Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 7.5 CVE-2021-41586 In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially reset the system user password. Gradle 2021.1.3+ Fix from $1,9502021-09-24 HIGH 7.5 CVE-2021-41587 In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially discover credentials for other resources. Gradle 2021.1.3+ Fix from $1,9502021-09-24 MEDIUM 5.3 CVE-2020-24327 Server Side Request Forgery (SSRF) vulnerability exists in Discourse 2.3.2 and 2.6 via the email function. When writing an email in an editor, you ca… Discourse Patch available Fix from $1,6002021-09-23 MEDIUM 6.5 CVE-2021-21993 The vCenter Server contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in vCenter Server Content Library.… Cloud Foundation 5.0+ Fix from $1,6002021-09-23 MEDIUM 5.3 CVE-2021-39339 The Telefication WordPress plugin is vulnerable to Open Proxy and Server-Side Request Forgery via the ~/bypass.php file due to a user-supplied URL re… Telefication after 1.8.0 Fix from $1,6002021-09-22 HIGH 7.5 CVE-2021-37419 Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to SSRF. Manageengine Admanager Plus 6.1+ Fix from $1,9502021-09-21 CRITICAL 9.0 CVE-2021-40438 KEVEPSS 100% A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP … Enterprise Linux Patch available Fix from $2,3002021-09-16 CRITICAL 9.9 CVE-2021-33690EPSS 69% Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions -… Netweaver Development Infrastructure Patch available Fix from $2,3002021-09-15 HIGH 8.1 CVE-2021-33705 The SAP NetWeaver Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, component Iviews Editor contains a Server-Side Request Forgery (SSRF) … Netweaver Portal Patch available Fix from $1,9502021-09-15 MEDIUM 5.3 CVE-2020-21122 UReport v2.2.9 contains a Server-Side Request Forgery (SSRF) in the designer page which allows attackers to detect intranet device ports. Ureport No fix yet Fix from $1,6002021-09-15 HIGH 8.8 CVE-2021-23029 On version 16.0.x before 16.0.1.2, insufficient permission checks may allow authenticated users with guest privileges to perform Server-Side Request … Big Ip Advanced Web Application Firewall 16.0.1.2+ Fix from $1,9502021-09-14 HIGH 7.5 CVE-2021-28910 BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 contains basic SSRF vulnerability. It allow unauthenticated attackers to request to any internal … Eibport Firmware 3.9.1+ Fix from $1,9502021-09-09 CRITICAL 9.8 CVE-2021-39497 eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function. Eyoucms No fix yet Fix from $2,3002021-09-07 MEDIUM 6.5 CVE-2021-39195 Misskey is an open source, decentralized microblogging platform. In affected versions a Server-Side Request Forgery vulnerability exists in "Upload f… Misskey 12.90.0+ Fix from $1,6002021-09-07 MEDIUM 6.5 CVE-2021-3758 bookstack is vulnerable to Server-Side Request Forgery (SSRF) Bookstack 21.08+ Fix from $1,6002021-09-02 HIGH 7.5 CVE-2020-20341 YzmCMS v5.5 contains a server-side request forgery (SSRF) in the grab_image() function. Yzmcms No fix yet Fix from $1,9502021-09-01 MEDIUM 6.6 CVE-2021-36043 Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a blind SSRF vulnerability in the bundl… Adobe Commerce after 2.4.2 Fix from $1,6002021-09-01 HIGH 7.5 CVE-2021-22026 The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor wit… Cloud Foundation 8.5.0+ Fix from $1,9502021-08-30 HIGH 7.5 CVE-2021-22027 The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor wit… Cloud Foundation 8.5.0+ Fix from $1,9502021-08-30 HIGH 7.5 CVE-2020-14160 An SSRF vulnerability in Gotenberg through 6.2.1 exists in the remote URL to PDF conversion, which results in a remote attacker being able to read lo… Gotenberg after 6.2.1 Fix from $1,9502021-08-26 HIGH 8.8 CVE-2021-28627 Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by a Server-side Request Forgery. An authenticat… Experience Manager after 6.5.8.0 Fix from $1,9502021-08-24 HIGH 8.5 CVE-2021-39152EPSS 11% XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to reques… Fedora 1.4.18+ Fix from $1,9502021-08-23 HIGH 8.5 CVE-2021-39150 XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to reques… Fedora 1.4.18+ Fix from $1,9502021-08-23 MEDIUM 6.5 CVE-2020-25353 A server-side request forgery (SSRF) vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability allowed remote authenticated attacke… Rconfig No fix yet Fix from $1,6002021-08-20 MEDIUM 6.5 CVE-2021-22255 SSRF in URL file upload in Baserow <1.1.0 allows remote authenticated users to retrieve files from the internal server network exposed over HTTP by i… Baserow 1.1.0+ Fix from $1,6002021-08-20 HIGH 8.8 CVE-2021-37711 Versions prior to 6.4.3.1 contain an authenticated server-side request forgery vulnerability in file upload via URL. Version 6.4.3.1 contains a patch… Shopware 6.4.3.1+ Fix from $1,9502021-08-16 CRITICAL 9.8 CVE-2021-37353 Nagios XI Docker Wizard before version 1.1.3 is vulnerable to SSRF due to improper sanitation in table_population.php. Nagios Xi Docker Wizard 1.1.3+ Fix from $2,3002021-08-13 MEDIUM 6.5 CVE-2021-32603 A server-side request forgery (SSRF) (CWE-918) vulnerability in FortiManager and FortiAnalyser GUI 7.0.0, 6.4.5 and below, 6.2.7 and below, 6.0.11 an… Fortianalyzer 6.2.8 / 6.4.6+ Fix from $1,6002021-08-05 CRITICAL 9.8 CVE-2021-24472EPSS 57% The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users,… Kentharadio 2.0.2 / 3.9.9.2+ Fix from $2,3002021-08-02 MEDIUM 6.3 CVE-2020-4974 IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requ… Engineering Lifecycle Optimization Engineering Insights No fix yet Fix from $1,6002021-07-28