Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.8
CVE-2020-24444
AEM Forms SP6 add-on for AEM 6.5.6.0 and Forms add-on package for AEM 6.4 Service Pack 8 Cumulative Fix Pack 2 (6.4.8.2) have a blind Server-Side Req…
Experience Manager Forms Add On
Mitigation only
MEDIUM 5.3
CVE-2020-28976EPSS 28%
The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal an…
Canto
No fix yet
MEDIUM 5.3
CVE-2020-28977EPSS 15%
The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and …
Canto
No fix yet
MEDIUM 5.3
CVE-2020-28978EPSS 15%
The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and …
Canto
No fix yet
MEDIUM 6.5
CVE-2020-24815
A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2 allows authen…
Microstrategy
No fix yet
CRITICAL 9.8
CVE-2020-28360
Insufficient RegEx in private-ip npm package v1.0.5 and below insufficiently filters reserved IP ranges resulting in indeterminate SSRF. An attacker …
Private Ip
after 1.0.5
MEDIUM 5.3
CVE-2020-27624
JetBrains YouTrack before 2020.3.888 was vulnerable to SSRF.
Youtrack
2020.3.888+
MEDIUM 5.3
CVE-2020-27626
JetBrains YouTrack before 2020.3.5333 was vulnerable to SSRF.
Youtrack
2020.3.5333+
HIGH 7.5
CVE-2019-17566EPSS 11%
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-c…
Batik
1.13+
HIGH 7.2
CVE-2020-7329
Server-side request forgery vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers trigger server-side …
Mvision Endpoint
20.11+
HIGH 7.2
CVE-2020-7328
External entity attack vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers to gain control of a reso…
Mvision Endpoint
20.11+
HIGH 7.2
CVE-2020-24063
The Canto plugin 1.3.0 for WordPress allows includes/lib/download.php?subdomain= SSRF.
Canto
Mitigation only
MEDIUM 5.3
CVE-2020-26811
SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over…
Commerce Cloud \(accelerator Payment Mock\)
No fix yet
HIGH 8.6
CVE-2020-26815
SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send a crafted request to a vulne…
Fiori Launchpad \(news Tile Application\)
Mitigation only
MEDIUM 5.5
CVE-2020-27018
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a server side request forgery vulnerability which could allow…
Interscan Messaging Security Virtual Appliance
after 9.1
CRITICAL 9.1
CVE-2020-15297
Insufficient validation in the Bitdefender Update Server and BEST Relay components of Bitdefender Endpoint Security Tools versions prior to 6.6.20.29…
Update Server
6.6.20.294+
MEDIUM 5.9
CVE-2020-28168
Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL t…
Axios
1.0+
HIGH 7.5
CVE-2020-28043
MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL.
Misp
after 2.4.133
CRITICAL 9.8
CVE-2020-24881EPSS 73%
SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.
Osticket
1.14.3+
MEDIUM 5.3
CVE-2020-24710
Gophish before 0.11.0 allows SSRF attacks.
Gophish
0.11.0+
MEDIUM 5.8
CVE-2020-7126
A remote server-side request forgery (ssrf) vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
Airwave Glass
1.3.2+
CRITICAL 9.8
CVE-2020-25466
A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execu…
Crmeb
Mitigation only
MEDIUM 5.0
CVE-2020-15002
OX App Suite through 7.10.3 allows SSRF via the the /ajax/messaging/message message API.
Open Xchange Appsuite
after 7.10.3
MEDIUM 6.5
CVE-2020-25820EPSS 10%
BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document that has a …
Bigbluebutton
2.2.27+
MEDIUM 5.3
CVE-2020-6308EPSS 62%
SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary va…
Businessobjects Business Intelligence Platform
Mitigation only
HIGH 7.3
CVE-2020-15822
In JetBrains YouTrack before 2020.2.10514, SSRF is possible because URL filtering can be escaped.
Youtrack
2020.2.10514+
CRITICAL 9.8
CVE-2020-27197
TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the…
Opentaxii
after 1.1.117
CRITICAL 9.8
CVE-2020-26948EPSS 87%
Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.
Emby
4.5.0+
HIGH 8.2
CVE-2020-7740
This affects all versions of package node-pdf-generator. Due to lack of user input validation and sanitization done to the content given to node-pdf-…
Node Pdf Generator
Mitigation only
HIGH 8.2
CVE-2020-7739
This affects all versions of package phantomjs-seo. It is possible for an attacker to craft a url that will be passed to a PhantomJS instance allowin…
Phantomjs Seo
Patch available