Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.1
CVE-2022-0768
Server-Side Request Forgery (SSRF) in GitHub repository rudloff/alltube prior to 3.0.2.
Alltube
3.0.2+
CRITICAL 9.1
CVE-2022-25260
JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF).
Hub
2021.1.14276+
MEDIUM 6.5
CVE-2022-24333
In JetBrains TeamCity before 2021.2, blind SSRF via an XML-RPC call was possible.
Teamcity
2021.2+
HIGH 7.5
CVE-2022-24980
An issue was discovered in the Kitodo.Presentation (aka dif) extension before 2.3.2, 3.x before 3.2.3, and 3.3.x before 3.3.4 for TYPO3. A missing ac…
Kitodo.presentation
2.3.2 / 3.2.3+
CRITICAL 9.8
CVE-2022-21215
This vulnerability could allow an attacker to force the server to create and execute a web request granting access to backend APIs that are only acce…
Mimosa Management Platform
1.0.3 / 2.5.4.1+
CRITICAL 9.1
CVE-2022-0671
A flaw was found in vscode-xml in versions prior to 0.19.0. Schema download could lead to blind SSRF or DoS via a large file.
Vscode Xml
0.19.0+
CRITICAL 9.8
CVE-2021-20325
Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regress…
Enterprise Linux
Mitigation only
HIGH 8.8
CVE-2022-23644
BookWyrm is a decentralized social network for tracking reading habits and reviewing books. The functionality to load a cover via url is vulnerable t…
Bookwyrm
0.3.0+
CRITICAL 9.8
CVE-2022-24568
Novel-plus v3.6.0 was discovered to be vulnerable to Server-Side Request Forgery (SSRF) via user-supplied crafted input.
Novel Plus
No fix yet
HIGH 7.5
CVE-2021-45325
Server Side Request Forgery (SSRF) vulneraility exists in Gitea before 1.7.0 using the OpenID URL.
Gitea
1.7.0+
MEDIUM 5.3
CVE-2022-0508
Server-Side Request Forgery (SSRF) in GitHub repository chocobozzz/peertube prior to f33e515991a32885622b217bf2ed1d1b0d9d6832
Peertube
2021-12-13+
HIGH 7.5
CVE-2022-23206
In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted…
Traffic Control
5.1.6 / 6.1.0+
HIGH 8.2
CVE-2022-24129EPSS 6%
The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insufficient restriction of the req…
Oidc Op
3.0.4+
CRITICAL 9.8
CVE-2021-42637
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server Side Request Forgery (SSRF) v…
Web Stack
19.1.1.13+
CRITICAL 9.8
CVE-2022-0339
Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16.
Calibre Web
0.6.16+
HIGH 8.8
CVE-2022-22993
A limited SSRF vulnerability was discovered on Western Digital My Cloud devices that could allow an attacker to impersonate a server and reach any pa…
My Cloud Os
5.19.117+
HIGH 8.6
CVE-2021-22821
A CWE-918 Server-Side Request Forgery (SSRF) vulnerability exists that could cause the station web server to forward requests to unintended network t…
Evlink City Evc1s22p4 Firmware
3.4.0.2+
HIGH 7.1
CVE-2022-21697
Jupyter Server Proxy is a Jupyter notebook server extension to proxy web services. Versions of Jupyter Server Proxy prior to 3.2.1 are vulnerable to …
Jupyter Server Proxy
3.2.1+
HIGH 7.5
CVE-2021-23664
The package @isomorphic-git/cors-proxy before 2.7.1 are vulnerable to Server-side Request Forgery (SSRF) due to missing sanitization and validation o…
Cors Proxy
2.7.1+
HIGH 8.8
CVE-2021-45394
An issue was discovered in Spipu HTML2PDF before 5.2.4. Attackers can trigger deserialization of arbitrary data via the injection of a malicious <lin…
Html2pdf
5.2.4+
HIGH 7.5
CVE-2022-0132
peertube is vulnerable to Server-Side Request Forgery (SSRF)
Peertube
Patch available
HIGH 7.5
CVE-2021-27738
All request mappings in `StreamingCoordinatorController.java` handling `/kylin/api/streaming_coordinator/*` REST API endpoints did not include any se…
Kylin
3.1.2+
CRITICAL 9.8
CVE-2022-0086
uppy is vulnerable to Server-Side Request Forgery (SSRF)
Uppy
2.3.3+
CRITICAL 9.8
CVE-2021-44659
Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve a Server…
Gocd
No fix yet
HIGH 7.5
CVE-2021-22056
VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor…
Identity Manager
after 8.6
HIGH 7.5
CVE-2021-22054 KEVEPSS 97%
VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 con…
Workspace One Uem Console
20.0.8.36 / 20.11.0.40+
HIGH 7.5
CVE-2021-3959
A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security Tools allows an attacker to pro…
Gravityzone
3.3.8.272+
MEDIUM 6.1
CVE-2021-34425
The Zoom Client for Meetings before version 5.7.3 (for Android, iOS, Linux, macOS, and Windows) contain a server side request forgery vulnerability i…
Meetings
5.7.3+
HIGH 8.1
CVE-2021-39057
IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to …
Spectrum Protect Plus
10.1.9+
HIGH 7.5
CVE-2021-39935 KEVEPSS 36%
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, …
GitLab
14.3.6 / 14.4.4+