Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2022-24825
Smokescreen is a simple HTTP proxy that fogs over naughty URLs. The primary use case for Smokescreen is to prevent server-side request forgery (SSRF)…
Smokescreen
0.0.3+
HIGH 7.5
CVE-2022-29153EPSS 9%
HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows re…
Fedora
1.9.17 / 1.10.10+
HIGH 7.2
CVE-2022-1037
The EXMAGE WordPress plugin before 1.0.7 does to ensure that images added via URLs are external images, which could lead to a blind SSRF issue by usi…
Exmage
1.0.7+
HIGH 8.8
CVE-2022-27426
A Server-Side Request Forgery (SSRF) in Chamilo LMS v1.11.13 allows attackers to enumerate the internal network and execute arbitrary system commands…
Chamilo Lms
after 1.11.16
CRITICAL 9.1
CVE-2022-26499EPSS 8%
An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces s…
Debian Linux
18.11.2+
HIGH 7.3
CVE-2022-22339
IBM Planning Analytics 2.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized request…
Planning Analytics
Patch available
HIGH 8.8
CVE-2021-36202
Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to inject malicious code into the …
Metasys Application And Data Server
10.1.5 / 11.0.2+
MEDIUM 6.5
CVE-2020-27375
Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Transmitting Write Requests and Chars.
Icheck Connect Bp Monitor Bp Testing 118 Firmware
No fix yet
HIGH 8.1
CVE-2022-1213
SSRF filter bypass port 80, 433 in GitHub repository livehelperchat/livehelperchat prior to 3.67v. An attacker could make the application perform arb…
Live Helper Chat
3.97+
MEDIUM 5.3
CVE-2022-1188
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions starting from 14.8 before 14.8.5, …
GitLab
14.7.7 / 14.8.5+
CRITICAL 9.1
CVE-2022-0990
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.
Calibre Web
0.6.18+
CRITICAL 9.9
CVE-2022-0939
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.
Calibre Web
0.6.18+
HIGH 7.6
CVE-2022-0425
A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Se…
GitLab
after 14.7.1
HIGH 8.1
CVE-2022-1191
SSRF on index.php/cobrowse/proxycss/ in GitHub repository livehelperchat/livehelperchat prior to 3.96.
Live Helper Chat
3.96+
HIGH 7.2
CVE-2021-33581
MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP services, by abusing the feature to…
Mashzone Nextgen
after 10.7
HIGH 7.6
CVE-2022-24789
C1 CMS is an open-source, .NET based Content Management System (CMS). Versions prior to 6.12 allow an authenticated user to exploit Server Side Reque…
C1 Cms
6.12+
HIGH 8.1
CVE-2022-0136
A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnerable to a blind SSRF attack th…
GitLab
after 14.7.1
CRITICAL 9.1
CVE-2022-0249
A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared address spac…
GitLab
after 14.7.1
HIGH 7.5
CVE-2021-44139EPSS 6%
Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF).
Sentinel
No fix yet
CRITICAL 9.1
CVE-2022-0591EPSS 20%
The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitabl…
Formcraft3
3.8.28+
HIGH 8.8
CVE-2022-27245
An issue was discovered in MISP before 2.4.156. app/Model/Server.php does not restrict generateServerSettings to the CLI. This could lead to SSRF.
Misp
2.4.156+
HIGH 7.5
CVE-2021-45968EPSS 10%
An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Phone System before 7.20.x (and …
Jive
after 7.19
HIGH 7.5
CVE-2021-46107EPSS 7%
Ligeo Archives Ligeo Basics as of 02_01-2022 is vulnerable to Server Side Request Forgery (SSRF) which allows an attacker to read any documents via t…
Ligeo Basics
No fix yet
HIGH 7.5
CVE-2021-45851
A Server-Side Request Forgery (SSRF) attack in FUXA 1.1.3 can be carried out leading to the obtaining of sensitive information from the server's inte…
Fuxa
No fix yet
MEDIUM 6.5
CVE-2021-39051
IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to server-side request forgery, caused by improper input of application serv…
Spectrum Copy Data Management
2.2.15.0+
MEDIUM 5.3
CVE-2022-0870
Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.5.
Gogs
0.12.5+
MEDIUM 6.1
CVE-2022-24739
alltube is an html front end for youtube-dl. On releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redire…
Alltube
3.0.3+
CRITICAL 9.8
CVE-2022-0766
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.
Calibre Web
0.6.17+
CRITICAL 9.9
CVE-2022-0767
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.
Calibre Web
0.6.17+
HIGH 7.5
CVE-2022-0528
Server-Side Request Forgery (SSRF) in GitHub repository transloadit/uppy prior to 3.3.1.
Uppy
3.3.1+