Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2020-8128
An unintended require and server-side request forgery vulnerabilities in jsreport version 2.5.0 and earlier allow attackers to execute arbitrary code.
Jsreport
after 2.5.0
MEDIUM 5.3
CVE-2019-4741
IBM Content Navigator 3.0CD is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requ…
Content Navigator
Mitigation only
MEDIUM 5.0
CVE-2020-8118
An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in…
Nextcloud Server
15.0.9 / 16.0.2+
HIGH 7.5
CVE-2020-3938
SysJust Syuan-Gu-Da-Shih, versions before 20191223, contain vulnerability of Request Forgery, allowing attackers to launch inquiries into network arc…
Syuan Gu Da Shin
20191223+
CRITICAL 9.8
CVE-2013-4864EPSS 6%
MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url parameter to cgi-bin/cmh/pro…
Veralite Firmware
No fix yet
CRITICAL 9.8
CVE-2019-5464
A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF where the li…
GitLab
11.11.7+
HIGH 7.5
CVE-2007-6758
Server-side request forgery (SSRF) vulnerability in feed-proxy.php in extjs 5.0.0.
Ext Js
No fix yet
HIGH 7.5
CVE-2019-19835
SSRF in AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote denial of service via the server attribute …
Unleashed
9.10.2.0.84 / 9.12.3.0.136+
HIGH 7.5
CVE-2020-1925
Apache Olingo versions 4.0.0 to 4.7.0 provide the AsyncRequestWrapperImpl class which reads a URL from the Location header, and then sends a GET or D…
Olingo
after 4.7.0
HIGH 8.8
CVE-2019-19261
GitLab Enterprise Edition (EE) 6.7 and later through 12.5 allows SSRF.
GitLab
12.5.1+
MEDIUM 5.0
CVE-2018-20497
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF.
GitLab
11.4.13 / 11.5.6+
HIGH 7.2
CVE-2018-20499
An issue was discovered in GitLab Community and Enterprise Edition before 11.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It all…
GitLab
11.4.13 / 11.5.6+
MEDIUM 6.5
CVE-2019-20055
LuquidPixels LiquiFire OS 4.8.0 allows SSRF via the call%3Durl substring followed by a URL in square brackets.
Liquifire Os
No fix yet
HIGH 7.2
CVE-2019-19999
Halo before 1.2.0-beta.1 allows Server Side Template Injection (SSTI) because TemplateClassResolver.SAFER_RESOLVER is not used in the FreeMarker conf…
Halo
after 1.1.1
HIGH 7.3
CVE-2019-18379
Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a server-side request forgery (SSRF) exploit, which is a type of issue that can le…
Messaging Gateway
10.7.3+
CRITICAL 9.8
CVE-2019-16948
An SSRF issue was discovered in Enghouse Web Chat 6.1.300.31. In any POST request, one can replace the port number at WebServiceLocation=http://local…
Web Chat
No fix yet
HIGH 7.2
CVE-2019-8156
A server-side request forgery (SSRF) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated us…
Magento
2.2.10 / 2.3.2+
HIGH 7.2
CVE-2019-8151
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with admin…
Magento
2.2.10 / 2.3.2+
CRITICAL 9.8
CVE-2019-18394EPSS 32%
A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrar…
Openfire
after 4.4.2
CRITICAL 9.8
CVE-2019-18355
An SSRF issue was discovered in the legacy Web launcher in Thycotic Secret Server before 10.7.
Secret Server
10.7.000000+
HIGH 7.5
CVE-2019-17400
The unoconv package before 0.9 mishandles untrusted pathnames, leading to SSRF and local file inclusion.
Universal Office Converter
0.9+
CRITICAL 9.8
CVE-2019-17669EPSS 5%
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name a…
WordPress
5.2.4+
CRITICAL 9.8
CVE-2019-17670
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relat…
WordPress
5.2.4+
MEDIUM 5.4
CVE-2019-14225
OX App Suite 7.10.1 and 7.10.2 allows SSRF.
Open Xchange Appsuite
No fix yet
HIGH 7.5
CVE-2017-18638EPSS 15%
send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF. The vulnerable SSRF endpoint can be use…
Graphite
after 1.1.5
MEDIUM 5.3
CVE-2019-15021
A security vulnerability exists in the Zingbox Inspector versions 1.294 and earlier, that can allow an attacker to easily identify instances of Zingb…
Inspector
after 1.294
MEDIUM 5.3
CVE-2019-15164
rpcapd/daemon.c in libpcap before 1.9.1 allows SSRF because a URL may be provided as a capture source.
Libpcap
1.9.1+
CRITICAL 9.8
CVE-2019-13335
SalesAgility SuiteCRM 7.10.x 7.10.19 and 7.11.x before and 7.11.7 has SSRF.
Suitecrm
7.10.19 / 7.11.7+
CRITICAL 10.0
CVE-2019-16932EPSS 39%
A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.
Visualizer
3.3.1+
MEDIUM 5.3
CVE-2019-4262
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requ…
Qradar Security Information And Event Manager
7.2.8 / 7.3.2+