Vulnerability index

Browse CVEs

2,859 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 5.3 CVE-2021-28060 A Server-Side Request Forgery (SSRF) vulnerability in Group Office 6.4.196 allows a remote attacker to forge GET requests to arbitrary URLs via the u… Group Office No fix yet Fix from $1,6002021-04-14 CRITICAL 9.8 CVE-2021-27905EPSS 93% The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter … Solr 8.8.2+ Fix from $2,3002021-04-13 HIGH 8.6 CVE-2021-29357 The ECT Provider component in OutSystems Platform Server 10 before 10.0.1104.0 and 11 before 11.9.0 (and LifeTime management console before 11.7.0) a… Lifetime Management Console 10.0.1104.0 / 11.7.0+ Fix from $1,9502021-04-12 MEDIUM 6.5 CVE-2021-20480 IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a rem… Websphere Application Server after 8.5.5.19 Fix from $1,6002021-04-08 HIGH 8.3 CVE-2020-24139 Server-side request forgery in Wcms 0.3.2 lets an attacker send crafted requests from the back-end server of a vulnerable web application via the pat… Wcms No fix yet Fix from $1,9502021-04-07 HIGH 8.3 CVE-2020-24140 Server-side request forgery in Wcms 0.3.2 let an attacker send crafted requests from the back-end server of a vulnerable web application via the page… Wcms No fix yet Fix from $1,9502021-04-07 HIGH 7.5 CVE-2021-24150 The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request For… Likebtn Like Button 2.6.32+ Fix from $1,9502021-04-05 MEDIUM 5.3 CVE-2021-28941 Because of no validation on a curl command in MagpieRSS 0.72 in the /extlib/Snoopy.class.inc file, when you send a request to the /scripts/magpie_deb… Magpierss No fix yet Fix from $1,6002021-04-02 HIGH 7.5 CVE-2021-22696EPSS 7% CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization F… Cxf 3.3.10 / 3.4.3+ Fix from $1,9502021-04-02 HIGH 7.5 CVE-2020-19613 Server Side Request Forgery (SSRF) vulnerability in saveUrlAs function in ImagesService.java in sunkaifei FlyCMS version 20190503. Flycms No fix yet Fix from $1,9502021-04-01 HIGH 7.5 CVE-2021-21975 KEVEPSS 78% Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the v… Cloud Foundation Mitigation only Fix from $1,9502021-03-31 CRITICAL 9.8 CVE-2021-22986 KEVEPSS 100% On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-I… Big Ip Access Policy Manager 12.1.5.3 / 13.1.3.6+ Fix from $2,3002021-03-31 CRITICAL 9.8 CVE-2021-1627 MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub… Mule after 4.2.2 Fix from $2,3002021-03-26 CRITICAL 9.1 CVE-2021-26715 The OpenID Connect server implementation for MITREid Connect through 1.3.3 contains a Server Side Request Forgery (SSRF) vulnerability. The vulnerabi… Connect after 1.3.3 Fix from $2,3002021-03-25 MEDIUM 6.5 CVE-2020-15809 spxmanage on certain SpinetiX devices allows requests that access unintended resources because of SSRF and Path Traversal. This affects HMP350, HMP30… Dsos after 4.5.2-1.0.36229 Fix from $1,6002021-03-24 MEDIUM 5.0 CVE-2021-22178 An issue has been discovered in GitLab affecting all versions starting from 13.2. Gitlab was vulnerable to SRRF attack through the Prometheus integra… GitLab 13.6.7 / 13.7.7+ Fix from $1,6002021-03-24 MEDIUM 5.4 CVE-2021-22179 A vulnerability was discovered in GitLab versions before 12.2. GitLab was vulnerable to a SSRF attack through the Outbound Requests feature. GitLab 13.6.6 / 13.7.6+ Fix from $1,6002021-03-24 HIGH 8.6 CVE-2021-21349EPSS 47% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $1,9502021-03-23 CRITICAL 9.1 CVE-2021-21342EPSS 50% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed … Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 MEDIUM 6.1 CVE-2020-4882 IBM Planning Analytics 2.0 could be vulnerable to a Server-Side Request Forgery (SSRF) attack by constucting URLs from user-controlled data . This co… Planning Analytics Mitigation only Fix from $1,6002021-03-22 MEDIUM 6.7 CVE-2020-5014 IBM DataPower Gateway V10 and V2018 could allow a local attacker with administrative privileges to execute arbitrary code on the system using a serve… Datapower Gateway after 2018.4.1.14 Fix from $1,6002021-03-08 CRITICAL 9.1 CVE-2021-26855 KEVEPSS 100% Microsoft Exchange Server Remote Code Execution Vulnerability Exchange Server Patch available Fix from $2,3002021-03-03 MEDIUM 5.3 CVE-2020-12529 An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2 There is a SSRF in the LDAP access c… Mbconnect24 after 2.6.2 Fix from $1,6002021-03-02 MEDIUM 5.3 CVE-2021-23345 All versions of package github.com/thecodingmachine/gotenberg are vulnerable to Server-side Request Forgery (SSRF) via the /convert/html endpoint whe… Gotenberg No fix yet Fix from $1,6002021-02-26 CRITICAL 9.8 CVE-2020-23534 A server-side request forgery (SSRF) vulnerability in Upgrade.php of gopeak masterlab 2.1.5, via the 'source' parameter. Masterlab No fix yet Fix from $2,3002021-02-25 CRITICAL 9.8 CVE-2021-27670EPSS 61% Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter. Appspace No fix yet Fix from $2,3002021-02-25 HIGH 8.2 CVE-2020-11987EPSS 14% Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-craf… Batik after 1.13 Fix from $1,9502021-02-24 HIGH 8.2 CVE-2020-11988EPSS 7% Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By usi… Xmlgraphics Commons after 2.4 Fix from $1,9502021-02-24 MEDIUM 5.3 CVE-2021-21973 KEVEPSS 88% The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin… Cloud Foundation 3.10.1.2 / 4.2+ Fix from $1,6002021-02-24 MEDIUM 5.0 CVE-2020-36232 The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, f… Atlassian Gadgets 4.2.37 / 4.3.2.4+ Fix from $1,6002021-02-22