Vulnerability index

Browse CVEs

2,859 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 6.1 CVE-2021-27214 A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote … Manageengine Adselfservice Plus No fix yet Fix from $1,6002021-02-19 MEDIUM 6.5 CVE-2021-3204 SSRF in the document conversion component of Webware Webdesktop 5.1.15 allows an attacker to read all files from the server. Webdesktop No fix yet Fix from $1,6002021-02-19 HIGH 8.3 CVE-2020-10252 An issue was discovered in ownCloud before 10.4. Because of an SSRF issue (via the apps/files_sharing/external remote parameter), an authenticated at… Owncloud 10.4.0+ Fix from $1,9502021-02-19 CRITICAL 10.0 CVE-2021-27329 Friendica 2021.01 allows SSRF via parse_url?binurl= for DNS lookups or HTTP requests to arbitrary domain names. Frendica Mitigation only Fix from $2,3002021-02-18 MEDIUM 6.5 CVE-2020-28463 All versions of package reportlab are vulnerable to Server-side Request Forgery (SSRF) via img tags. In order to reduce risk, use trustedSchemes & tr… Fedora No fix yet Fix from $1,6002021-02-18 CRITICAL 9.8 CVE-2021-27103 KEVEPSS 11% Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later. Fta 9_12_416+ Fix from $2,3002021-02-16 HIGH 7.5 CVE-2020-35558 An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. There is an SSRF in th… Mbconnect24 after 2.11.2 Fix from $1,9502021-02-16 MEDIUM 5.3 CVE-2020-35561 An issue was discovered MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. There is… Mbconnect24 after 2.11.2 Fix from $1,6002021-02-16 HIGH 7.2 CVE-2021-21311 KEVEPSS 90% Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request for… Debian Linux 4.7.9+ Fix from $1,9502021-02-11 MEDIUM 5.3 CVE-2021-25241 A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 could all… Apex One Patch available Fix from $1,6002021-02-04 MEDIUM 5.3 CVE-2021-25236 A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro OfficeScan XG SP1 and Worry-Free Business Security 10.0 SP1 … Officescan Patch available Fix from $1,6002021-02-04 HIGH 7.5 CVE-2020-35667 JetBrains TeamCity Plugin before 2020.2.85695 SSRF. Vulnerability that could potentially expose user credentials. Teamcity 2020.2.85695+ Fix from $1,9502021-02-03 HIGH 7.7 CVE-2021-21287EPSS 25% MinIO is a High Performance Object Storage released under Apache License v2.0. In MinIO before version RELEASE.2021-01-30T00-20-58Z there is a server… Minio 2021-01-30t00-20-58z+ Fix from $1,9502021-02-01 HIGH 7.5 CVE-2020-23776 A SSRF vulnerability exists in Winmail 6.5 in app.php in the key parameter when HTTPS is on. An attacker can use this vulnerability to cause the serv… Winmail No fix yet Fix from $1,9502021-01-26 MEDIUM 6.5 CVE-2020-36200 TinyCheck before commits 9fd360d and ea53de8 allowed an authenticated attacker to send an HTTP GET request to the crafted URLs. Tinycheck 2020-12-18+ Fix from $1,6002021-01-26 HIGH 8.8 CVE-2021-1272 A vulnerability in the session validation feature of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypa… Data Center Network Manager 11.5+ Fix from $1,9502021-01-20 HIGH 7.5 CVE-2020-24641 In Aruba AirWave Glass before 1.3.3, there is a Server-Side Request Forgery vulnerability through an unauthenticated endpoint that if successfully ex… Airwave Glass 1.3.3+ Fix from $1,9502021-01-15 HIGH 8.6 CVE-2021-21009 Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier), 19.2.3 (and earlier) and 19.… Campaign Classic after 20.3.1 Fix from $1,9502021-01-13 MEDIUM 6.4 CVE-2021-23927 OX App Suite through 7.10.4 allows SSRF via a URL with an @ character in an appsuite/api/oauth/proxy PUT request. Open Xchange Appsuite after 7.10.4 Fix from $1,6002021-01-12 MEDIUM 5.4 CVE-2020-24700 OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconfig. substring. Open Xchange Appsuite after 7.10.3 Fix from $1,6002021-01-12 CRITICAL 9.8 CVE-2020-35205 Server Side Request Forgery (SSRF) in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to scan internal ports and … Policy Authority For Unified Communications No fix yet Fix from $2,3002021-01-11 HIGH 8.8 CVE-2020-28735 Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role). Plone 5.2.3+ Fix from $1,9502020-12-30 MEDIUM 6.5 CVE-2020-35850 An SSRF issue was discovered in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product. NOTE: the vendor states "I … Cockpit No fix yet Fix from $1,6002020-12-30 HIGH 7.5 CVE-2020-26032 An SSRF issue was discovered in Zammad before 3.4.1. The SMS configuration interface for Massenversand is implemented in a way that renders the resul… Zammad 3.4.1+ Fix from $1,9502020-12-28 CRITICAL 9.8 CVE-2020-35712 Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations. Arcgis Server 10.8+ Fix from $2,3002020-12-26 HIGH 7.5 CVE-2020-8464EPSS 6% A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to send requests that appear to come from the… Interscan Web Security Virtual Appliance No fix yet Fix from $1,9502020-12-17 MEDIUM 6.5 CVE-2019-14476 AdRem NetCrunch 10.6.0.4587 has a Server-Side Request Forgery (SSRF) vulnerability in the NetCrunch server. Every user can trick the server into perf… Netcrunch No fix yet Fix from $1,6002020-12-16 HIGH 7.7 CVE-2020-26258EPSS 82% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability c… Struts 1.4.15 / 6.0.0+ Fix from $1,9502020-12-16 MEDIUM 5.3 CVE-2020-10770EPSS 70% A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_u… Keycloak 12.0.2+ Fix from $1,6002020-12-15 MEDIUM 5.3 CVE-2020-17513 In Apache Airflow versions prior to 1.10.13, the Charts and Query View of the old (Flask-admin based) UI were vulnerable for SSRF attack. Airflow 1.10.13+ Fix from $1,6002020-12-14