Vulnerability index

Browse CVEs

2,859 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 7.5 CVE-2018-5004 Adobe Experience Manager versions 6.2 and 6.3 have a Server-Side Request Forgery vulnerability. Successful exploitation could lead to sensitive infor… Experience Manager 6.4.0+ Fix from $1,9502018-07-20 HIGH 7.5 CVE-2018-5006EPSS 54% Adobe Experience Manager versions 6.4 and earlier have a Server-Side Request Forgery vulnerability. Successful exploitation could lead to sensitive i… Experience Manager after 6.4.0 Fix from $1,9502018-07-20 CRITICAL 9.8 CVE-2018-0398 Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a server-s… Finesse Mitigation only Fix from $2,3002018-07-18 CRITICAL 9.8 CVE-2018-0399 Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to retrieve a clearte… Finesse Mitigation only Fix from $2,3002018-07-18 CRITICAL 9.8 CVE-2018-0403 Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, … Unified Contact Center Express Mitigation only Fix from $2,3002018-07-18 HIGH 7.2 CVE-2018-13790 A Server Side Request Forgery (SSRF) vulnerability in tools/files/importers/remote.php in concrete5 8.2.0 can lead to attacks on the local network an… Concrete Cms No fix yet Fix from $1,9502018-07-09 CRITICAL 9.8 CVE-2018-12571EPSS 30% uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS queries fo… Forefront Unified Access Gateway No fix yet Fix from $2,3002018-07-05 HIGH 7.5 CVE-2017-0929EPSS 13% DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able… Dotnetnuke 9.2.0+ Fix from $1,9502018-07-03 MEDIUM 6.5 CVE-2018-1000606 A server-side request forgery vulnerability exists in Jenkins URLTrigger Plugin 0.41 and earlier in URLTrigger.java that allows attackers with Overal… Urltrigger after 0.41 Fix from $1,6002018-06-26 HIGH 8.8 CVE-2018-1000553 Trovebox version <= 4.0.0-rc6 contains a Server-Side request forgery vulnerability in webhook component that can result in read or update internal re… Trovebox after 3.0.0 Fix from $1,9502018-06-26 CRITICAL 9.8 CVE-2018-12678 Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query parameter for the /websocket/exec en… Portainer 1.18.0+ Fix from $2,3002018-06-22 HIGH 8.8 CVE-2018-5752 The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev… Open Xchange Appsuite after 7.6.3 Fix from $1,9502018-06-16 CRITICAL 9.8 CVE-2018-11586EPSS 15% XML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote unauthenticated users to read arbitrary files or conduct… Searchblox No fix yet Fix from $2,3002018-06-05 MEDIUM 6.4 CVE-2018-1000182 A server-side request forgery vulnerability exists in Jenkins Git Plugin 3.9.0 and older in AssemblaWeb.java, GitBlitRepositoryBrowser.java, Gitiles.… Git after 3.9.0 Fix from $1,6002018-06-05 MEDIUM 5.4 CVE-2018-1000184 A server-side request forgery vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubPluginConfig.java that allows attackers with Ov… GitHub after 1.29.0 Fix from $1,6002018-06-05 MEDIUM 5.4 CVE-2018-1000188 A server-side request forgery vulnerability exists in Jenkins CAS Plugin 1.4.1 and older in CasSecurityRealm.java that allows attackers with Overall/… Cas after 1.4.1 Fix from $1,6002018-06-05 MEDIUM 6.5 CVE-2018-9920 Server side request forgery exists in the runtime application in K2 smartforms 4.6.11 via a modified hostname in an https://*/Identity/STS/Forms/Scri… Smartforms Mitigation only Fix from $1,6002018-05-24 CRITICAL 9.8 CVE-2018-11031 application/home/controller/debug.php in PHPRAP 1.0.4 through 1.0.8 has SSRF via the /debug URI, as demonstrated by an api[url]=file:////etc/passwd&a… Phprap after 1.0.8 Fix from $2,3002018-05-14 CRITICAL 9.8 CVE-2018-9919 A web-accessible backdoor, with resultant SSRF, exists in Tp-shop 2.0.5 through 2.0.8, which allows remote attackers to obtain sensitive information,… Tp Shop after 2.0.8 Fix from $2,3002018-05-02 CRITICAL 9.1 CVE-2018-9302EPSS 9% SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary files or send T… Cockpit after 0.5.5 Fix from $2,3002018-05-02 CRITICAL 9.8 CVE-2018-8939 An SSRF issue was discovered in NmAPI.exe in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can submit specially crafted requests via the… Whatsup Gold 18.0+ Fix from $2,3002018-05-01 MEDIUM 6.5 CVE-2018-8801 GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component. GitLab 10.3+ Fix from $1,6002018-04-25 MEDIUM 6.5 CVE-2018-10174 Digital Guardian Management Console 7.1.2.0015 has an SSRF issue that allows remote attackers to read arbitrary files via file:// URLs, send TCP traf… Management Console No fix yet Fix from $1,6002018-04-20 HIGH 8.8 CVE-2018-10220 Glastopf 3.1.3-dev has SSRF, as demonstrated by the abc.php a parameter. NOTE: the vendor indicates that this is intentional behavior because the pro… Glastopf No fix yet Fix from $1,9502018-04-19 CRITICAL 9.8 CVE-2017-14323 SSRF (Server Side Request Forgery) in getRemoteImage.php in Ueditor in Onethink V1.0 and V1.1 allows remote attackers to obtain sensitive information… Onethink No fix yet Fix from $2,3002018-04-10 CRITICAL 9.1 CVE-2017-14611 SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the ur… Cockpit No fix yet Fix from $2,3002018-04-10 HIGH 7.2 CVE-2017-18096 The OAuth status rest resource in Atlassian Application Links before version 5.2.7, from 5.3.0 before 5.3.4 and from 5.4.0 before 5.4.3 allows remote… Application Links 5.2.7 / 5.3.4+ Fix from $1,9502018-04-04 CRITICAL 9.8 CVE-2017-16614 SSRF (Server Side Request Forgery) in tpshop 2.0.5 and 2.0.6 allows remote attackers to obtain sensitive information, attack intranet hosts, or possi… Tpshop Mitigation only Fix from $2,3002018-03-30 CRITICAL 9.1 CVE-2018-1000138 I, Librarian version 4.8 and earlier contains a SSRF vulnerability in "url" parameter of getFromWeb in functions.php that can result in the attacker … I\, Librarian after 4.8 Fix from $2,3002018-03-23 HIGH 7.3 CVE-2018-7516 A server-side request forgery vulnerability has been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 I… G Cam\/efd 2250 Firmware Mitigation only Fix from $1,9502018-03-22