Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.3
CVE-2020-11980
In Karaf, JMX authentication takes place using JAAS and authorization takes place using ACL files. By default, only an "admin" can actually invoke on…
Karaf
4.2.9+
HIGH 7.5
CVE-2020-9643
Adobe Experience Manager versions 6.5 and earlier have a server-side request forgery (ssrf) vulnerability. Successful exploitation could lead to sens…
Experience Manager
6.4.8.1 / 6.5.5.0+
HIGH 7.5
CVE-2020-9645
Adobe Experience Manager versions 6.5 and earlier have a blind server-side request forgery (ssrf) vulnerability. Successful exploitation could lead t…
Experience Manager
6.4.8.1 / 6.5.5.0+
HIGH 7.2
CVE-2020-12725
Havoc Research discovered an authenticated Server-Side Request Forgery (SSRF) via the "JSON" data source of Redash open-source 8.0.0 and prior. Possi…
Redash
after 8.0.0
CRITICAL 9.8
CVE-2020-4101
"HCL Digital Experience is susceptible to Server Side Request Forgery."
Hcl Digital Experience
Mitigation only
CRITICAL 9.8
CVE-2020-6275
SAP Netweaver AS ABAP, versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, are vulnerable for Server Side Request Forgery Attac…
Netweaver Application Server Abap
Mitigation only
HIGH 7.4
CVE-2020-4529
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send una…
Maximo Asset Management
Patch available
MEDIUM 6.3
CVE-2020-8555
The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a S…
Kubernetes
1.15.11 / 1.16.9+
HIGH 8.2
CVE-2020-13379EPSS 100%
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/clie…
Grafana
after 7.0.1
HIGH 8.8
CVE-2014-8943
Lexiglot through 2014-11-20 allows SSRF via the admin.php?page=projects svn_url parameter.
Lexiglot
after 2014-11-20
CRITICAL 9.8
CVE-2020-13226
WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this node's en…
Api Manager
Mitigation only
HIGH 8.8
CVE-2020-8830
CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other analysis via the SUBCA-1 field …
Ruckus Zoneflex R500 Firmware
No fix yet
HIGH 7.2
CVE-2020-11885
WSO2 Enterprise Integrator through 6.6.0 has an XXE vulnerability where a user (with admin console access) can use the XML validator to make unintend…
Enterprise Integrator
after 6.6.0
MEDIUM 6.3
CVE-2020-4294
IBM QRadar 7.3.0 to 7.3.3 Patch 2 is vulnerable to Server Side Request Forgery (SSRF). This may allow an authenticated attacker to send unauthorized …
Qradar Security Information And Event Manager
7.3.3+
CRITICAL 9.8
CVE-2020-10980
GitLab EE/CE 8.0.rc1 to 12.9 is vulnerable to a blind SSRF in the FogBugz integration.
GitLab
after 12.9
MEDIUM 5.3
CVE-2020-11453
Microstrategy Web 10.4 is vulnerable to Server-Side Request Forgery in the Test Web Service functionality exposed through the path /MicroStrategyWS/.…
Microstrategy Web
Patch available
CRITICAL 9.8
CVE-2020-10956
GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature.
GitLab
12.9.1+
HIGH 7.5
CVE-2020-3769
Adobe Experience Manager versions 6.5 and earlier have a server-side request forgery (ssrf) vulnerability. Successful exploitation could lead to sens…
Experience Manager
after 6.5.0
MEDIUM 6.5
CVE-2020-10791
app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger out…
Openitcockpit
3.7.3+
CRITICAL 9.8
CVE-2019-11574
An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php and Subs.php because user-sup…
Simple Machine Forum
2.0.17+
MEDIUM 6.5
CVE-2020-8138
A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulner…
Nextcloud Server
15.0.14 / 16.0.7+
HIGH 8.1
CVE-2020-8134
Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network or otherwise interact wit…
Ghost
3.10.0+
CRITICAL 9.8
CVE-2020-8135
The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external …
Uppy
1.9.3+
CRITICAL 9.8
CVE-2020-10077
GitLab EE 3.0 through 12.8.1 allows SSRF. An internal investigation revealed that a particular deprecated service was creating a server side request …
GitLab
after 12.8.1
CRITICAL 9.8
CVE-2020-8540EPSS 13%
An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to …
Manageengine Desktop Central
2020-03-07+
HIGH 7.5
CVE-2019-13121
An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability whic…
GitLab
after 12.0.2
CRITICAL 9.8
CVE-2019-12443
An issue was discovered in GitLab Community and Enterprise Edition 10.2 through 11.11. Multiple features contained Server-Side Request Forgery (SSRF)…
GitLab
after 11.11.0
CRITICAL 9.8
CVE-2020-10212
upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishandled and because it…
Responsive Filemanager
No fix yet
MEDIUM 5.0
CVE-2019-18846
OX App Suite through 7.10.2 allows SSRF.
Open Xchange Appsuite
after 7.10.2
CRITICAL 9.8
CVE-2020-7796 KEVEPSS 84%
Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.
Zimbra Collaboration Suite
8.8.15+