Vulnerability index

Browse CVEs

2,859 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 6.5 CVE-2020-5784 Server-Side Request Forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a low privileged user to cause the application to perform HTTP GET request… Trb245 Firmware No fix yet Fix from $1,6002020-10-01 MEDIUM 6.5 CVE-2020-24570 An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a CSRF issue (with resultant SSRF) in the com_mb24pr… Mbconnect24 after 2.6.1 Fix from $1,6002020-09-30 MEDIUM 6.5 CVE-2020-16171EPSS 6% An issue was discovered in Acronis Cyber Backup before 12.5 Build 16342. Some API endpoints on port 9877 under /api/ams/ accept an additional custom … Cyber Backup after 12.5 Fix from $1,6002020-09-21 HIGH 8.8 CVE-2020-13309 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a blind SSRF attack through the reposit… GitLab 13.1.10 / 13.2.8+ Fix from $1,9502020-09-14 MEDIUM 6.5 CVE-2020-4632 IBM InfoSphere Metadata Asset Manager 11.7 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticat… Infosphere Metadata Asset Manager Mitigation only Fix from $1,6002020-09-04 MEDIUM 5.0 CVE-2020-12644 OX App Suite 7.10.3 and earlier allows SSRF, related to the mail account API and the /folder/list API. Open Xchange Appsuite after 7.10.3 Fix from $1,6002020-08-31 MEDIUM 6.5 CVE-2020-24898 The Table Filter and Charts for Confluence Server app before 5.3.26 (for Atlassian Confluence) allows SSRF via the "Table from CSV" macro (URL parame… Table Filter And Charts For Confluence Server 5.3.26+ Fix from $1,6002020-08-29 HIGH 7.5 CVE-2020-9298 The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an attacker to send requests on beh… Orca 8.7.0+ Fix from $1,9502020-08-28 MEDIUM 5.3 CVE-2020-24548 Ericom Access Server 9.2.0 (for AccessNow and Ericom Blaze) allows SSRF to make outbound WebSocket connection requests on arbitrary TCP ports, and pr… Access Server No fix yet Fix from $1,6002020-08-26 MEDIUM 6.5 CVE-2020-17386 Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly. With cookie of an authenticated user, attackers can temper with th… Cellos Mitigation only Fix from $1,6002020-08-25 HIGH 7.2 CVE-2020-14044 ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Server-Side Request Forgery (SSRF) vulnerability was found in Codiad v1.7.8 and later. A user with admin … Codiad No fix yet Fix from $1,9502020-08-24 MEDIUM 5.8 CVE-2020-5775EPSS 7% Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas application to perform HTTP GET re… Canvas Learning Management Service Patch available Fix from $1,6002020-08-21 CRITICAL 9.1 CVE-2020-15152 ftp-srv is an npm package which is a modern and extensible FTP server designed to be simple yet configurable. In ftp-srv before versions 2.19.6, 3.1.… Ftp Srv 2.19.6 / 3.1.2+ Fix from $2,3002020-08-17 MEDIUM 5.8 CVE-2020-8226 A vulnerability exists in phpBB <v3.2.10 and <v3.3.1 which allowed remote image dimensions check to be used to SSRF. Phpbb 3.2.10 / 3.3.1+ Fix from $1,6002020-08-17 HIGH 7.1 CVE-2020-14296 Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible Tower provider, an attacker co… Cloudforms Management Engine Mitigation only Fix from $1,9502020-08-11 HIGH 8.8 CVE-2020-13295 For GitLab Runner before 13.0.12, 13.1.6, 13.2.3, by replacing dockerd with a malicious server, the Shared Runner is susceptible to SSRF. Runner 13.0.12 / 13.1.6+ Fix from $1,9502020-08-10 MEDIUM 5.8 CVE-2020-16248 Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted … Blackbox Exporter after 0.17.0 Fix from $1,6002020-08-09 HIGH 7.5 CVE-2020-15823 JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component. Youtrack 2020.2.8873+ Fix from $1,9502020-08-08 MEDIUM 5.3 CVE-2020-15819 JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports. Youtrack 2020.2.10643+ Fix from $1,6002020-08-08 HIGH 8.8 CVE-2020-13970 Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated… Shopware 6.2.3+ Fix from $1,9502020-07-28 HIGH 7.5 CVE-2020-15879 Bitwarden Server 1.35.1 allows SSRF because it does not consider certain IPv6 addresses (ones beginning with fc, fd, fe, or ff, and the :: address) a… Server Patch available Fix from $1,9502020-07-21 HIGH 7.5 CVE-2020-8205 The uppy npm package < 1.13.2 and < 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to sc… Uppy 1.13.2+ Fix from $1,9502020-07-20 MEDIUM 5.8 CVE-2020-6282 SAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, and SAP NetWeaver AS JAVA (IIOP service) (CORE-… Netweaver Application Server Java Mitigation only Fix from $1,6002020-07-14 CRITICAL 9.8 CVE-2020-14056 Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of the web fetch functionality. Th… Monsta Ftp after 2.10.1 Fix from $2,3002020-07-01 MEDIUM 5.3 CVE-2019-20408 The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the content of internal network reso… Jira 8.7.0+ Fix from $1,6002020-07-01 CRITICAL 9.8 CVE-2020-13484 Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview url parameter, if the destinat… Bitrix24 after 20.0.975 Fix from $2,3002020-06-24 MEDIUM 5.5 CVE-2019-20872 An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. SSRF can attack local services. Mattermost Server 4.10.8 / 5.7.3+ Fix from $1,6002020-06-19 MEDIUM 6.5 CVE-2020-8544 OX App Suite through 7.10.3 allows SSRF. Open Xchange Appsuite No fix yet Fix from $1,6002020-06-16 HIGH 7.5 CVE-2020-13650 An issue was discovered in DigDash 2018R2 before p20200210 and 2019R1 before p20200210. The login page is vulnerable to Server-Side Request Forgery (… Digdash Mitigation only Fix from $1,9502020-06-15 MEDIUM 5.0 CVE-2020-9427 OX Guard 2.10.3 and earlier allows SSRF. Ox Guard No fix yet Fix from $1,6002020-06-15