Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 6.8 CVE-2021-37940 An information disclosure via GET request server-side request forgery vulnerability was discovered with the Workplace Search Github Enterprise Server… Enterprise Search 7.16.0+ Fix from $1,6002021-12-07 CRITICAL 9.8 CVE-2021-40091 An SSRF issue was discovered in SquaredUp for SCOM 5.2.1.6654. Squaredup 5.3.1+ Fix from $2,3002021-12-06 HIGH 7.2 CVE-2021-4075 snipe-it is vulnerable to Server-Side Request Forgery (SSRF) Snipe It Patch available Fix from $1,9502021-12-06 HIGH 8.8 CVE-2021-40809 An issue was discovered in Jamf Pro before 10.32.0, aka PI-009921. An account can be granted incorrect privileges in response to authentication that … Jamf 10.32.0+ Fix from $1,9502021-12-01 MEDIUM 5.3 CVE-2021-36327 Dell EMC Streaming Data Platform versions before 1.3 contain a Server Side Request Forgery Vulnerability. A remote unauthenticated attacker may poten… Emc Streaming Data Platform 1.3+ Fix from $1,6002021-11-30 HIGH 7.5 CVE-2021-43296 Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to an SSRF attack in ActionExecutor. Manageengine Supportcenter Plus Mitigation only Fix from $1,9502021-11-30 CRITICAL 9.8 CVE-2021-22049 The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A maliciou… Vcenter Server Patch available Fix from $2,3002021-11-24 HIGH 8.8 CVE-2021-43780 Redash is a package for data visualization and sharing. In versions 10.0 and priorm the implementation of URL-loading data sources like JSON, CSV, or… Redash 10.0.1+ Fix from $1,9502021-11-24 HIGH 7.5 CVE-2021-3552 A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security Tools allows an attacker to pro… Endpoint Security Tools 6.2.21.160 / 6.6.27.390+ Fix from $1,9502021-11-24 HIGH 7.5 CVE-2021-3553 A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService of Bitdefender Endpoint Security Tools allows an attacker to use the Endpo… Endpoint Security Tools 6.2.21.160 / 6.6.27.390+ Fix from $1,9502021-11-24 HIGH 7.5 CVE-2021-23718 The package ssrf-agent before 1.0.5 are vulnerable to Server-side Request Forgery (SSRF) via the defaultIpChecker function. It fails to properly vali… Ssrf Agent 1.0.5+ Fix from $1,9502021-11-22 MEDIUM 5.3 CVE-2021-22969 Concrete CMS (formerly concrete5) versions below 8.5.7 has a SSRF mitigation bypass using DNS Rebind attack giving an attacker the ability to fetch c… Concrete Cms 8.5.7+ Fix from $1,6002021-11-19 HIGH 7.5 CVE-2021-22970 Concrete CMS (formerly concrete5) versions 8.5.6 and below and version 9.0.0 allow local IP importing causing the system to be vulnerable toa. SSRF a… Concrete Cms after 8.5.6 Fix from $1,9502021-11-19 CRITICAL 9.8 CVE-2021-39303 The server in Jamf Pro before 10.32.0 has an SSRF vulnerability, aka PI-006352. NOTE: Jamf Nation will also publish an article about this vulnerabili… Jamf 10.32.0+ Fix from $2,3002021-11-12 HIGH 8.8 CVE-2021-43562 An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The extension fails to restrict the image do… Pixx.io 1.0.6+ Fix from $1,9502021-11-10 MEDIUM 5.4 CVE-2021-29738 IBM InfoSphere Data Flow Designer (IBM InfoSphere Information Server 11.7 ) is vulnerable to server-side request forgery (SSRF). This may allow an au… Infosphere Information Server Patch available Fix from $1,6002021-11-02 HIGH 8.8 CVE-2021-29844 IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requ… Engineering Lifecycle Optimization Patch available Fix from $1,9502021-10-27 MEDIUM 6.5 CVE-2021-35512 An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200. Manageengine Applications Manager No fix yet Fix from $1,6002021-10-21 MEDIUM 5.3 CVE-2021-41792 An issue was discovered in Hyland org.alfresco:alfresco-content-services through 6.2.2.18 and org.alfresco:alfresco-transform-services through 1.3. A… Alfresco Content Services after 6.2.2.18 Fix from $1,6002021-10-21 HIGH 7.5 CVE-2021-32663 iTop is an open source web based IT Service Management tool. In affected versions an attacker can call the system setup without authentication. Given… Itop 2.6.5 / 2.7.5+ Fix from $1,9502021-10-19 CRITICAL 9.1 CVE-2021-42091 An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration. Zammad 4.1.1+ Fix from $2,3002021-10-07 CRITICAL 9.8 CVE-2021-22958 A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP address to bypass the limitatio… Concrete Cms 8.5.5+ Fix from $2,3002021-10-07 HIGH 8.1 CVE-2020-21649 Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploited via the sql() method. Myucms No fix yet Fix from $1,9502021-10-06 CRITICAL 9.1 CVE-2020-21653 Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploited via the sj() method. Myucms No fix yet Fix from $2,3002021-10-06 MEDIUM 5.4 CVE-2021-39894 In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit… GitLab 14.1.7 / 14.2.5+ Fix from $1,6002021-10-05 HIGH 8.1 CVE-2021-39867 In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server… GitLab 14.1.7 / 14.2.5+ Fix from $1,9502021-10-05 MEDIUM 6.5 CVE-2021-37223 Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php. Any authenticated user can cr… Nagios Xi after 5.8.4 Fix from $1,6002021-10-05 HIGH 7.5 CVE-2021-37104 There is a server-side request forgery vulnerability in HUAWEI P40 versions 10.1.0.118(C00E116R3P3). This vulnerability is due to insufficient valida… P40 Firmware Mitigation only Fix from $1,9502021-09-28 MEDIUM 6.4 CVE-2021-40109 A SSRF issue was discovered in Concrete CMS through 8.5.5. Users can access forbidden files on their local network. A user with permissions to upload… Concrete Cms 8.5.6+ Fix from $1,6002021-09-27 MEDIUM 6.5 CVE-2021-41385 The third party intelligence connector in Securonix SNYPR 6.3.1 Build 184295_0302 allows an authenticated user to obtain access to server configurati… Snypr Mitigation only Fix from $1,6002021-09-27