Vulnerability index

Browse CVEs

2,859 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 6.3 CVE-2020-11980 In Karaf, JMX authentication takes place using JAAS and authorization takes place using ACL files. By default, only an "admin" can actually invoke on… Karaf 4.2.9+ Fix from $1,6002020-06-12 HIGH 7.5 CVE-2020-9643 Adobe Experience Manager versions 6.5 and earlier have a server-side request forgery (ssrf) vulnerability. Successful exploitation could lead to sens… Experience Manager 6.4.8.1 / 6.5.5.0+ Fix from $1,9502020-06-12 HIGH 7.5 CVE-2020-9645 Adobe Experience Manager versions 6.5 and earlier have a blind server-side request forgery (ssrf) vulnerability. Successful exploitation could lead t… Experience Manager 6.4.8.1 / 6.5.5.0+ Fix from $1,9502020-06-12 HIGH 7.2 CVE-2020-12725 Havoc Research discovered an authenticated Server-Side Request Forgery (SSRF) via the "JSON" data source of Redash open-source 8.0.0 and prior. Possi… Redash after 8.0.0 Fix from $1,9502020-06-11 CRITICAL 9.8 CVE-2020-4101 "HCL Digital Experience is susceptible to Server Side Request Forgery." Hcl Digital Experience Mitigation only Fix from $2,3002020-06-11 CRITICAL 9.8 CVE-2020-6275 SAP Netweaver AS ABAP, versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, are vulnerable for Server Side Request Forgery Attac… Netweaver Application Server Abap Mitigation only Fix from $2,3002020-06-10 HIGH 7.4 CVE-2020-4529 IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send una… Maximo Asset Management Patch available Fix from $1,9502020-06-08 MEDIUM 6.3 CVE-2020-8555 The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a S… Kubernetes 1.15.11 / 1.16.9+ Fix from $1,6002020-06-05 HIGH 8.2 CVE-2020-13379EPSS 100% The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/clie… Grafana after 7.0.1 Fix from $1,9502020-06-03 HIGH 8.8 CVE-2014-8943 Lexiglot through 2014-11-20 allows SSRF via the admin.php?page=projects svn_url parameter. Lexiglot after 2014-11-20 Fix from $1,9502020-06-01 CRITICAL 9.8 CVE-2020-13226 WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this node's en… Api Manager Mitigation only Fix from $2,3002020-05-20 HIGH 8.8 CVE-2020-8830 CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other analysis via the SUBCA-1 field … Ruckus Zoneflex R500 Firmware No fix yet Fix from $1,9502020-05-05 HIGH 7.2 CVE-2020-11885 WSO2 Enterprise Integrator through 6.6.0 has an XXE vulnerability where a user (with admin console access) can use the XML validator to make unintend… Enterprise Integrator after 6.6.0 Fix from $1,9502020-04-17 MEDIUM 6.3 CVE-2020-4294 IBM QRadar 7.3.0 to 7.3.3 Patch 2 is vulnerable to Server Side Request Forgery (SSRF). This may allow an authenticated attacker to send unauthorized … Qradar Security Information And Event Manager 7.3.3+ Fix from $1,6002020-04-15 CRITICAL 9.8 CVE-2020-10980 GitLab EE/CE 8.0.rc1 to 12.9 is vulnerable to a blind SSRF in the FogBugz integration. GitLab after 12.9 Fix from $2,3002020-04-08 MEDIUM 5.3 CVE-2020-11453 Microstrategy Web 10.4 is vulnerable to Server-Side Request Forgery in the Test Web Service functionality exposed through the path /MicroStrategyWS/.… Microstrategy Web Patch available Fix from $1,6002020-04-02 CRITICAL 9.8 CVE-2020-10956 GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature. GitLab 12.9.1+ Fix from $2,3002020-03-27 HIGH 7.5 CVE-2020-3769 Adobe Experience Manager versions 6.5 and earlier have a server-side request forgery (ssrf) vulnerability. Successful exploitation could lead to sens… Experience Manager after 6.5.0 Fix from $1,9502020-03-25 MEDIUM 6.5 CVE-2020-10791 app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger out… Openitcockpit 3.7.3+ Fix from $1,6002020-03-25 CRITICAL 9.8 CVE-2019-11574 An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php and Subs.php because user-sup… Simple Machine Forum 2.0.17+ Fix from $2,3002020-03-20 MEDIUM 6.5 CVE-2020-8138 A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulner… Nextcloud Server 15.0.14 / 16.0.7+ Fix from $1,6002020-03-20 HIGH 8.1 CVE-2020-8134 Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network or otherwise interact wit… Ghost 3.10.0+ Fix from $1,9502020-03-20 CRITICAL 9.8 CVE-2020-8135 The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external … Uppy 1.9.3+ Fix from $2,3002020-03-20 CRITICAL 9.8 CVE-2020-10077 GitLab EE 3.0 through 12.8.1 allows SSRF. An internal investigation revealed that a particular deprecated service was creating a server side request … GitLab after 12.8.1 Fix from $2,3002020-03-13 CRITICAL 9.8 CVE-2020-8540EPSS 13% An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to … Manageengine Desktop Central 2020-03-07+ Fix from $2,3002020-03-11 HIGH 7.5 CVE-2019-13121 An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability whic… GitLab after 12.0.2 Fix from $1,9502020-03-10 CRITICAL 9.8 CVE-2019-12443 An issue was discovered in GitLab Community and Enterprise Edition 10.2 through 11.11. Multiple features contained Server-Side Request Forgery (SSRF)… GitLab after 11.11.0 Fix from $2,3002020-03-10 CRITICAL 9.8 CVE-2020-10212 upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishandled and because it… Responsive Filemanager No fix yet Fix from $2,3002020-03-07 MEDIUM 5.0 CVE-2019-18846 OX App Suite through 7.10.2 allows SSRF. Open Xchange Appsuite after 7.10.2 Fix from $1,6002020-02-21 CRITICAL 9.8 CVE-2020-7796 KEVEPSS 84% Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled. Zimbra Collaboration Suite 8.8.15+ Fix from $2,3002020-02-18