Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2019-5725
qibosoft through V7 allows remote attackers to read arbitrary files via the member/index.php main parameter, as demonstrated by SSRF to a URL on the …
Qibosoft
after 7.0
CRITICAL 9.1
CVE-2018-19601
Rhymix CMS 1.9.8.1 allows SSRF via an index.php?module=admin&act=dispModuleAdminFileBox SVG upload.
Rhymix
Patch available
CRITICAL 10.0
CVE-2019-3905
Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF.
Manageengine Adselfservice Plus
Mitigation only
CRITICAL 10.0
CVE-2018-14721EPSS 10%
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure …
Debian Linux
2.6.7.2 / 2.7.9.5+
CRITICAL 9.8
CVE-2018-20596
Jspxcms v9.0.0 allows SSRF.
Jspxcms
Mitigation only
MEDIUM 6.5
CVE-2018-20528
JEECMS 9 has SSRF via the ueditor/getRemoteImage.jspx upfile parameter.
Jeecms
Mitigation only
HIGH 8.1
CVE-2018-20436
The "secret chat" feature in Telegram 4.9.1 for Android has a "side channel" in which Telegram servers send GET requests for URLs typed while composi…
Telegram
No fix yet
HIGH 8.0
CVE-2018-20228
Subsonic V6.1.5 allows internetRadioSettings.view streamUrl CSRF, with resultant SSRF.
Subsonic
No fix yet
HIGH 8.8
CVE-2018-18646
An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows SSRF.
GitLab
11.2.7 / 11.3.8+
CRITICAL 10.0
CVE-2018-18843
The Kubernetes integration in GitLab Enterprise Edition 11.x before 11.2.8, 11.3.x before 11.3.9, and 11.4.x before 11.4.4 has SSRF.
GitLab
11.2.8 / 11.3.9+
MEDIUM 6.5
CVE-2018-19651
admin/functions/remote.php in Interspire Email Marketer through 6.1.6 has Server Side Request Forgery (SSRF) via a what=importurl&url= request with a…
Email Marketer
after 6.1.6
CRITICAL 10.0
CVE-2018-19047
mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '<img src="http://192.168' substr…
Mpdf
after 7.1.6
HIGH 8.6
CVE-2018-18867
An SSRF issue was discovered in tecrail Responsive FileManager 9.13.4 via the upload.php url parameter. NOTE: this issue exists because of an incompl…
Responsive Filemanager
No fix yet
CRITICAL 9.8
CVE-2018-18753
Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF.
Typecho
No fix yet
HIGH 8.6
CVE-2018-16793EPSS 11%
Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parameter in /owa/auth/logon.aspx i…
Exchange Server
No fix yet
HIGH 8.6
CVE-2018-16794EPSS 8%
Microsoft ADFS 4.0 Windows Server 2016 and previous (Active Directory Federation Services) has an SSRF vulnerability via the txtBoxEmail parameter in…
Active Directory Federation Services
after 4.0
HIGH 8.6
CVE-2018-2463
The Omni Commerce Connect API (OCC) of SAP Hybris Commerce, versions 6.*, is vulnerable to server-side request forgery (SSRF) attacks. This is due to…
Hybris
after 6.7
CRITICAL 9.9
CVE-2018-1789
IBM API Connect v2018.1.0 through v2018.3.4 could allow an attacker to send a specially crafted request to conduct a server side request forgery atta…
Api Connect
after 2018.3.4
CRITICAL 9.1
CVE-2018-16444
An issue was discovered in SeaCMS 6.61. adm1n/admin_reslib.php has SSRF via the url parameter.
Seacms
No fix yet
HIGH 8.6
CVE-2018-16409
In Gogs 0.11.53, an attacker can use migrate to send arbitrary HTTP GET requests, leading to SSRF.
Gogs
Mitigation only
HIGH 7.5
CVE-2018-15895
An SSRF vulnerability was discovered in idreamsoft iCMS 7.0.11 because the remote function in app/spider/spider_tools.class.php does not block DNS ho…
Icms
7.0.11+
CRITICAL 10.0
CVE-2018-10511
A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to conduct a server-side request forgery (SSRF) attack …
Control Manager
Patch available
CRITICAL 9.6
CVE-2018-2445
AdminTools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allows an attacker to manipulate the vulnerable application to send craft…
Businessobjects Business Intelligence
Mitigation only
CRITICAL 10.0
CVE-2018-3774
Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authenticati…
Url Parse
1.4.3+
HIGH 8.6
CVE-2018-15192
An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.
Gitea
1.5.0+
CRITICAL 9.8
CVE-2018-14728EPSS 77%
upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.
Responsive Filemanager
No fix yet
HIGH 7.5
CVE-2018-14858
An SSRF vulnerability was discovered in idreamsoft iCMS before V7.0.11 because the remote function in app/spider/spider_tools.class.php does not bloc…
Icms
7.0.11+
MEDIUM 6.5
CVE-2018-1999026
A server-side request forgery vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublisher.java that allows attackers …
Tracetronic Ecu Test
after 2.3
CRITICAL 9.8
CVE-2018-14514
An SSRF vulnerability was discovered in idreamsoft iCMS V7.0.9 that allows attackers to read sensitive files, access an intranet, or possibly have un…
Icms
No fix yet
HIGH 7.5
CVE-2018-12809
Adobe Experience Manager versions 6.4 and earlier have a Server-Side Request Forgery vulnerability. Successful exploitation could lead to sensitive i…
Experience Manager
after 6.4.0