Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.1
CVE-2021-27214
A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote …
Manageengine Adselfservice Plus
No fix yet
MEDIUM 6.5
CVE-2021-3204
SSRF in the document conversion component of Webware Webdesktop 5.1.15 allows an attacker to read all files from the server.
Webdesktop
No fix yet
HIGH 8.3
CVE-2020-10252
An issue was discovered in ownCloud before 10.4. Because of an SSRF issue (via the apps/files_sharing/external remote parameter), an authenticated at…
Owncloud
10.4.0+
CRITICAL 10.0
CVE-2021-27329
Friendica 2021.01 allows SSRF via parse_url?binurl= for DNS lookups or HTTP requests to arbitrary domain names.
Frendica
Mitigation only
MEDIUM 6.5
CVE-2020-28463
All versions of package reportlab are vulnerable to Server-side Request Forgery (SSRF) via img tags. In order to reduce risk, use trustedSchemes & tr…
Fedora
No fix yet
CRITICAL 9.8
CVE-2021-27103 KEVEPSS 11%
Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later.
Fta
9_12_416+
HIGH 7.5
CVE-2020-35558
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. There is an SSRF in th…
Mbconnect24
after 2.11.2
MEDIUM 5.3
CVE-2020-35561
An issue was discovered MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. There is…
Mbconnect24
after 2.11.2
HIGH 7.2
CVE-2021-21311 KEVEPSS 90%
Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request for…
Debian Linux
4.7.9+
MEDIUM 5.3
CVE-2021-25241
A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 could all…
Apex One
Patch available
MEDIUM 5.3
CVE-2021-25236
A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro OfficeScan XG SP1 and Worry-Free Business Security 10.0 SP1 …
Officescan
Patch available
HIGH 7.5
CVE-2020-35667
JetBrains TeamCity Plugin before 2020.2.85695 SSRF. Vulnerability that could potentially expose user credentials.
Teamcity
2020.2.85695+
HIGH 7.7
CVE-2021-21287EPSS 25%
MinIO is a High Performance Object Storage released under Apache License v2.0. In MinIO before version RELEASE.2021-01-30T00-20-58Z there is a server…
Minio
2021-01-30t00-20-58z+
HIGH 7.5
CVE-2020-23776
A SSRF vulnerability exists in Winmail 6.5 in app.php in the key parameter when HTTPS is on. An attacker can use this vulnerability to cause the serv…
Winmail
No fix yet
MEDIUM 6.5
CVE-2020-36200
TinyCheck before commits 9fd360d and ea53de8 allowed an authenticated attacker to send an HTTP GET request to the crafted URLs.
Tinycheck
2020-12-18+
HIGH 8.8
CVE-2021-1272
A vulnerability in the session validation feature of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypa…
Data Center Network Manager
11.5+
HIGH 7.5
CVE-2020-24641
In Aruba AirWave Glass before 1.3.3, there is a Server-Side Request Forgery vulnerability through an unauthenticated endpoint that if successfully ex…
Airwave Glass
1.3.3+
HIGH 8.6
CVE-2021-21009
Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier), 19.2.3 (and earlier) and 19.…
Campaign Classic
after 20.3.1
MEDIUM 6.4
CVE-2021-23927
OX App Suite through 7.10.4 allows SSRF via a URL with an @ character in an appsuite/api/oauth/proxy PUT request.
Open Xchange Appsuite
after 7.10.4
MEDIUM 5.4
CVE-2020-24700
OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconfig. substring.
Open Xchange Appsuite
after 7.10.3
CRITICAL 9.8
CVE-2020-35205
Server Side Request Forgery (SSRF) in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to scan internal ports and …
Policy Authority For Unified Communications
No fix yet
HIGH 8.8
CVE-2020-28735
Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).
Plone
5.2.3+
MEDIUM 6.5
CVE-2020-35850
An SSRF issue was discovered in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product. NOTE: the vendor states "I …
Cockpit
No fix yet
HIGH 7.5
CVE-2020-26032
An SSRF issue was discovered in Zammad before 3.4.1. The SMS configuration interface for Massenversand is implemented in a way that renders the resul…
Zammad
3.4.1+
CRITICAL 9.8
CVE-2020-35712
Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations.
Arcgis Server
10.8+
HIGH 7.5
CVE-2020-8464EPSS 6%
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to send requests that appear to come from the…
Interscan Web Security Virtual Appliance
No fix yet
MEDIUM 6.5
CVE-2019-14476
AdRem NetCrunch 10.6.0.4587 has a Server-Side Request Forgery (SSRF) vulnerability in the NetCrunch server. Every user can trick the server into perf…
Netcrunch
No fix yet
HIGH 7.7
CVE-2020-26258EPSS 82%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability c…
Struts
1.4.15 / 6.0.0+
MEDIUM 5.3
CVE-2020-10770EPSS 70%
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_u…
Keycloak
12.0.2+
MEDIUM 5.3
CVE-2020-17513
In Apache Airflow versions prior to 1.10.13, the Charts and Query View of the old (Flask-admin based) UI were vulnerable for SSRF attack.
Airflow
1.10.13+