9.8
CVE-2022-40357
A security issue was discovered in Z-BlogPHP <= 1.7.2. A Server-Side Request Forgery (SSRF) vulnerability in the zb_users/plugin/UEditor/php/action_c…
Z Blogphp
after 1.7.2
HIGH 8.8
CVE-2022-38931
A Server-Side Request Forgery (SSRF) in fetch_net_file_upload function of baijiacmsV4 v4.1.4 allows remote attackers to force the application to make…
Baijiacms
No fix yet
HIGH 8.4
CVE-2022-30579
The Web Player component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a difficul…
Spotfire Analytics Platform
Mitigation only
MEDIUM 5.3
CVE-2022-39211
Nextcloud server is an open source personal cloud platform. In affected versions it was found that locally running webservices can be found and reque…
Nextcloud Enterprise Server
22.2.10.4 / 23.0.8+
MEDIUM 5.8
CVE-2022-36112
GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk featu…
Glpi
10.0.3+
CRITICAL 9.1
CVE-2022-2900
Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 8.1.0.
Parse Url
8.1.0+
HIGH 8.8
CVE-2022-38298
Appsmith v1.7.11 was discovered to allow attackers to execute an authenticated Server-Side Request Forgery (SSRF) via redirecting incoming requests t…
Appsmith
Patch available
CRITICAL 9.8
CVE-2022-38292
SLiMS Senayan Library Management System v9.4.2 was discovered to contain multiple Server-Side Request Forgeries via the components /bibliography/marc…
Senayan Library Management System
No fix yet
CRITICAL 9.8
CVE-2022-36376
Server-Side Request Forgery (SSRF) vulnerability in Rank Math SEO plugin <= 1.0.95 at WordPress.
Seo
after 1.0.95
CRITICAL 9.8
CVE-2022-40305
A Server-Side Request Forgery issue in Canto Cumulus through 11.1.3 allows attackers to enumerate the internal network, overload network resources, a…
Canto
after 11.1.3
CRITICAL 9.8
CVE-2022-36663
Gluu Oxauth before v4.4.1 allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted request_uri parameter.
Oxauth
4.4.1+
HIGH 7.5
CVE-2022-31196
Databasir is a database metadata management platform. Databasir <= 1.06 has Server-Side Request Forgery (SSRF) vulnerability. The SSRF is triggered b…
Databasir
1.0.7+
CRITICAL 9.8
CVE-2021-27693
Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage.
Publiccms
4.0.202011.b+
CRITICAL 9.8
CVE-2022-35583EPSS 15%
wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial…
Wkhtmltopdf
No fix yet
HIGH 7.5
CVE-2022-38187
Prior to version 10.9.0, the sharing/rest/content/features/analyze endpoint is always accessible to anonymous users, which could allow an unauthentic…
Portal For Arcgis
10.9+
HIGH 7.5
CVE-2020-23622
An issue in the UPnP protocol in 4thline cling 2.0.0 through 2.1.2 allows remote attackers to cause a denial of service via an unchecked CALLBACK par…
Cling
after 2.1.2
CRITICAL 9.8
CVE-2022-35949
undici is an HTTP/1.1 client, written from scratch for Node.js.`undici` is vulnerable to SSRF (Server-side Request Forgery) when an application takes…
Undici
after 5.8.1
HIGH 7.5
CVE-2022-37041
An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. The value of the X-Forwarded-H…
Collaboration
Patch available
MEDIUM 6.5
CVE-2022-2756
Server-Side Request Forgery (SSRF) in GitHub repository kareadita/kavita prior to 0.5.4.1.
Kavita
0.5.4.1+
CRITICAL 9.8
CVE-2022-31132
Nextcloud Mail is an email application for the nextcloud personal cloud product. Affected versions shipped with a CSS minifier on the path `./vendor/…
Mail
1.12.8 / 1.13.6+
CRITICAL 9.8
CVE-2022-31188EPSS 49%
CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were found to be subject to a Server-s…
Computer Vision Annotation Tool
2.0.0+
HIGH 8.8
CVE-2022-31776
IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to server-side…
Datapower Gateway
10.5.0.1+
HIGH 8.8
CVE-2022-36997
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and rel…
Flex Appliance
Patch available
MEDIUM 5.7
CVE-2021-43959
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to access the content of internal …
Jira Service Desk
4.13.20 / 4.20.8+