Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 5.3 CVE-2022-32457 Digiwin BPM has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network… Business Process Management 5.8.8.1+ Fix from $1,6002022-07-20 MEDIUM 5.4 CVE-2022-22416 IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to server-side request forgery (SSRF). This may allow an authen… Partner Engagement Manager 6.1.2.5 / 6.2.0.3+ Fix from $1,6002022-07-19 CRITICAL 9.1 CVE-2022-25800 Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool. Request Tracker For Incident Response 4.0.3 / 5.0.3+ Fix from $2,3002022-07-14 CRITICAL 9.1 CVE-2022-25801 Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools. Request Tracker For Incident Response 4.0.3 / 5.0.3+ Fix from $2,3002022-07-14 HIGH 7.5 CVE-2022-22982 The vCenter Server contains a server-side request forgery (SSRF) vulnerability. A malicious actor with network access to 443 on the vCenter Server ma… Cloud Foundation after 4.3.1 Fix from $1,9502022-07-13 HIGH 7.5 CVE-2022-2339 With this SSRF vulnerability, an attacker can reach internal addresses to make a request as the server and read it's contents. This attack can lead t… Nocodb 0.92.0+ Fix from $1,9502022-07-07 MEDIUM 5.5 CVE-2022-25876 The package link-preview-js before 2.1.16 are vulnerable to Server-side Request Forgery (SSRF) which allows attackers to send arbitrary requests to t… Link Preview Js 2.1.16+ Fix from $1,6002022-07-01 MEDIUM 6.5 CVE-2022-26135EPSS 71% A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up fea… Jira Data Center 4.13.22 / 4.20.10+ Fix from $1,6002022-06-30 MEDIUM 5.3 CVE-2022-0085 Server-Side Request Forgery (SSRF) in GitHub repository dompdf/dompdf prior to 2.0.0. Dompdf 2.0.0+ Fix from $1,6002022-06-28 CRITICAL 9.8 CVE-2022-32995EPSS 16% Halo CMS v1.5.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the template remote download function. Halo No fix yet Fix from $2,3002022-06-27 CRITICAL 9.8 CVE-2022-2216 Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 7.0.0. Parse Url 7.0.0+ Fix from $2,3002022-06-27 HIGH 7.2 CVE-2022-1977 The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL b… Import All Pages\, Post Types\, Products\, Orders\, And Users As Xml \& Csv 6.5.3+ Fix from $1,9502022-06-27 MEDIUM 5.0 CVE-2022-23080 In directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media upload functionality which allows … Directus after 9.6.0 Fix from $1,6002022-06-22 MEDIUM 5.3 CVE-2021-36761 The GeoAnalytics feature in Qlik Sense April 2020 patch 4 allows SSRF. Qlik Sense Mitigation only Fix from $1,6002022-06-21 MEDIUM 6.5 CVE-2022-23071 In Recipes, versions 0.9.1 through 1.2.5 are vulnerable to Server Side Request Forgery (SSRF), in the “Import Recipe” functionality. When an attacker… Recipes after 1.2.5 Fix from $1,6002022-06-19 CRITICAL 9.8 CVE-2021-41403EPSS 19% flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities. Flatcore Cms Patch available Fix from $2,3002022-06-15 CRITICAL 9.1 CVE-2021-40604 A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users to request arbitrary URLs or… Ips Community Suite 4.6.2+ Fix from $2,3002022-06-13 MEDIUM 6.5 CVE-2022-28217 Some part of SAP NetWeaver (EP Web Page Composer) does not sufficiently validate an XML document accepted from an untrusted source, which allows an a… Netweaver No fix yet Fix from $1,6002022-06-13 MEDIUM 6.1 CVE-2022-24969 bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check whic… Dubbo 2.6.12 / 2.7.15+ Fix from $1,6002022-06-09 CRITICAL 9.1 CVE-2022-31386 A Server-Side Request Forgery (SSRF) in the getFileBinary function of nbnbk cms 3 allows attackers to force the application to make arbitrary request… Nbnbk No fix yet Fix from $2,3002022-06-09 CRITICAL 9.1 CVE-2022-31390 Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Update function in app/admin/c/TemplateControlle… Jizhicms No fix yet Fix from $2,3002022-06-09 CRITICAL 9.1 CVE-2022-31393 Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Index function in app/admin/c/PluginsController.… Jizhicms No fix yet Fix from $2,3002022-06-09 CRITICAL 9.1 CVE-2022-31827EPSS 21% MonstaFTP v2.10.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the function performFetchRequest at HTTPFetcher.php. Monstaftp No fix yet Fix from $2,3002022-06-09 CRITICAL 9.1 CVE-2022-31830EPSS 16% Kity Minder v1.3.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the init function at ImageCapture.class.php. Kity Minder No fix yet Fix from $2,3002022-06-09 HIGH 7.5 CVE-2022-27780 The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usi… Curl 7.83.1+ Fix from $1,9502022-06-02 HIGH 7.5 CVE-2021-40186 The AppCheck research team identified a Server-Side Request Forgery (SSRF) vulnerability within the DNN CMS platform, formerly known as DotNetNuke. S… Dotnetnuke after 9.10.2 Fix from $1,9502022-06-02 MEDIUM 6.5 CVE-2022-1285 Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.8. Gogs 0.12.8+ Fix from $1,6002022-06-01 HIGH 7.5 CVE-2022-1815EPSS 6% Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2. Drawio 18.1.2+ Fix from $1,9502022-05-25 HIGH 7.5 CVE-2022-29309 mysiteforme v2.2.1 was discovered to contain a Server-Side Request Forgery. Mysiteforme No fix yet Fix from $1,9502022-05-24 HIGH 7.5 CVE-2022-28997 CSZCMS v1.3.0 allows attackers to execute a Server-Side Request Forgery (SSRF) which can be leveraged to leak sensitive data via a local file inclusi… Cszcms No fix yet Fix from $1,9502022-05-23