Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2021-26699
OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled by the imageconverter componen…
Open Xchange Appsuite
No fix yet
HIGH 8.1
CVE-2021-22726
A CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Pa…
Evlink City Evc1s22p4 Firmware
Mitigation only
HIGH 8.1
CVE-2021-31216
Siren Investigate before 11.1.1 contains a server side request forgery (SSRF) defect in the built-in image proxy route (which is enabled by default).…
Investigate
11.1.1+
MEDIUM 5.4
CVE-2021-29749
IBM Secure External Authentication Server 6.0.2 and IBM Secure Proxy 6.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an aut…
Secure External Authentication Server
Patch available
CRITICAL 9.1
CVE-2021-34473 KEVEPSS 100%
Microsoft Exchange Server Remote Code Execution Vulnerability
Exchange Server
Patch available
MEDIUM 6.5
CVE-2021-33213
An SSRF vulnerability in the "Upload from URL" feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated users to retrieve HTTP and FTP…
Http Commander
No fix yet
HIGH 7.5
CVE-2020-23079
SSRF vulnerability in Halo <=1.3.2 exists in the SMTP configuration, which can detect the server intranet.
Halo
after 1.3.2
CRITICAL 9.1
CVE-2021-29102
A Server-Side Request Forgery (SSRF) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote, unauthenticated attacker to …
Arcgis Server
10.9.0+
HIGH 7.5
CVE-2020-20582
A server side request forgery (SSRF) vulnerability in /ApiAdminDomainSettings.php of MipCMS 5.0.1 allows attackers to access sensitive information.
Mipcms
No fix yet
MEDIUM 5.3
CVE-2020-24141
Server-side request forgery in the WP-DownloadManager plugin 1.68.4 for WordPress lets an attacker send crafted requests from the back-end server of …
Wp Downloadmanager
Mitigation only
CRITICAL 9.8
CVE-2020-24142
Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker send crafted request…
Video Downloader For Tiktok
Mitigation only
CRITICAL 9.1
CVE-2020-24147
Server-side request forgery (SSR) vulnerability in the WP Smart Import (wp-smart-import) plugin 1.0.0 for WordPress via the file field.
Wp Smart Import
Mitigation only
CRITICAL 9.1
CVE-2020-24148EPSS 15%
Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the data parameter in a moove_rea…
Import Xml And Rss Feeds
Mitigation only
HIGH 7.5
CVE-2020-24149
Server-side request forgery (SSRF) in the Podcast Importer SecondLine (podcast-importer-secondline) plugin 1.1.4 for WordPress via the podcast_feed p…
Podcast Importer Secondline
No fix yet
CRITICAL 9.8
CVE-2021-35209
An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.x before 9.0.0 Patc…
Collaboration
8.8.15+
CRITICAL 9.9
CVE-2021-32639
Emissary is a P2P-based, data-driven workflow engine. Emissary version 6.4.0 is vulnerable to Server-Side Request Forgery (SSRF). In particular, the …
Emissary
after 6.4.0
CRITICAL 9.8
CVE-2021-31531
Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF).
Manageengine Servicedesk Plus Msp
10.5+
MEDIUM 5.3
CVE-2021-34808
Server-Side Request Forgery (SSRF) vulnerability in cgi component in Synology Media Server before 1.8.3-2881 allows remote attackers to access intran…
Media Server
1.8.3-2881+
MEDIUM 6.5
CVE-2021-20483
IBM Security Identity Manager 6.0.2 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticat…
Security Identity Manager
Patch available
CRITICAL 9.8
CVE-2021-32682EPSS 70%
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnera…
Elfinder
2.1.59+
CRITICAL 9.8
CVE-2021-22175 KEVEPSS 53%
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting…
GitLab
13.6.7 / 13.7.7+
CRITICAL 9.8
CVE-2020-15377
Webtools in Brocade SANnav before version 2.1.1 allows unauthenticated users to make requests to arbitrary hosts due to a misconfiguration; this is c…
Sannav
2.1.1+
HIGH 7.6
CVE-2021-31950
Microsoft SharePoint Server Spoofing Vulnerability
Sharepoint Foundation
Patch available
HIGH 7.5
CVE-2021-33571EPSS 5%
In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit…
Django
2.2.24 / 3.1.12+
HIGH 8.6
CVE-2021-22214EPSS 28%
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions st…
GitLab
13.10.5 / 13.11.5+
HIGH 7.5
CVE-2020-35970
An issue was discovered in YzmCMS 5.8. There is a SSRF vulnerability in the background collection management that allows arbitrary file read.
Yzmcms
No fix yet
MEDIUM 5.4
CVE-2021-20343
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se…
Collaborative Lifecycle Management
Patch available
MEDIUM 5.4
CVE-2021-20345
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se…
Collaborative Lifecycle Management
Patch available
MEDIUM 5.4
CVE-2021-20346
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se…
Collaborative Lifecycle Management
Patch available
MEDIUM 5.4
CVE-2021-20347
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se…
Collaborative Lifecycle Management
Patch available