Vulnerability index

Browse CVEs

2,859 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
CRITICAL 9.8 CVE-2020-8128 An unintended require and server-side request forgery vulnerabilities in jsreport version 2.5.0 and earlier allow attackers to execute arbitrary code. Jsreport after 2.5.0 Fix from $2,3002020-02-14 MEDIUM 5.3 CVE-2019-4741 IBM Content Navigator 3.0CD is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requ… Content Navigator Mitigation only Fix from $1,6002020-02-12 MEDIUM 5.0 CVE-2020-8118 An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in… Nextcloud Server 15.0.9 / 16.0.2+ Fix from $1,6002020-02-04 HIGH 7.5 CVE-2020-3938 SysJust Syuan-Gu-Da-Shih, versions before 20191223, contain vulnerability of Request Forgery, allowing attackers to launch inquiries into network arc… Syuan Gu Da Shin 20191223+ Fix from $1,9502020-02-04 CRITICAL 9.8 CVE-2013-4864EPSS 6% MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url parameter to cgi-bin/cmh/pro… Veralite Firmware No fix yet Fix from $2,3002020-01-28 CRITICAL 9.8 CVE-2019-5464 A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF where the li… GitLab 11.11.7+ Fix from $2,3002020-01-28 HIGH 7.5 CVE-2007-6758 Server-side request forgery (SSRF) vulnerability in feed-proxy.php in extjs 5.0.0. Ext Js No fix yet Fix from $1,9502020-01-23 HIGH 7.5 CVE-2019-19835 SSRF in AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote denial of service via the server attribute … Unleashed 9.10.2.0.84 / 9.12.3.0.136+ Fix from $1,9502020-01-23 HIGH 7.5 CVE-2020-1925 Apache Olingo versions 4.0.0 to 4.7.0 provide the AsyncRequestWrapperImpl class which reads a URL from the Location header, and then sends a GET or D… Olingo after 4.7.0 Fix from $1,9502020-01-09 HIGH 8.8 CVE-2019-19261 GitLab Enterprise Edition (EE) 6.7 and later through 12.5 allows SSRF. GitLab 12.5.1+ Fix from $1,9502020-01-03 MEDIUM 5.0 CVE-2018-20497 An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF. GitLab 11.4.13 / 11.5.6+ Fix from $1,6002019-12-30 HIGH 7.2 CVE-2018-20499 An issue was discovered in GitLab Community and Enterprise Edition before 11.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It all… GitLab 11.4.13 / 11.5.6+ Fix from $1,9502019-12-30 MEDIUM 6.5 CVE-2019-20055 LuquidPixels LiquiFire OS 4.8.0 allows SSRF via the call%3Durl substring followed by a URL in square brackets. Liquifire Os No fix yet Fix from $1,6002019-12-29 HIGH 7.2 CVE-2019-19999 Halo before 1.2.0-beta.1 allows Server Side Template Injection (SSTI) because TemplateClassResolver.SAFER_RESOLVER is not used in the FreeMarker conf… Halo after 1.1.1 Fix from $1,9502019-12-26 HIGH 7.3 CVE-2019-18379 Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a server-side request forgery (SSRF) exploit, which is a type of issue that can le… Messaging Gateway 10.7.3+ Fix from $1,9502019-12-11 CRITICAL 9.8 CVE-2019-16948 An SSRF issue was discovered in Enghouse Web Chat 6.1.300.31. In any POST request, one can replace the port number at WebServiceLocation=http://local… Web Chat No fix yet Fix from $2,3002019-11-13 HIGH 7.2 CVE-2019-8156 A server-side request forgery (SSRF) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated us… Magento 2.2.10 / 2.3.2+ Fix from $1,9502019-11-06 HIGH 7.2 CVE-2019-8151 A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with admin… Magento 2.2.10 / 2.3.2+ Fix from $1,9502019-11-06 CRITICAL 9.8 CVE-2019-18394EPSS 32% A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrar… Openfire after 4.4.2 Fix from $2,3002019-10-24 CRITICAL 9.8 CVE-2019-18355 An SSRF issue was discovered in the legacy Web launcher in Thycotic Secret Server before 10.7. Secret Server 10.7.000000+ Fix from $2,3002019-10-23 HIGH 7.5 CVE-2019-17400 The unoconv package before 0.9 mishandles untrusted pathnames, leading to SSRF and local file inclusion. Universal Office Converter 0.9+ Fix from $1,9502019-10-21 CRITICAL 9.8 CVE-2019-17669EPSS 5% WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name a… WordPress 5.2.4+ Fix from $2,3002019-10-17 CRITICAL 9.8 CVE-2019-17670 WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relat… WordPress 5.2.4+ Fix from $2,3002019-10-17 MEDIUM 5.4 CVE-2019-14225 OX App Suite 7.10.1 and 7.10.2 allows SSRF. Open Xchange Appsuite No fix yet Fix from $1,6002019-10-14 HIGH 7.5 CVE-2017-18638EPSS 15% send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF. The vulnerable SSRF endpoint can be use… Graphite after 1.1.5 Fix from $1,9502019-10-11 MEDIUM 5.3 CVE-2019-15021 A security vulnerability exists in the Zingbox Inspector versions 1.294 and earlier, that can allow an attacker to easily identify instances of Zingb… Inspector after 1.294 Fix from $1,6002019-10-09 MEDIUM 5.3 CVE-2019-15164 rpcapd/daemon.c in libpcap before 1.9.1 allows SSRF because a URL may be provided as a capture source. Libpcap 1.9.1+ Fix from $1,6002019-10-03 CRITICAL 9.8 CVE-2019-13335 SalesAgility SuiteCRM 7.10.x 7.10.19 and 7.11.x before and 7.11.7 has SSRF. Suitecrm 7.10.19 / 7.11.7+ Fix from $2,3002019-10-02 CRITICAL 10.0 CVE-2019-16932EPSS 39% A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data. Visualizer 3.3.1+ Fix from $2,3002019-09-30 MEDIUM 5.3 CVE-2019-4262 IBM QRadar SIEM 7.2 and 7.3 is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requ… Qradar Security Information And Event Manager 7.2.8 / 7.3.2+ Fix from $1,6002019-09-26