Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2021-28060
A Server-Side Request Forgery (SSRF) vulnerability in Group Office 6.4.196 allows a remote attacker to forge GET requests to arbitrary URLs via the u…
Group Office
No fix yet
CRITICAL 9.8
CVE-2021-27905EPSS 93%
The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter …
Solr
8.8.2+
HIGH 8.6
CVE-2021-29357
The ECT Provider component in OutSystems Platform Server 10 before 10.0.1104.0 and 11 before 11.9.0 (and LifeTime management console before 11.7.0) a…
Lifetime Management Console
10.0.1104.0 / 11.7.0+
MEDIUM 6.5
CVE-2021-20480
IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a rem…
Websphere Application Server
after 8.5.5.19
HIGH 8.3
CVE-2020-24139
Server-side request forgery in Wcms 0.3.2 lets an attacker send crafted requests from the back-end server of a vulnerable web application via the pat…
Wcms
No fix yet
HIGH 8.3
CVE-2020-24140
Server-side request forgery in Wcms 0.3.2 let an attacker send crafted requests from the back-end server of a vulnerable web application via the page…
Wcms
No fix yet
HIGH 7.5
CVE-2021-24150
The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request For…
Likebtn Like Button
2.6.32+
MEDIUM 5.3
CVE-2021-28941
Because of no validation on a curl command in MagpieRSS 0.72 in the /extlib/Snoopy.class.inc file, when you send a request to the /scripts/magpie_deb…
Magpierss
No fix yet
HIGH 7.5
CVE-2021-22696EPSS 7%
CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization F…
Cxf
3.3.10 / 3.4.3+
HIGH 7.5
CVE-2020-19613
Server Side Request Forgery (SSRF) vulnerability in saveUrlAs function in ImagesService.java in sunkaifei FlyCMS version 20190503.
Flycms
No fix yet
HIGH 7.5
CVE-2021-21975 KEVEPSS 78%
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the v…
Cloud Foundation
Mitigation only
CRITICAL 9.8
CVE-2021-22986 KEVEPSS 100%
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-I…
Big Ip Access Policy Manager
12.1.5.3 / 13.1.3.6+
CRITICAL 9.8
CVE-2021-1627
MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub…
Mule
after 4.2.2
CRITICAL 9.1
CVE-2021-26715
The OpenID Connect server implementation for MITREid Connect through 1.3.3 contains a Server Side Request Forgery (SSRF) vulnerability. The vulnerabi…
Connect
after 1.3.3
MEDIUM 6.5
CVE-2020-15809
spxmanage on certain SpinetiX devices allows requests that access unintended resources because of SSRF and Path Traversal. This affects HMP350, HMP30…
Dsos
after 4.5.2-1.0.36229
MEDIUM 5.0
CVE-2021-22178
An issue has been discovered in GitLab affecting all versions starting from 13.2. Gitlab was vulnerable to SRRF attack through the Prometheus integra…
GitLab
13.6.7 / 13.7.7+
MEDIUM 5.4
CVE-2021-22179
A vulnerability was discovered in GitLab versions before 12.2. GitLab was vulnerable to a SSRF attack through the Outbound Requests feature.
GitLab
13.6.6 / 13.7.6+
HIGH 8.6
CVE-2021-21349EPSS 47%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…
Activemq
1.4.16 / 5.5+
CRITICAL 9.1
CVE-2021-21342EPSS 50%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed …
Activemq
1.4.16 / 5.5+
MEDIUM 6.1
CVE-2020-4882
IBM Planning Analytics 2.0 could be vulnerable to a Server-Side Request Forgery (SSRF) attack by constucting URLs from user-controlled data . This co…
Planning Analytics
Mitigation only
MEDIUM 6.7
CVE-2020-5014
IBM DataPower Gateway V10 and V2018 could allow a local attacker with administrative privileges to execute arbitrary code on the system using a serve…
Datapower Gateway
after 2018.4.1.14
CRITICAL 9.1
CVE-2021-26855 KEVEPSS 100%
Microsoft Exchange Server Remote Code Execution Vulnerability
Exchange Server
Patch available
MEDIUM 5.3
CVE-2020-12529
An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2 There is a SSRF in the LDAP access c…
Mbconnect24
after 2.6.2
MEDIUM 5.3
CVE-2021-23345
All versions of package github.com/thecodingmachine/gotenberg are vulnerable to Server-side Request Forgery (SSRF) via the /convert/html endpoint whe…
Gotenberg
No fix yet
CRITICAL 9.8
CVE-2020-23534
A server-side request forgery (SSRF) vulnerability in Upgrade.php of gopeak masterlab 2.1.5, via the 'source' parameter.
Masterlab
No fix yet
CRITICAL 9.8
CVE-2021-27670EPSS 61%
Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.
Appspace
No fix yet
HIGH 8.2
CVE-2020-11987EPSS 14%
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-craf…
Batik
after 1.13
HIGH 8.2
CVE-2020-11988EPSS 7%
Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By usi…
Xmlgraphics Commons
after 2.4
MEDIUM 5.3
CVE-2021-21973 KEVEPSS 88%
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin…
Cloud Foundation
3.10.1.2 / 4.2+
MEDIUM 5.0
CVE-2020-36232
The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, f…
Atlassian Gadgets
4.2.37 / 4.3.2.4+