Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2014-3990EPSS 7%
The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to conduct server-side request forger…
Opencart
after 1.5.6.4
CRITICAL 10.0
CVE-2018-1000124
I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_s…
I\, Librarian
after 4.8
CRITICAL 9.8
CVE-2018-7667
Adminer through 4.3.1 has SSRF via the server parameter.
Adminer
after 4.3.1
MEDIUM 5.3
CVE-2018-1000067
An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to have Jen…
Jenkins
after 2.106
HIGH 7.5
CVE-2018-7055
GroupViewProxyServlet in RoomWizard before 4.4.x allows SSRF via the url parameter.
Roomwizard Firmware
4.4.0+
MEDIUM 5.3
CVE-2018-2370
Server Side Request Forgery (SSRF) vulnerability in SAP Central Management Console, BI Launchpad and Fiori BI Launchpad, 4.10, from 4.20, from 4.30, …
Bi Launchpad
Mitigation only
HIGH 8.3
CVE-2018-1000056
Jenkins JUnit Plugin 1.23 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user p…
Junit
after 1.23
HIGH 8.3
CVE-2018-1000054
Jenkins CCM Plugin 3.1 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user perm…
Ccm
after 3.1
HIGH 8.3
CVE-2018-1000055
Jenkins Android Lint Plugin 2.5 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with …
Android Lint
after 2.5
HIGH 8.1
CVE-2017-6201
A Server Side Request Forgery vulnerability exists in the install app process in Sandstorm before build 0.203. A remote attacker may exploit this iss…
Sandstorm
0.203+
HIGH 8.8
CVE-2018-6186
Citrix NetScaler VPX through NS12.0 53.13.nc allows an SSRF attack via the /rapi/read_url URI by an authenticated attacker who has a webapp account. …
Netscaler
Mitigation only
HIGH 7.5
CVE-2018-6029
The copy function in application/admin/controller/Article.php in NoneCms 1.3.0 allows remote attackers to access the content of internal and external…
Nonecms
No fix yet
MEDIUM 6.5
CVE-2018-1042EPSS 16%
Moodle 3.x has Server Side Request Forgery in the filepicker.
Moodle
after 3.1.9
MEDIUM 5.3
CVE-2017-16865
The Trello importer in Atlassian Jira before version 7.6.1 allows remote attackers to access the content of internal network resources via a Server S…
Jira
7.6.1+
HIGH 7.5
CVE-2017-1000419
phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting internal …
Phpbb
No fix yet
MEDIUM 6.5
CVE-2017-15886
Server-side request forgery (SSRF) vulnerability in Link Preview in Synology Chat before 2.0.0-1124 allows remote authenticated users to download arb…
Chat
2.0.0-1124+
HIGH 8.6
CVE-2017-17697
The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/ping.
Harbor
1.3.0+
MEDIUM 5.3
CVE-2017-15943
The configuration file import for applications, spyware and vulnerability objects functionality in the web interface in Palo Alto Networks PAN-OS bef…
Pan Os
6.1.19 / 7.0.19+
CRITICAL 10.0
CVE-2017-11291EPSS 6%
An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A Server-Side Request Forgery (SSRF) vulnerability exists that could be abused t…
Connect
after 9.6.2
HIGH 7.2
CVE-2017-14585
A Server Side Request Forgery (SSRF) vulnerability could lead to remote code execution for authenticated administrators. This issue was introduced in…
Hipchat Data Center
2.2.6 / 3.1.0+
HIGH 7.5
CVE-2017-4928
The flash-based vSphere Web Client (6.0 prior to 6.0 U3c and 5.5 prior to 5.5 U3f) i.e. not the new HTML5-based vSphere Client, contains SSRF and CRL…
Vcenter Server
Patch available
HIGH 8.1
CVE-2017-16870
The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugins/updraftplus/admin.php via a…
Updraftplus
after 1.13.12
CRITICAL 9.8
CVE-2017-1000237
I, Librarian version <=4.6 & 4.7 is vulnerable to Server-Side Request Forgery in the ajaxsupplement.php resulting in the attacker being able to reset…
I\, Librarian
after 4.6
CRITICAL 9.8
CVE-2017-0889
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter class. Attack…
Paperclip
5.2.0+
CRITICAL 9.8
CVE-2017-0905
The Recurly Client Ruby Library before 2.0.13, 2.1.11, 2.2.5, 2.3.10, 2.4.11, 2.5.4, 2.6.3, 2.7.8, 2.8.2, 2.9.2, 2.10.4, 2.11.3 is vulnerable to a Se…
Recurly Client Ruby
Patch available
CRITICAL 9.8
CVE-2017-0906
The Recurly Client Python Library before 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1, 2.6.2 is vulnerable to a Server-Side Request Forgery vulnerabili…
Recurly Client Python
after 2.4.4
CRITICAL 9.8
CVE-2017-0907
The Recurly Client .NET Library before 1.0.1, 1.1.10, 1.2.8, 1.3.2, 1.4.14, 1.5.3, 1.6.2, 1.7.1, 1.8.1 is vulnerable to a Server-Side Request Forgery…
Recurly Client .net
Patch available
HIGH 8.0
CVE-2017-1000139
Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to server-side request forgery attacks as…
Mahara
Patch available
HIGH 8.6
CVE-2017-15644EPSS 9%
SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:8000.
Webmin
after 1.850
MEDIUM 6.3
CVE-2017-7553
The external_request api call in App Studio (millicore) allows server side request forgery (SSRF). An attacker could use this flaw to probe the netwo…
Mobile Application Platform
after 4.4.3