Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 5.4 CVE-2021-20348 IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se… Collaborative Lifecycle Management Patch available Fix from $1,6002021-06-02 CRITICAL 9.1 CVE-2021-33181 Server-Side Request Forgery (SSRF) vulnerability in webapi component in Synology Video Station before 2.4.10-1632 allows remote authenticated users t… Video Station 2.4.10-1632+ Fix from $2,3002021-06-01 HIGH 7.7 CVE-2021-33184 Server-Side request forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.15-3563 allows remote authentic… Download Station 3.8.15-3563+ Fix from $1,9502021-06-01 MEDIUM 6.1 CVE-2021-25640 In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or S… Dubbo 2.6.9 / 2.7.9+ Fix from $1,6002021-06-01 MEDIUM 5.5 CVE-2020-14327 A Server-side request forgery (SSRF) flaw was found in Ansible Tower in versions before 3.6.5 and before 3.7.2. Functionality on the Tower server is … Ansible Tower 3.6.5 / 3.7.2+ Fix from $1,6002021-05-27 CRITICAL 9.8 CVE-2021-21985 KEVEPSS 100% The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in whi… Vcenter Server 3.10.2.1 / 4.2.1+ Fix from $2,3002021-05-26 CRITICAL 9.1 CVE-2021-30108 Feehi CMS 2.1.1 is affected by a Server-side request forgery (SSRF) vulnerability. When the user modifies the HTTP Referer header to any url, the ser… Feehi Cms No fix yet Fix from $2,3002021-05-24 HIGH 7.5 CVE-2021-33511 Plone though 5.2.4 allows SSRF via the lxml parser. This affects Diazo themes, Dexterity TTW schemas, and modeleditors in plone.app.theming, plone.ap… Plone after 5.2.4 Fix from $1,9502021-05-21 CRITICAL 9.8 CVE-2017-17674 BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be… Remedy Mid Tier Mitigation only Fix from $2,3002021-05-19 MEDIUM 5.4 CVE-2021-20535 IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attack… Jazz Reporting Service Mitigation only Fix from $1,6002021-05-13 HIGH 7.5 CVE-2021-31910 In JetBrains TeamCity before 2020.2.3, information disclosure via SSRF was possible. Teamcity 2020.2.3+ Fix from $1,9502021-05-11 HIGH 7.1 CVE-2021-31828 An SSRF issue in Open Distro for Elasticsearch (ODFE) before 1.13.1.0 allows an existing privileged user to enumerate listening services or interact … Open Distro 1.13.1.0+ Fix from $1,9502021-05-06 MEDIUM 5.8 CVE-2021-29490EPSS 70% Jellyfin is a free software media system that provides media from a dedicated server to end-user devices via multiple apps. Verions prior to 10.7.3 v… Jellyfin 10.7.3+ Fix from $1,6002021-05-06 MEDIUM 6.5 CVE-2020-28943 OX App Suite 7.10.4 and earlier allows SSRF via a snippet. Open Xchange Appsuite after 7.10.4 Fix from $1,6002021-04-30 HIGH 7.5 CVE-2020-22002 An Unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Inim Electronics Smartliving SmartLAN/G/SI <=6.x within the GetImage fu… Smartliving 505 Firmware No fix yet Fix from $1,9502021-04-29 CRITICAL 9.8 CVE-2021-29145 A remote server side request forgery (SSRF) remote code execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to … Clearpass 6.7.14 / 6.8.6+ Fix from $2,3002021-04-29 MEDIUM 6.4 CVE-2021-31779 The yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows SSRF via a backend user account. Yoast Seo 7.2.1+ Fix from $1,6002021-04-28 CRITICAL 10.0 CVE-2021-29475 HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker is able to receive arbitrary files from the file sys… Hedgedoc 1.5.0+ Fix from $2,3002021-04-26 CRITICAL 9.8 CVE-2020-35313EPSS 45% A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attac… Wondercms No fix yet Fix from $2,3002021-04-20 MEDIUM 6.5 CVE-2021-29431 Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due to lack of parameter validatio… Sydent 2.3.0+ Fix from $1,6002021-04-15 MEDIUM 5.3 CVE-2021-28060 A Server-Side Request Forgery (SSRF) vulnerability in Group Office 6.4.196 allows a remote attacker to forge GET requests to arbitrary URLs via the u… Group Office No fix yet Fix from $1,6002021-04-14 CRITICAL 9.8 CVE-2021-27905EPSS 93% The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter … Solr 8.8.2+ Fix from $2,3002021-04-13 HIGH 8.6 CVE-2021-29357 The ECT Provider component in OutSystems Platform Server 10 before 10.0.1104.0 and 11 before 11.9.0 (and LifeTime management console before 11.7.0) a… Lifetime Management Console 10.0.1104.0 / 11.7.0+ Fix from $1,9502021-04-12 MEDIUM 6.5 CVE-2021-20480 IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a rem… Websphere Application Server after 8.5.5.19 Fix from $1,6002021-04-08 HIGH 8.3 CVE-2020-24139 Server-side request forgery in Wcms 0.3.2 lets an attacker send crafted requests from the back-end server of a vulnerable web application via the pat… Wcms No fix yet Fix from $1,9502021-04-07 HIGH 8.3 CVE-2020-24140 Server-side request forgery in Wcms 0.3.2 let an attacker send crafted requests from the back-end server of a vulnerable web application via the page… Wcms No fix yet Fix from $1,9502021-04-07 HIGH 7.5 CVE-2021-24150 The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request For… Likebtn Like Button 2.6.32+ Fix from $1,9502021-04-05 MEDIUM 5.3 CVE-2021-28941 Because of no validation on a curl command in MagpieRSS 0.72 in the /extlib/Snoopy.class.inc file, when you send a request to the /scripts/magpie_deb… Magpierss No fix yet Fix from $1,6002021-04-02 HIGH 7.5 CVE-2021-22696EPSS 7% CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization F… Cxf 3.3.10 / 3.4.3+ Fix from $1,9502021-04-02 HIGH 7.5 CVE-2020-19613 Server Side Request Forgery (SSRF) vulnerability in saveUrlAs function in ImagesService.java in sunkaifei FlyCMS version 20190503. Flycms No fix yet Fix from $1,9502021-04-01