Vulnerability index

Browse CVEs

2,859 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 5.8 CVE-2020-24444 AEM Forms SP6 add-on for AEM 6.5.6.0 and Forms add-on package for AEM 6.4 Service Pack 8 Cumulative Fix Pack 2 (6.4.8.2) have a blind Server-Side Req… Experience Manager Forms Add On Mitigation only Fix from $1,6002020-12-10 MEDIUM 5.3 CVE-2020-28976EPSS 28% The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal an… Canto No fix yet Fix from $1,6002020-11-30 MEDIUM 5.3 CVE-2020-28977EPSS 15% The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and … Canto No fix yet Fix from $1,6002020-11-30 MEDIUM 5.3 CVE-2020-28978EPSS 15% The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and … Canto No fix yet Fix from $1,6002020-11-30 MEDIUM 6.5 CVE-2020-24815 A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2 allows authen… Microstrategy No fix yet Fix from $1,6002020-11-24 CRITICAL 9.8 CVE-2020-28360 Insufficient RegEx in private-ip npm package v1.0.5 and below insufficiently filters reserved IP ranges resulting in indeterminate SSRF. An attacker … Private Ip after 1.0.5 Fix from $2,3002020-11-23 MEDIUM 5.3 CVE-2020-27624 JetBrains YouTrack before 2020.3.888 was vulnerable to SSRF. Youtrack 2020.3.888+ Fix from $1,6002020-11-16 MEDIUM 5.3 CVE-2020-27626 JetBrains YouTrack before 2020.3.5333 was vulnerable to SSRF. Youtrack 2020.3.5333+ Fix from $1,6002020-11-16 HIGH 7.5 CVE-2019-17566EPSS 11% Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-c… Batik 1.13+ Fix from $1,9502020-11-12 HIGH 7.2 CVE-2020-7329 Server-side request forgery vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers trigger server-side … Mvision Endpoint 20.11+ Fix from $1,9502020-11-11 HIGH 7.2 CVE-2020-7328 External entity attack vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers to gain control of a reso… Mvision Endpoint 20.11+ Fix from $1,9502020-11-11 HIGH 7.2 CVE-2020-24063 The Canto plugin 1.3.0 for WordPress allows includes/lib/download.php?subdomain= SSRF. Canto Mitigation only Fix from $1,9502020-11-10 MEDIUM 5.3 CVE-2020-26811 SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over… Commerce Cloud \(accelerator Payment Mock\) No fix yet Fix from $1,6002020-11-10 HIGH 8.6 CVE-2020-26815 SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send a crafted request to a vulne… Fiori Launchpad \(news Tile Application\) Mitigation only Fix from $1,9502020-11-10 MEDIUM 5.5 CVE-2020-27018 Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a server side request forgery vulnerability which could allow… Interscan Messaging Security Virtual Appliance after 9.1 Fix from $1,6002020-11-09 CRITICAL 9.1 CVE-2020-15297 Insufficient validation in the Bitdefender Update Server and BEST Relay components of Bitdefender Endpoint Security Tools versions prior to 6.6.20.29… Update Server 6.6.20.294+ Fix from $2,3002020-11-09 MEDIUM 5.9 CVE-2020-28168 Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL t… Axios 1.0+ Fix from $1,6002020-11-06 HIGH 7.5 CVE-2020-28043 MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL. Misp after 2.4.133 Fix from $1,9502020-11-02 CRITICAL 9.8 CVE-2020-24881EPSS 73% SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning. Osticket 1.14.3+ Fix from $2,3002020-11-02 MEDIUM 5.3 CVE-2020-24710 Gophish before 0.11.0 allows SSRF attacks. Gophish 0.11.0+ Fix from $1,6002020-10-28 MEDIUM 5.8 CVE-2020-7126 A remote server-side request forgery (ssrf) vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. Airwave Glass 1.3.2+ Fix from $1,6002020-10-26 CRITICAL 9.8 CVE-2020-25466 A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execu… Crmeb Mitigation only Fix from $2,3002020-10-23 MEDIUM 5.0 CVE-2020-15002 OX App Suite through 7.10.3 allows SSRF via the the /ajax/messaging/message message API. Open Xchange Appsuite after 7.10.3 Fix from $1,6002020-10-23 MEDIUM 6.5 CVE-2020-25820EPSS 10% BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document that has a … Bigbluebutton 2.2.27+ Fix from $1,6002020-10-21 MEDIUM 5.3 CVE-2020-6308EPSS 62% SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary va… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002020-10-20 HIGH 7.3 CVE-2020-15822 In JetBrains YouTrack before 2020.2.10514, SSRF is possible because URL filtering can be escaped. Youtrack 2020.2.10514+ Fix from $1,9502020-10-19 CRITICAL 9.8 CVE-2020-27197 TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the… Opentaxii after 1.1.117 Fix from $2,3002020-10-17 CRITICAL 9.8 CVE-2020-26948EPSS 87% Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter. Emby 4.5.0+ Fix from $2,3002020-10-10 HIGH 8.2 CVE-2020-7740 This affects all versions of package node-pdf-generator. Due to lack of user input validation and sanitization done to the content given to node-pdf-… Node Pdf Generator Mitigation only Fix from $1,9502020-10-06 HIGH 8.2 CVE-2020-7739 This affects all versions of package phantomjs-seo. It is possible for an attacker to craft a url that will be passed to a PhantomJS instance allowin… Phantomjs Seo Patch available Fix from $1,9502020-10-06