Vulnerability index

Browse CVEs

2,859 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
MEDIUM 5.3 CVE-2019-1872 A vulnerability in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway Series software could allow an unauthenticated, remote at… Telepresence Video Communication Server Mitigation only Fix from $1,6002019-06-05 MEDIUM 6.5 CVE-2019-6981 Zimbra Collaboration Suite 8.7.x through 8.8.11 allows Blind SSRF in the Feed component. Zimbra Collaboration Suite 8.7.11 / 8.8.9+ Fix from $1,6002019-05-29 CRITICAL 9.8 CVE-2018-17198 Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java S… Roller after 5.1.2 Fix from $2,3002019-05-28 CRITICAL 9.9 CVE-2017-13667 OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF. Open Xchange Appsuite after 7.8.4 Fix from $2,3002019-05-23 HIGH 8.8 CVE-2019-12161 WPO WebPageTest 19.04 allows SSRF because ValidateURL in www/runtest.php does not consider octal encoding of IP addresses (such as 0300.0250 as a rep… Webpagetest Mitigation only Fix from $1,9502019-05-17 MEDIUM 5.8 CVE-2019-6516 An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to force the application to perform requests to the internal workstation (port… Dashboard Server Mitigation only Fix from $1,6002019-05-14 CRITICAL 9.8 CVE-2019-11066 openid.php in LightOpenID through 1.3.1 allows SSRF via a crafted OpenID 2.0 assertion request using the HTTP GET method. Lightopenid after 1.3.1 Fix from $2,3002019-05-10 HIGH 7.7 CVE-2019-7652EPSS 5% TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. To exploit the vulnerability, an attacker mu… Cortex Analyzers 1.15.2+ Fix from $1,9502019-05-09 MEDIUM 5.8 CVE-2019-11767 Server side request forgery (SSRF) in phpBB before 3.2.6 allows checking for the existence of files and services on the local network of the host thr… Phpbb 3.2.6+ Fix from $1,6002019-05-05 HIGH 7.5 CVE-2019-0227EPSS 92% A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits… Axis Patch available Fix from $1,9502019-05-01 HIGH 7.5 CVE-2019-9621 KEVEPSS 81% Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows S… Zimbra Collaboration Suite 8.6.0 / 8.7.11+ Fix from $1,9502019-04-30 CRITICAL 9.8 CVE-2019-11565 Server Side Request Forgery (SSRF) exists in the Print My Blog plugin before 1.6.7 for WordPress via the site parameter. Print My Blog 1.6.7+ Fix from $2,3002019-04-27 CRITICAL 10.0 CVE-2019-9174 An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows SSRF. GitLab 11.6.10 / 11.7.6+ Fix from $2,3002019-04-17 CRITICAL 9.8 CVE-2019-4203 IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal can be exploited by app developers to download arbitrary files from the host OS and potentially … Api Connect after 5.0.8.6 Fix from $2,3002019-04-15 CRITICAL 10.0 CVE-2019-10686 An SSRF vulnerability was found in an API from Ctrip Apollo through 1.4.0-SNAPSHOT. An attacker may use it to do an intranet port scan or raise a GET… Apollo after 1.3.0 Fix from $2,3002019-04-01 CRITICAL 9.8 CVE-2019-3395EPSS 7% The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), from version 6.7.0 before 6.8.… Confluence 6.6.12 / 6.12.3+ Fix from $2,3002019-03-25 CRITICAL 10.0 CVE-2019-3809 A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, w… Moodle after 3.1.15 Fix from $2,3002019-03-25 HIGH 7.5 CVE-2019-6970 Moodle 3.5.x before 3.5.4 allows SSRF. Moodle 3.5.4+ Fix from $1,9502019-03-21 MEDIUM 5.4 CVE-2018-13103 OX App Suite 7.8.4 and earlier allows SSRF. Open Xchange Appsuite after 7.8.4 Fix from $1,6002019-03-21 HIGH 7.5 CVE-2017-3164EPSS 19% Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist … Solr after 7.6.0 Fix from $1,9502019-03-08 CRITICAL 9.6 CVE-2019-8982EPSS 28% com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disc… Wavemarker Studio No fix yet Fix from $2,3002019-02-21 HIGH 8.6 CVE-2018-18569 The Dundas BI server before 5.0.1.1010 is vulnerable to a Server-Side Request Forgery attack, allowing an attacker to forge arbitrary requests (with … Dundas Bi No fix yet Fix from $1,9502019-02-11 MEDIUM 5.0 CVE-2019-1679 A vulnerability in the web interface of Cisco TelePresence Conductor, Cisco Expressway Series, and Cisco TelePresence Video Communication Server (VCS… Telepresence Video Communication Server Mitigation only Fix from $1,6002019-02-07 HIGH 7.3 CVE-2018-15657 An SSRF issue was discovered in 42Gears SureMDM before 2018-11-27 via the /api/DownloadUrlResponse.ashx "url" parameter. Suremdm 2018-11-27+ Fix from $1,9502019-02-05 MEDIUM 5.8 CVE-2018-15516 The FTP service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices allows remote attackers to conduct a PORT command bounce scan via port 8000,… Central Wifimanager No fix yet Fix from $1,6002019-01-31 HIGH 8.6 CVE-2018-15517EPSS 44% The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually all… Central Wifimanager No fix yet Fix from $1,9502019-01-31 MEDIUM 6.5 CVE-2018-12609 OX App Suite 7.8.4 and earlier allows Server-Side Request Forgery. Open Xchange Appsuite after 7.8.4 Fix from $1,6002019-01-30 HIGH 7.7 CVE-2019-6257 A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal network r… Elfinder 2.1.46+ Fix from $1,9502019-01-14 MEDIUM 6.5 CVE-2018-1000421 An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read … Mesos after 0.17.1 Fix from $1,6002019-01-09 MEDIUM 6.5 CVE-2018-1000422 An improper authorization vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java that allows attacke… Crowd2 after 2.0.0 Fix from $1,6002019-01-09