Vulnerability index

Browse CVEs

2,859 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 7.5 CVE-2019-5725 qibosoft through V7 allows remote attackers to read arbitrary files via the member/index.php main parameter, as demonstrated by SSRF to a URL on the … Qibosoft after 7.0 Fix from $1,9502019-01-08 CRITICAL 9.1 CVE-2018-19601 Rhymix CMS 1.9.8.1 allows SSRF via an index.php?module=admin&act=dispModuleAdminFileBox SVG upload. Rhymix Patch available Fix from $2,3002019-01-03 CRITICAL 10.0 CVE-2019-3905 Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF. Manageengine Adselfservice Plus Mitigation only Fix from $2,3002019-01-03 CRITICAL 10.0 CVE-2018-14721EPSS 10% FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure … Debian Linux 2.6.7.2 / 2.7.9.5+ Fix from $2,3002019-01-02 CRITICAL 9.8 CVE-2018-20596 Jspxcms v9.0.0 allows SSRF. Jspxcms Mitigation only Fix from $2,3002018-12-30 MEDIUM 6.5 CVE-2018-20528 JEECMS 9 has SSRF via the ueditor/getRemoteImage.jspx upfile parameter. Jeecms Mitigation only Fix from $1,6002018-12-28 HIGH 8.1 CVE-2018-20436 The "secret chat" feature in Telegram 4.9.1 for Android has a "side channel" in which Telegram servers send GET requests for URLs typed while composi… Telegram No fix yet Fix from $1,9502018-12-24 HIGH 8.0 CVE-2018-20228 Subsonic V6.1.5 allows internetRadioSettings.view streamUrl CSRF, with resultant SSRF. Subsonic No fix yet Fix from $1,9502018-12-19 HIGH 8.8 CVE-2018-18646 An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows SSRF. GitLab 11.2.7 / 11.3.8+ Fix from $1,9502018-12-04 CRITICAL 10.0 CVE-2018-18843 The Kubernetes integration in GitLab Enterprise Edition 11.x before 11.2.8, 11.3.x before 11.3.9, and 11.4.x before 11.4.4 has SSRF. GitLab 11.2.8 / 11.3.9+ Fix from $2,3002018-12-04 MEDIUM 6.5 CVE-2018-19651 admin/functions/remote.php in Interspire Email Marketer through 6.1.6 has Server Side Request Forgery (SSRF) via a what=importurl&url= request with a… Email Marketer after 6.1.6 Fix from $1,6002018-11-28 CRITICAL 10.0 CVE-2018-19047 mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '<img src="http://192.168' substr… Mpdf after 7.1.6 Fix from $2,3002018-11-07 HIGH 8.6 CVE-2018-18867 An SSRF issue was discovered in tecrail Responsive FileManager 9.13.4 via the upload.php url parameter. NOTE: this issue exists because of an incompl… Responsive Filemanager No fix yet Fix from $1,9502018-10-31 CRITICAL 9.8 CVE-2018-18753 Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF. Typecho No fix yet Fix from $2,3002018-10-29 HIGH 8.6 CVE-2018-16793EPSS 11% Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parameter in /owa/auth/logon.aspx i… Exchange Server No fix yet Fix from $1,9502018-09-21 HIGH 8.6 CVE-2018-16794EPSS 8% Microsoft ADFS 4.0 Windows Server 2016 and previous (Active Directory Federation Services) has an SSRF vulnerability via the txtBoxEmail parameter in… Active Directory Federation Services after 4.0 Fix from $1,9502018-09-18 HIGH 8.6 CVE-2018-2463 The Omni Commerce Connect API (OCC) of SAP Hybris Commerce, versions 6.*, is vulnerable to server-side request forgery (SSRF) attacks. This is due to… Hybris after 6.7 Fix from $1,9502018-09-11 CRITICAL 9.9 CVE-2018-1789 IBM API Connect v2018.1.0 through v2018.3.4 could allow an attacker to send a specially crafted request to conduct a server side request forgery atta… Api Connect after 2018.3.4 Fix from $2,3002018-09-07 CRITICAL 9.1 CVE-2018-16444 An issue was discovered in SeaCMS 6.61. adm1n/admin_reslib.php has SSRF via the url parameter. Seacms No fix yet Fix from $2,3002018-09-04 HIGH 8.6 CVE-2018-16409 In Gogs 0.11.53, an attacker can use migrate to send arbitrary HTTP GET requests, leading to SSRF. Gogs Mitigation only Fix from $1,9502018-09-03 HIGH 7.5 CVE-2018-15895 An SSRF vulnerability was discovered in idreamsoft iCMS 7.0.11 because the remote function in app/spider/spider_tools.class.php does not block DNS ho… Icms 7.0.11+ Fix from $1,9502018-08-27 CRITICAL 10.0 CVE-2018-10511 A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to conduct a server-side request forgery (SSRF) attack … Control Manager Patch available Fix from $2,3002018-08-15 CRITICAL 9.6 CVE-2018-2445 AdminTools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allows an attacker to manipulate the vulnerable application to send craft… Businessobjects Business Intelligence Mitigation only Fix from $2,3002018-08-14 CRITICAL 10.0 CVE-2018-3774 Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authenticati… Url Parse 1.4.3+ Fix from $2,3002018-08-12 HIGH 8.6 CVE-2018-15192 An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services. Gitea 1.5.0+ Fix from $1,9502018-08-08 CRITICAL 9.8 CVE-2018-14728EPSS 77% upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter. Responsive Filemanager No fix yet Fix from $2,3002018-08-03 HIGH 7.5 CVE-2018-14858 An SSRF vulnerability was discovered in idreamsoft iCMS before V7.0.11 because the remote function in app/spider/spider_tools.class.php does not bloc… Icms 7.0.11+ Fix from $1,9502018-08-02 MEDIUM 6.5 CVE-2018-1999026 A server-side request forgery vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublisher.java that allows attackers … Tracetronic Ecu Test after 2.3 Fix from $1,6002018-08-01 CRITICAL 9.8 CVE-2018-14514 An SSRF vulnerability was discovered in idreamsoft iCMS V7.0.9 that allows attackers to read sensitive files, access an intranet, or possibly have un… Icms No fix yet Fix from $2,3002018-07-23 HIGH 7.5 CVE-2018-12809 Adobe Experience Manager versions 6.4 and earlier have a Server-Side Request Forgery vulnerability. Successful exploitation could lead to sensitive i… Experience Manager after 6.4.0 Fix from $1,9502018-07-20