Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2021-20348
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se…
Collaborative Lifecycle Management
Patch available
CRITICAL 9.1
CVE-2021-33181
Server-Side Request Forgery (SSRF) vulnerability in webapi component in Synology Video Station before 2.4.10-1632 allows remote authenticated users t…
Video Station
2.4.10-1632+
HIGH 7.7
CVE-2021-33184
Server-Side request forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.15-3563 allows remote authentic…
Download Station
3.8.15-3563+
MEDIUM 6.1
CVE-2021-25640
In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or S…
Dubbo
2.6.9 / 2.7.9+
MEDIUM 5.5
CVE-2020-14327
A Server-side request forgery (SSRF) flaw was found in Ansible Tower in versions before 3.6.5 and before 3.7.2. Functionality on the Tower server is …
Ansible Tower
3.6.5 / 3.7.2+
CRITICAL 9.8
CVE-2021-21985 KEVEPSS 100%
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in whi…
Vcenter Server
3.10.2.1 / 4.2.1+
CRITICAL 9.1
CVE-2021-30108
Feehi CMS 2.1.1 is affected by a Server-side request forgery (SSRF) vulnerability. When the user modifies the HTTP Referer header to any url, the ser…
Feehi Cms
No fix yet
HIGH 7.5
CVE-2021-33511
Plone though 5.2.4 allows SSRF via the lxml parser. This affects Diazo themes, Dexterity TTW schemas, and modeleditors in plone.app.theming, plone.ap…
Plone
after 5.2.4
CRITICAL 9.8
CVE-2017-17674
BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be…
Remedy Mid Tier
Mitigation only
MEDIUM 5.4
CVE-2021-20535
IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attack…
Jazz Reporting Service
Mitigation only
HIGH 7.5
CVE-2021-31910
In JetBrains TeamCity before 2020.2.3, information disclosure via SSRF was possible.
Teamcity
2020.2.3+
HIGH 7.1
CVE-2021-31828
An SSRF issue in Open Distro for Elasticsearch (ODFE) before 1.13.1.0 allows an existing privileged user to enumerate listening services or interact …
Open Distro
1.13.1.0+
MEDIUM 5.8
CVE-2021-29490EPSS 70%
Jellyfin is a free software media system that provides media from a dedicated server to end-user devices via multiple apps. Verions prior to 10.7.3 v…
Jellyfin
10.7.3+
MEDIUM 6.5
CVE-2020-28943
OX App Suite 7.10.4 and earlier allows SSRF via a snippet.
Open Xchange Appsuite
after 7.10.4
HIGH 7.5
CVE-2020-22002
An Unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Inim Electronics Smartliving SmartLAN/G/SI <=6.x within the GetImage fu…
Smartliving 505 Firmware
No fix yet
CRITICAL 9.8
CVE-2021-29145
A remote server side request forgery (SSRF) remote code execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to …
Clearpass
6.7.14 / 6.8.6+
MEDIUM 6.4
CVE-2021-31779
The yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows SSRF via a backend user account.
Yoast Seo
7.2.1+
CRITICAL 10.0
CVE-2021-29475
HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker is able to receive arbitrary files from the file sys…
Hedgedoc
1.5.0+
CRITICAL 9.8
CVE-2020-35313EPSS 45%
A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attac…
Wondercms
No fix yet
MEDIUM 6.5
CVE-2021-29431
Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due to lack of parameter validatio…
Sydent
2.3.0+
MEDIUM 5.3
CVE-2021-28060
A Server-Side Request Forgery (SSRF) vulnerability in Group Office 6.4.196 allows a remote attacker to forge GET requests to arbitrary URLs via the u…
Group Office
No fix yet
CRITICAL 9.8
CVE-2021-27905EPSS 93%
The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter …
Solr
8.8.2+
HIGH 8.6
CVE-2021-29357
The ECT Provider component in OutSystems Platform Server 10 before 10.0.1104.0 and 11 before 11.9.0 (and LifeTime management console before 11.7.0) a…
Lifetime Management Console
10.0.1104.0 / 11.7.0+
MEDIUM 6.5
CVE-2021-20480
IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a rem…
Websphere Application Server
after 8.5.5.19
HIGH 8.3
CVE-2020-24139
Server-side request forgery in Wcms 0.3.2 lets an attacker send crafted requests from the back-end server of a vulnerable web application via the pat…
Wcms
No fix yet
HIGH 8.3
CVE-2020-24140
Server-side request forgery in Wcms 0.3.2 let an attacker send crafted requests from the back-end server of a vulnerable web application via the page…
Wcms
No fix yet
HIGH 7.5
CVE-2021-24150
The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request For…
Likebtn Like Button
2.6.32+
MEDIUM 5.3
CVE-2021-28941
Because of no validation on a curl command in MagpieRSS 0.72 in the /extlib/Snoopy.class.inc file, when you send a request to the /scripts/magpie_deb…
Magpierss
No fix yet
HIGH 7.5
CVE-2021-22696EPSS 7%
CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization F…
Cxf
3.3.10 / 3.4.3+
HIGH 7.5
CVE-2020-19613
Server Side Request Forgery (SSRF) vulnerability in saveUrlAs function in ImagesService.java in sunkaifei FlyCMS version 20190503.
Flycms
No fix yet