Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
CRITICAL 9.1 CVE-2022-0768 Server-Side Request Forgery (SSRF) in GitHub repository rudloff/alltube prior to 3.0.2. Alltube 3.0.2+ Fix from $2,3002022-02-28 CRITICAL 9.1 CVE-2022-25260 JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF). Hub 2021.1.14276+ Fix from $2,3002022-02-25 MEDIUM 6.5 CVE-2022-24333 In JetBrains TeamCity before 2021.2, blind SSRF via an XML-RPC call was possible. Teamcity 2021.2+ Fix from $1,6002022-02-25 HIGH 7.5 CVE-2022-24980 An issue was discovered in the Kitodo.Presentation (aka dif) extension before 2.3.2, 3.x before 3.2.3, and 3.3.x before 3.3.4 for TYPO3. A missing ac… Kitodo.presentation 2.3.2 / 3.2.3+ Fix from $1,9502022-02-19 CRITICAL 9.8 CVE-2022-21215 This vulnerability could allow an attacker to force the server to create and execute a web request granting access to backend APIs that are only acce… Mimosa Management Platform 1.0.3 / 2.5.4.1+ Fix from $2,3002022-02-18 CRITICAL 9.1 CVE-2022-0671 A flaw was found in vscode-xml in versions prior to 0.19.0. Schema download could lead to blind SSRF or DoS via a large file. Vscode Xml 0.19.0+ Fix from $2,3002022-02-18 CRITICAL 9.8 CVE-2021-20325 Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regress… Enterprise Linux Mitigation only Fix from $2,3002022-02-18 HIGH 8.8 CVE-2022-23644 BookWyrm is a decentralized social network for tracking reading habits and reviewing books. The functionality to load a cover via url is vulnerable t… Bookwyrm 0.3.0+ Fix from $1,9502022-02-16 CRITICAL 9.8 CVE-2022-24568 Novel-plus v3.6.0 was discovered to be vulnerable to Server-Side Request Forgery (SSRF) via user-supplied crafted input. Novel Plus No fix yet Fix from $2,3002022-02-10 HIGH 7.5 CVE-2021-45325 Server Side Request Forgery (SSRF) vulneraility exists in Gitea before 1.7.0 using the OpenID URL. Gitea 1.7.0+ Fix from $1,9502022-02-08 MEDIUM 5.3 CVE-2022-0508 Server-Side Request Forgery (SSRF) in GitHub repository chocobozzz/peertube prior to f33e515991a32885622b217bf2ed1d1b0d9d6832 Peertube 2021-12-13+ Fix from $1,6002022-02-08 HIGH 7.5 CVE-2022-23206 In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted… Traffic Control 5.1.6 / 6.1.0+ Fix from $1,9502022-02-06 HIGH 8.2 CVE-2022-24129EPSS 6% The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insufficient restriction of the req… Oidc Op 3.0.4+ Fix from $1,9502022-02-04 CRITICAL 9.8 CVE-2021-42637 PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server Side Request Forgery (SSRF) v… Web Stack 19.1.1.13+ Fix from $2,3002022-02-02 CRITICAL 9.8 CVE-2022-0339 Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16. Calibre Web 0.6.16+ Fix from $2,3002022-01-30 HIGH 8.8 CVE-2022-22993 A limited SSRF vulnerability was discovered on Western Digital My Cloud devices that could allow an attacker to impersonate a server and reach any pa… My Cloud Os 5.19.117+ Fix from $1,9502022-01-28 HIGH 8.6 CVE-2021-22821 A CWE-918 Server-Side Request Forgery (SSRF) vulnerability exists that could cause the station web server to forward requests to unintended network t… Evlink City Evc1s22p4 Firmware 3.4.0.2+ Fix from $1,9502022-01-28 HIGH 7.1 CVE-2022-21697 Jupyter Server Proxy is a Jupyter notebook server extension to proxy web services. Versions of Jupyter Server Proxy prior to 3.2.1 are vulnerable to … Jupyter Server Proxy 3.2.1+ Fix from $1,9502022-01-25 HIGH 7.5 CVE-2021-23664 The package @isomorphic-git/cors-proxy before 2.7.1 are vulnerable to Server-side Request Forgery (SSRF) due to missing sanitization and validation o… Cors Proxy 2.7.1+ Fix from $1,9502022-01-21 HIGH 8.8 CVE-2021-45394 An issue was discovered in Spipu HTML2PDF before 5.2.4. Attackers can trigger deserialization of arbitrary data via the injection of a malicious <lin… Html2pdf 5.2.4+ Fix from $1,9502022-01-18 HIGH 7.5 CVE-2022-0132 peertube is vulnerable to Server-Side Request Forgery (SSRF) Peertube Patch available Fix from $1,9502022-01-10 HIGH 7.5 CVE-2021-27738 All request mappings in `StreamingCoordinatorController.java` handling `/kylin/api/streaming_coordinator/*` REST API endpoints did not include any se… Kylin 3.1.2+ Fix from $1,9502022-01-06 CRITICAL 9.8 CVE-2022-0086 uppy is vulnerable to Server-Side Request Forgery (SSRF) Uppy 2.3.3+ Fix from $2,3002022-01-04 CRITICAL 9.8 CVE-2021-44659 Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve a Server… Gocd No fix yet Fix from $2,3002021-12-22 HIGH 7.5 CVE-2021-22056 VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor… Identity Manager after 8.6 Fix from $1,9502021-12-20 HIGH 7.5 CVE-2021-22054 KEVEPSS 97% VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 con… Workspace One Uem Console 20.0.8.36 / 20.11.0.40+ Fix from $1,9502021-12-17 HIGH 7.5 CVE-2021-3959 A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security Tools allows an attacker to pro… Gravityzone 3.3.8.272+ Fix from $1,9502021-12-16 MEDIUM 6.1 CVE-2021-34425 The Zoom Client for Meetings before version 5.7.3 (for Android, iOS, Linux, macOS, and Windows) contain a server side request forgery vulnerability i… Meetings 5.7.3+ Fix from $1,6002021-12-14 HIGH 8.1 CVE-2021-39057 IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to … Spectrum Protect Plus 10.1.9+ Fix from $1,9502021-12-13 HIGH 7.5 CVE-2021-39935 KEVEPSS 36% An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, … GitLab 14.3.6 / 14.4.4+ Fix from $1,9502021-12-13