Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2022-32457
Digiwin BPM has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network…
Business Process Management
5.8.8.1+
MEDIUM 5.4
CVE-2022-22416
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to server-side request forgery (SSRF). This may allow an authen…
Partner Engagement Manager
6.1.2.5 / 6.2.0.3+
CRITICAL 9.1
CVE-2022-25800
Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool.
Request Tracker For Incident Response
4.0.3 / 5.0.3+
CRITICAL 9.1
CVE-2022-25801
Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools.
Request Tracker For Incident Response
4.0.3 / 5.0.3+
HIGH 7.5
CVE-2022-22982
The vCenter Server contains a server-side request forgery (SSRF) vulnerability. A malicious actor with network access to 443 on the vCenter Server ma…
Cloud Foundation
after 4.3.1
HIGH 7.5
CVE-2022-2339
With this SSRF vulnerability, an attacker can reach internal addresses to make a request as the server and read it's contents. This attack can lead t…
Nocodb
0.92.0+
MEDIUM 5.5
CVE-2022-25876
The package link-preview-js before 2.1.16 are vulnerable to Server-side Request Forgery (SSRF) which allows attackers to send arbitrary requests to t…
Link Preview Js
2.1.16+
MEDIUM 6.5
CVE-2022-26135EPSS 71%
A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up fea…
Jira Data Center
4.13.22 / 4.20.10+
MEDIUM 5.3
CVE-2022-0085
Server-Side Request Forgery (SSRF) in GitHub repository dompdf/dompdf prior to 2.0.0.
Dompdf
2.0.0+
CRITICAL 9.8
CVE-2022-32995EPSS 16%
Halo CMS v1.5.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the template remote download function.
Halo
No fix yet
CRITICAL 9.8
CVE-2022-2216
Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 7.0.0.
Parse Url
7.0.0+
HIGH 7.2
CVE-2022-1977
The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL b…
Import All Pages\, Post Types\, Products\, Orders\, And Users As Xml \& Csv
6.5.3+
MEDIUM 5.0
CVE-2022-23080
In directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media upload functionality which allows …
Directus
after 9.6.0
MEDIUM 5.3
CVE-2021-36761
The GeoAnalytics feature in Qlik Sense April 2020 patch 4 allows SSRF.
Qlik Sense
Mitigation only
MEDIUM 6.5
CVE-2022-23071
In Recipes, versions 0.9.1 through 1.2.5 are vulnerable to Server Side Request Forgery (SSRF), in the “Import Recipe” functionality. When an attacker…
Recipes
after 1.2.5
CRITICAL 9.8
CVE-2021-41403EPSS 19%
flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities.
Flatcore Cms
Patch available
CRITICAL 9.1
CVE-2021-40604
A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users to request arbitrary URLs or…
Ips Community Suite
4.6.2+
MEDIUM 6.5
CVE-2022-28217
Some part of SAP NetWeaver (EP Web Page Composer) does not sufficiently validate an XML document accepted from an untrusted source, which allows an a…
Netweaver
No fix yet
MEDIUM 6.1
CVE-2022-24969
bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check whic…
Dubbo
2.6.12 / 2.7.15+
CRITICAL 9.1
CVE-2022-31386
A Server-Side Request Forgery (SSRF) in the getFileBinary function of nbnbk cms 3 allows attackers to force the application to make arbitrary request…
Nbnbk
No fix yet
CRITICAL 9.1
CVE-2022-31390
Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Update function in app/admin/c/TemplateControlle…
Jizhicms
No fix yet
CRITICAL 9.1
CVE-2022-31393
Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Index function in app/admin/c/PluginsController.…
Jizhicms
No fix yet
CRITICAL 9.1
CVE-2022-31827EPSS 21%
MonstaFTP v2.10.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the function performFetchRequest at HTTPFetcher.php.
Monstaftp
No fix yet
CRITICAL 9.1
CVE-2022-31830EPSS 16%
Kity Minder v1.3.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the init function at ImageCapture.class.php.
Kity Minder
No fix yet
HIGH 7.5
CVE-2022-27780
The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usi…
Curl
7.83.1+
HIGH 7.5
CVE-2021-40186
The AppCheck research team identified a Server-Side Request Forgery (SSRF) vulnerability within the DNN CMS platform, formerly known as DotNetNuke. S…
Dotnetnuke
after 9.10.2
MEDIUM 6.5
CVE-2022-1285
Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.8.
Gogs
0.12.8+
HIGH 7.5
CVE-2022-1815EPSS 6%
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2.
Drawio
18.1.2+
HIGH 7.5
CVE-2022-29309
mysiteforme v2.2.1 was discovered to contain a Server-Side Request Forgery.
Mysiteforme
No fix yet
HIGH 7.5
CVE-2022-28997
CSZCMS v1.3.0 allows attackers to execute a Server-Side Request Forgery (SSRF) which can be leveraged to leak sensitive data via a local file inclusi…
Cszcms
No fix yet