Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2021-41586
In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially reset the system user password.
Gradle
2021.1.3+
HIGH 7.5
CVE-2021-41587
In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially discover credentials for other resources.
Gradle
2021.1.3+
MEDIUM 5.3
CVE-2020-24327
Server Side Request Forgery (SSRF) vulnerability exists in Discourse 2.3.2 and 2.6 via the email function. When writing an email in an editor, you ca…
Discourse
Patch available
MEDIUM 6.5
CVE-2021-21993
The vCenter Server contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in vCenter Server Content Library.…
Cloud Foundation
5.0+
MEDIUM 5.3
CVE-2021-39339
The Telefication WordPress plugin is vulnerable to Open Proxy and Server-Side Request Forgery via the ~/bypass.php file due to a user-supplied URL re…
Telefication
after 1.8.0
HIGH 7.5
CVE-2021-37419
Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to SSRF.
Manageengine Admanager Plus
6.1+
CRITICAL 9.0
CVE-2021-40438 KEVEPSS 100%
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP …
Enterprise Linux
Patch available
CRITICAL 9.9
CVE-2021-33690EPSS 69%
Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions -…
Netweaver Development Infrastructure
Patch available
HIGH 8.1
CVE-2021-33705
The SAP NetWeaver Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, component Iviews Editor contains a Server-Side Request Forgery (SSRF) …
Netweaver Portal
Patch available
MEDIUM 5.3
CVE-2020-21122
UReport v2.2.9 contains a Server-Side Request Forgery (SSRF) in the designer page which allows attackers to detect intranet device ports.
Ureport
No fix yet
HIGH 8.8
CVE-2021-23029
On version 16.0.x before 16.0.1.2, insufficient permission checks may allow authenticated users with guest privileges to perform Server-Side Request …
Big Ip Advanced Web Application Firewall
16.0.1.2+
HIGH 7.5
CVE-2021-28910
BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 contains basic SSRF vulnerability. It allow unauthenticated attackers to request to any internal …
Eibport Firmware
3.9.1+
CRITICAL 9.8
CVE-2021-39497
eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function.
Eyoucms
No fix yet
MEDIUM 6.5
CVE-2021-39195
Misskey is an open source, decentralized microblogging platform. In affected versions a Server-Side Request Forgery vulnerability exists in "Upload f…
Misskey
12.90.0+
MEDIUM 6.5
CVE-2021-3758
bookstack is vulnerable to Server-Side Request Forgery (SSRF)
Bookstack
21.08+
HIGH 7.5
CVE-2020-20341
YzmCMS v5.5 contains a server-side request forgery (SSRF) in the grab_image() function.
Yzmcms
No fix yet
MEDIUM 6.6
CVE-2021-36043
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a blind SSRF vulnerability in the bundl…
Adobe Commerce
after 2.4.2
HIGH 7.5
CVE-2021-22026
The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor wit…
Cloud Foundation
8.5.0+
HIGH 7.5
CVE-2021-22027
The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor wit…
Cloud Foundation
8.5.0+
HIGH 7.5
CVE-2020-14160
An SSRF vulnerability in Gotenberg through 6.2.1 exists in the remote URL to PDF conversion, which results in a remote attacker being able to read lo…
Gotenberg
after 6.2.1
HIGH 8.8
CVE-2021-28627
Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by a Server-side Request Forgery. An authenticat…
Experience Manager
after 6.5.8.0
HIGH 8.5
CVE-2021-39152EPSS 11%
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to reques…
Fedora
1.4.18+
HIGH 8.5
CVE-2021-39150
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to reques…
Fedora
1.4.18+
MEDIUM 6.5
CVE-2020-25353
A server-side request forgery (SSRF) vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability allowed remote authenticated attacke…
Rconfig
No fix yet
MEDIUM 6.5
CVE-2021-22255
SSRF in URL file upload in Baserow <1.1.0 allows remote authenticated users to retrieve files from the internal server network exposed over HTTP by i…
Baserow
1.1.0+
HIGH 8.8
CVE-2021-37711
Versions prior to 6.4.3.1 contain an authenticated server-side request forgery vulnerability in file upload via URL. Version 6.4.3.1 contains a patch…
Shopware
6.4.3.1+
CRITICAL 9.8
CVE-2021-37353
Nagios XI Docker Wizard before version 1.1.3 is vulnerable to SSRF due to improper sanitation in table_population.php.
Nagios Xi Docker Wizard
1.1.3+
MEDIUM 6.5
CVE-2021-32603
A server-side request forgery (SSRF) (CWE-918) vulnerability in FortiManager and FortiAnalyser GUI 7.0.0, 6.4.5 and below, 6.2.7 and below, 6.0.11 an…
Fortianalyzer
6.2.8 / 6.4.6+
CRITICAL 9.8
CVE-2021-24472EPSS 57%
The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users,…
Kentharadio
2.0.2 / 3.9.9.2+
MEDIUM 6.3
CVE-2020-4974
IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requ…
Engineering Lifecycle Optimization Engineering Insights
No fix yet