Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 5.4 CVE-2021-26699 OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled by the imageconverter componen… Open Xchange Appsuite No fix yet Fix from $1,6002021-07-22 HIGH 8.1 CVE-2021-22726 A CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Pa… Evlink City Evc1s22p4 Firmware Mitigation only Fix from $1,9502021-07-21 HIGH 8.1 CVE-2021-31216 Siren Investigate before 11.1.1 contains a server side request forgery (SSRF) defect in the built-in image proxy route (which is enabled by default).… Investigate 11.1.1+ Fix from $1,9502021-07-19 MEDIUM 5.4 CVE-2021-29749 IBM Secure External Authentication Server 6.0.2 and IBM Secure Proxy 6.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an aut… Secure External Authentication Server Patch available Fix from $1,6002021-07-15 CRITICAL 9.1 CVE-2021-34473 KEVEPSS 100% Microsoft Exchange Server Remote Code Execution Vulnerability Exchange Server Patch available Fix from $2,3002021-07-14 MEDIUM 6.5 CVE-2021-33213 An SSRF vulnerability in the "Upload from URL" feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated users to retrieve HTTP and FTP… Http Commander No fix yet Fix from $1,6002021-07-14 HIGH 7.5 CVE-2020-23079 SSRF vulnerability in Halo <=1.3.2 exists in the SMTP configuration, which can detect the server intranet. Halo after 1.3.2 Fix from $1,9502021-07-12 CRITICAL 9.1 CVE-2021-29102 A Server-Side Request Forgery (SSRF) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote, unauthenticated attacker to … Arcgis Server 10.9.0+ Fix from $2,3002021-07-11 HIGH 7.5 CVE-2020-20582 A server side request forgery (SSRF) vulnerability in /ApiAdminDomainSettings.php of MipCMS 5.0.1 allows attackers to access sensitive information. Mipcms No fix yet Fix from $1,9502021-07-08 MEDIUM 5.3 CVE-2020-24141 Server-side request forgery in the WP-DownloadManager plugin 1.68.4 for WordPress lets an attacker send crafted requests from the back-end server of … Wp Downloadmanager Mitigation only Fix from $1,6002021-07-07 CRITICAL 9.8 CVE-2020-24142 Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker send crafted request… Video Downloader For Tiktok Mitigation only Fix from $2,3002021-07-07 CRITICAL 9.1 CVE-2020-24147 Server-side request forgery (SSR) vulnerability in the WP Smart Import (wp-smart-import) plugin 1.0.0 for WordPress via the file field. Wp Smart Import Mitigation only Fix from $2,3002021-07-07 CRITICAL 9.1 CVE-2020-24148EPSS 15% Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the data parameter in a moove_rea… Import Xml And Rss Feeds Mitigation only Fix from $2,3002021-07-07 HIGH 7.5 CVE-2020-24149 Server-side request forgery (SSRF) in the Podcast Importer SecondLine (podcast-importer-secondline) plugin 1.1.4 for WordPress via the podcast_feed p… Podcast Importer Secondline No fix yet Fix from $1,9502021-07-07 CRITICAL 9.8 CVE-2021-35209 An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.x before 9.0.0 Patc… Collaboration 8.8.15+ Fix from $2,3002021-07-02 CRITICAL 9.9 CVE-2021-32639 Emissary is a P2P-based, data-driven workflow engine. Emissary version 6.4.0 is vulnerable to Server-Side Request Forgery (SSRF). In particular, the … Emissary after 6.4.0 Fix from $2,3002021-07-02 CRITICAL 9.8 CVE-2021-31531 Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF). Manageengine Servicedesk Plus Msp 10.5+ Fix from $2,3002021-06-29 MEDIUM 5.3 CVE-2021-34808 Server-Side Request Forgery (SSRF) vulnerability in cgi component in Synology Media Server before 1.8.3-2881 allows remote attackers to access intran… Media Server 1.8.3-2881+ Fix from $1,6002021-06-18 MEDIUM 6.5 CVE-2021-20483 IBM Security Identity Manager 6.0.2 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticat… Security Identity Manager Patch available Fix from $1,6002021-06-16 CRITICAL 9.8 CVE-2021-32682EPSS 70% elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnera… Elfinder 2.1.59+ Fix from $2,3002021-06-14 CRITICAL 9.8 CVE-2021-22175 KEVEPSS 53% When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting… GitLab 13.6.7 / 13.7.7+ Fix from $2,3002021-06-11 CRITICAL 9.8 CVE-2020-15377 Webtools in Brocade SANnav before version 2.1.1 allows unauthenticated users to make requests to arbitrary hosts due to a misconfiguration; this is c… Sannav 2.1.1+ Fix from $2,3002021-06-09 HIGH 7.6 CVE-2021-31950 Microsoft SharePoint Server Spoofing Vulnerability Sharepoint Foundation Patch available Fix from $1,9502021-06-08 HIGH 7.5 CVE-2021-33571EPSS 5% In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit… Django 2.2.24 / 3.1.12+ Fix from $1,9502021-06-08 HIGH 8.6 CVE-2021-22214EPSS 28% When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions st… GitLab 13.10.5 / 13.11.5+ Fix from $1,9502021-06-08 HIGH 7.5 CVE-2020-35970 An issue was discovered in YzmCMS 5.8. There is a SSRF vulnerability in the background collection management that allows arbitrary file read. Yzmcms No fix yet Fix from $1,9502021-06-03 MEDIUM 5.4 CVE-2021-20343 IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se… Collaborative Lifecycle Management Patch available Fix from $1,6002021-06-02 MEDIUM 5.4 CVE-2021-20345 IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se… Collaborative Lifecycle Management Patch available Fix from $1,6002021-06-02 MEDIUM 5.4 CVE-2021-20346 IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se… Collaborative Lifecycle Management Patch available Fix from $1,6002021-06-02 MEDIUM 5.4 CVE-2021-20347 IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se… Collaborative Lifecycle Management Patch available Fix from $1,6002021-06-02