Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2020-5784
Server-Side Request Forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a low privileged user to cause the application to perform HTTP GET request…
Trb245 Firmware
No fix yet
MEDIUM 6.5
CVE-2020-24570
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a CSRF issue (with resultant SSRF) in the com_mb24pr…
Mbconnect24
after 2.6.1
MEDIUM 6.5
CVE-2020-16171EPSS 6%
An issue was discovered in Acronis Cyber Backup before 12.5 Build 16342. Some API endpoints on port 9877 under /api/ams/ accept an additional custom …
Cyber Backup
after 12.5
HIGH 8.8
CVE-2020-13309
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a blind SSRF attack through the reposit…
GitLab
13.1.10 / 13.2.8+
MEDIUM 6.5
CVE-2020-4632
IBM InfoSphere Metadata Asset Manager 11.7 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticat…
Infosphere Metadata Asset Manager
Mitigation only
MEDIUM 5.0
CVE-2020-12644
OX App Suite 7.10.3 and earlier allows SSRF, related to the mail account API and the /folder/list API.
Open Xchange Appsuite
after 7.10.3
MEDIUM 6.5
CVE-2020-24898
The Table Filter and Charts for Confluence Server app before 5.3.26 (for Atlassian Confluence) allows SSRF via the "Table from CSV" macro (URL parame…
Table Filter And Charts For Confluence Server
5.3.26+
HIGH 7.5
CVE-2020-9298
The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an attacker to send requests on beh…
Orca
8.7.0+
MEDIUM 5.3
CVE-2020-24548
Ericom Access Server 9.2.0 (for AccessNow and Ericom Blaze) allows SSRF to make outbound WebSocket connection requests on arbitrary TCP ports, and pr…
Access Server
No fix yet
MEDIUM 6.5
CVE-2020-17386
Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly. With cookie of an authenticated user, attackers can temper with th…
Cellos
Mitigation only
HIGH 7.2
CVE-2020-14044
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Server-Side Request Forgery (SSRF) vulnerability was found in Codiad v1.7.8 and later. A user with admin …
Codiad
No fix yet
MEDIUM 5.8
CVE-2020-5775EPSS 7%
Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas application to perform HTTP GET re…
Canvas Learning Management Service
Patch available
CRITICAL 9.1
CVE-2020-15152
ftp-srv is an npm package which is a modern and extensible FTP server designed to be simple yet configurable. In ftp-srv before versions 2.19.6, 3.1.…
Ftp Srv
2.19.6 / 3.1.2+
MEDIUM 5.8
CVE-2020-8226
A vulnerability exists in phpBB <v3.2.10 and <v3.3.1 which allowed remote image dimensions check to be used to SSRF.
Phpbb
3.2.10 / 3.3.1+
HIGH 7.1
CVE-2020-14296
Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible Tower provider, an attacker co…
Cloudforms Management Engine
Mitigation only
HIGH 8.8
CVE-2020-13295
For GitLab Runner before 13.0.12, 13.1.6, 13.2.3, by replacing dockerd with a malicious server, the Shared Runner is susceptible to SSRF.
Runner
13.0.12 / 13.1.6+
MEDIUM 5.8
CVE-2020-16248
Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted …
Blackbox Exporter
after 0.17.0
HIGH 7.5
CVE-2020-15823
JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component.
Youtrack
2020.2.8873+
MEDIUM 5.3
CVE-2020-15819
JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports.
Youtrack
2020.2.10643+
HIGH 8.8
CVE-2020-13970
Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated…
Shopware
6.2.3+
HIGH 7.5
CVE-2020-15879
Bitwarden Server 1.35.1 allows SSRF because it does not consider certain IPv6 addresses (ones beginning with fc, fd, fe, or ff, and the :: address) a…
Server
Patch available
HIGH 7.5
CVE-2020-8205
The uppy npm package < 1.13.2 and < 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to sc…
Uppy
1.13.2+
MEDIUM 5.8
CVE-2020-6282
SAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, and SAP NetWeaver AS JAVA (IIOP service) (CORE-…
Netweaver Application Server Java
Mitigation only
CRITICAL 9.8
CVE-2020-14056
Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of the web fetch functionality. Th…
Monsta Ftp
after 2.10.1
MEDIUM 5.3
CVE-2019-20408
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the content of internal network reso…
Jira
8.7.0+
CRITICAL 9.8
CVE-2020-13484
Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview url parameter, if the destinat…
Bitrix24
after 20.0.975
MEDIUM 5.5
CVE-2019-20872
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. SSRF can attack local services.
Mattermost Server
4.10.8 / 5.7.3+
MEDIUM 6.5
CVE-2020-8544
OX App Suite through 7.10.3 allows SSRF.
Open Xchange Appsuite
No fix yet
HIGH 7.5
CVE-2020-13650
An issue was discovered in DigDash 2018R2 before p20200210 and 2019R1 before p20200210. The login page is vulnerable to Server-Side Request Forgery (…
Digdash
Mitigation only
MEDIUM 5.0
CVE-2020-9427
OX Guard 2.10.3 and earlier allows SSRF.
Ox Guard
No fix yet