Vulnerability index

Browse CVEs

2,859 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 7.7 CVE-2019-15033 Pydio 6.0.8 allows Authenticated SSRF during a Remote Link Feature download. An attacker can specify an intranet address in the file parameter to ind… Pydio No fix yet Fix from $1,9502019-09-19 CRITICAL 9.1 CVE-2019-6837 A Server-Side Request Forgery (SSRF): CWE-918 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KN… Meg6501 0001 Firmware 1.3.7+ Fix from $2,3002019-09-17 MEDIUM 5.3 CVE-2019-15731 An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Non-members were able to comment on merge requests despite th… GitLab 12.0.8 / 12.1.8+ Fix from $1,6002019-09-16 HIGH 7.5 CVE-2019-15728 An issue was discovered in GitLab Community and Enterprise Edition 10.1 through 12.2.1. Protections against SSRF attacks on the Kubernetes integratio… GitLab 12.0.8 / 12.1.8+ Fix from $1,9502019-09-16 HIGH 7.5 CVE-2019-15730 An issue was discovered in GitLab Community and Enterprise Edition 8.14 through 12.2.1. The Jira integration contains a SSRF vulnerability as a resul… GitLab 12.0.8 / 12.1.8+ Fix from $1,9502019-09-16 MEDIUM 6.5 CVE-2019-8451EPSS 94% The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network reso… Jira Server 8.4.0+ Fix from $1,6002019-09-11 MEDIUM 5.3 CVE-2019-12996 In Mendix 7.23.5 and earlier, issue in XML import mappings allow DOCTYPE declarations in the XML input that is potentially unsafe. Mendix after 7.23.5 Fix from $1,6002019-09-10 HIGH 7.0 CVE-2019-6793 An issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The Jira integration feature is v… GitLab 11.5.8 / 11.6.6+ Fix from $1,9502019-09-09 HIGH 7.5 CVE-2019-12632 A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery … Finesse Mitigation only Fix from $1,9502019-09-05 HIGH 7.5 CVE-2019-12633 A vulnerability in Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to bypass access controls and c… Unified Contact Center Express 11.6+ Fix from $1,9502019-09-05 CRITICAL 10.0 CVE-2019-13020 The fetch API in Tightrope Media Carousel before 7.1.3 has CarouselAPI/v0/fetch?url= SSRF. This has two potential areas for abuse. First, a specially… Tightrope Media Carousel 7.1.3+ Fix from $2,3002019-08-26 CRITICAL 9.8 CVE-2019-15494 openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21. Openitcockpit 3.7.1+ Fix from $2,3002019-08-23 CRITICAL 10.0 CVE-2016-10926 The nelio-ab-testing plugin before 4.5.9 for WordPress has SSRF in ajax/iesupport.php. Nelio Ab Testing 4.5.9+ Fix from $2,3002019-08-22 CRITICAL 10.0 CVE-2016-10927 The nelio-ab-testing plugin before 4.5.11 for WordPress has SSRF in ajax/iesupport.php. Nelio Ab Testing 4.5.11+ Fix from $2,3002019-08-22 HIGH 8.6 CVE-2019-11897 A Server-Side Request Forgery (SSRF) vulnerability in the backup & restore functionality in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT… Iot Gateway Software 8.2.6 / 9.3.0+ Fix from $1,9502019-08-21 CRITICAL 9.8 CVE-2019-0345 A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Java (Administrator System Overview), versions 7.30… Netweaver Application Server Java Mitigation only Fix from $2,3002019-08-14 HIGH 8.8 CVE-2019-12959 Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer 6.2.0 and before for the ClientUtilServlet servlet via a URL in a parame… Manageengine Assetexplorer 6.2.0+ Fix from $1,9502019-08-08 CRITICAL 9.1 CVE-2019-12994 Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet via a parameter in a URL. Manageengine Assetexplorer Mitigation only Fix from $2,3002019-08-08 CRITICAL 9.8 CVE-2019-14255 A Server Side Request Forgery (SSRF) vulnerability in go-camo up to version 1.1.4 allows a remote attacker to perform HTTP requests to internal endpo… Go Camo after 1.1.4 Fix from $2,3002019-08-08 CRITICAL 9.8 CVE-2019-14704 An SSRF issue was discovered in HTTPD on MicroDigital N-series cameras with firmware through 6400.0.8.5 via FTP commands following a newline characte… Mdc N4090 Firmware after 6400.0.8.5 Fix from $2,3002019-08-06 HIGH 7.2 CVE-2019-7923 A server-side request forgery (SSRF) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Thi… Magento 2.1.18 / 2.2.9+ Fix from $1,9502019-08-02 HIGH 7.2 CVE-2019-7892 A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated… Magento 2.1.18 / 2.2.9+ Fix from $1,9502019-08-02 HIGH 7.2 CVE-2019-7911 A server-side request forgery (SSRF) vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.… Magento 2.1.18 / 2.2.9+ Fix from $1,9502019-08-02 HIGH 7.2 CVE-2019-7913 A server-side request forgery (SSRF) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Thi… Magento 2.1.18 / 2.2.9+ Fix from $1,9502019-08-02 HIGH 7.7 CVE-2018-19571EPSS 28% GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an SSRF vulnerability in webhook… GitLab 11.3.11 / 11.4.8+ Fix from $1,9502019-07-10 MEDIUM 6.5 CVE-2018-19495 An issue was discovered in GitLab Community and Enterprise Edition before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an SSRF v… GitLab 11.3.11 / 11.4.8+ Fix from $1,6002019-07-10 CRITICAL 9.8 CVE-2019-9827EPSS 27% Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host v… Hawtio after 2.5.0 Fix from $2,3002019-07-03 CRITICAL 9.8 CVE-2019-12852 An SSRF attack was possible on a JetBrains YouTrack server. The issue (1 of 2) was fixed in JetBrains YouTrack 2018.4.49168. Youtrack 2018.4.49168+ Fix from $2,3002019-07-03 CRITICAL 10.0 CVE-2019-12153 Lack of validation in the HTML parser in RealObjects PDFreactor before 10.1.10722 leads to SSRF, allowing attackers to access network or file resourc… Pdfreactor 10.1.10722+ Fix from $2,3002019-06-11 HIGH 7.5 CVE-2019-9187 ikiwiki before 3.20170111.1 and 3.2018x and 3.2019x before 3.20190228 allows SSRF via the aggregate plugin. The impact also includes reading local fi… Ikiwiki 3.20170111.1 / 3.20190226+ Fix from $1,9502019-06-05