Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.7
CVE-2019-15033
Pydio 6.0.8 allows Authenticated SSRF during a Remote Link Feature download. An attacker can specify an intranet address in the file parameter to ind…
Pydio
No fix yet
CRITICAL 9.1
CVE-2019-6837
A Server-Side Request Forgery (SSRF): CWE-918 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KN…
Meg6501 0001 Firmware
1.3.7+
MEDIUM 5.3
CVE-2019-15731
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Non-members were able to comment on merge requests despite th…
GitLab
12.0.8 / 12.1.8+
HIGH 7.5
CVE-2019-15728
An issue was discovered in GitLab Community and Enterprise Edition 10.1 through 12.2.1. Protections against SSRF attacks on the Kubernetes integratio…
GitLab
12.0.8 / 12.1.8+
HIGH 7.5
CVE-2019-15730
An issue was discovered in GitLab Community and Enterprise Edition 8.14 through 12.2.1. The Jira integration contains a SSRF vulnerability as a resul…
GitLab
12.0.8 / 12.1.8+
MEDIUM 6.5
CVE-2019-8451EPSS 94%
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network reso…
Jira Server
8.4.0+
MEDIUM 5.3
CVE-2019-12996
In Mendix 7.23.5 and earlier, issue in XML import mappings allow DOCTYPE declarations in the XML input that is potentially unsafe.
Mendix
after 7.23.5
HIGH 7.0
CVE-2019-6793
An issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The Jira integration feature is v…
GitLab
11.5.8 / 11.6.6+
HIGH 7.5
CVE-2019-12632
A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery …
Finesse
Mitigation only
HIGH 7.5
CVE-2019-12633
A vulnerability in Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to bypass access controls and c…
Unified Contact Center Express
11.6+
CRITICAL 10.0
CVE-2019-13020
The fetch API in Tightrope Media Carousel before 7.1.3 has CarouselAPI/v0/fetch?url= SSRF. This has two potential areas for abuse. First, a specially…
Tightrope Media Carousel
7.1.3+
CRITICAL 9.8
CVE-2019-15494
openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21.
Openitcockpit
3.7.1+
CRITICAL 10.0
CVE-2016-10926
The nelio-ab-testing plugin before 4.5.9 for WordPress has SSRF in ajax/iesupport.php.
Nelio Ab Testing
4.5.9+
CRITICAL 10.0
CVE-2016-10927
The nelio-ab-testing plugin before 4.5.11 for WordPress has SSRF in ajax/iesupport.php.
Nelio Ab Testing
4.5.11+
HIGH 8.6
CVE-2019-11897
A Server-Side Request Forgery (SSRF) vulnerability in the backup & restore functionality in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT…
Iot Gateway Software
8.2.6 / 9.3.0+
CRITICAL 9.8
CVE-2019-0345
A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Java (Administrator System Overview), versions 7.30…
Netweaver Application Server Java
Mitigation only
HIGH 8.8
CVE-2019-12959
Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer 6.2.0 and before for the ClientUtilServlet servlet via a URL in a parame…
Manageengine Assetexplorer
6.2.0+
CRITICAL 9.1
CVE-2019-12994
Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet via a parameter in a URL.
Manageengine Assetexplorer
Mitigation only
CRITICAL 9.8
CVE-2019-14255
A Server Side Request Forgery (SSRF) vulnerability in go-camo up to version 1.1.4 allows a remote attacker to perform HTTP requests to internal endpo…
Go Camo
after 1.1.4
CRITICAL 9.8
CVE-2019-14704
An SSRF issue was discovered in HTTPD on MicroDigital N-series cameras with firmware through 6400.0.8.5 via FTP commands following a newline characte…
Mdc N4090 Firmware
after 6400.0.8.5
HIGH 7.2
CVE-2019-7923
A server-side request forgery (SSRF) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Thi…
Magento
2.1.18 / 2.2.9+
HIGH 7.2
CVE-2019-7892
A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated…
Magento
2.1.18 / 2.2.9+
HIGH 7.2
CVE-2019-7911
A server-side request forgery (SSRF) vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.…
Magento
2.1.18 / 2.2.9+
HIGH 7.2
CVE-2019-7913
A server-side request forgery (SSRF) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Thi…
Magento
2.1.18 / 2.2.9+
HIGH 7.7
CVE-2018-19571EPSS 28%
GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an SSRF vulnerability in webhook…
GitLab
11.3.11 / 11.4.8+
MEDIUM 6.5
CVE-2018-19495
An issue was discovered in GitLab Community and Enterprise Edition before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an SSRF v…
GitLab
11.3.11 / 11.4.8+
CRITICAL 9.8
CVE-2019-9827EPSS 27%
Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host v…
Hawtio
after 2.5.0
CRITICAL 9.8
CVE-2019-12852
An SSRF attack was possible on a JetBrains YouTrack server. The issue (1 of 2) was fixed in JetBrains YouTrack 2018.4.49168.
Youtrack
2018.4.49168+
CRITICAL 10.0
CVE-2019-12153
Lack of validation in the HTML parser in RealObjects PDFreactor before 10.1.10722 leads to SSRF, allowing attackers to access network or file resourc…
Pdfreactor
10.1.10722+
HIGH 7.5
CVE-2019-9187
ikiwiki before 3.20170111.1 and 3.2018x and 3.2019x before 3.20190228 allows SSRF via the aggregate plugin. The impact also includes reading local fi…
Ikiwiki
3.20170111.1 / 3.20190226+