Vulnerability index

Browse CVEs

2,859 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
CRITICAL 9.8 CVE-2014-3990EPSS 7% The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to conduct server-side request forger… Opencart after 1.5.6.4 Fix from $2,3002018-03-20 CRITICAL 10.0 CVE-2018-1000124 I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_s… I\, Librarian after 4.8 Fix from $2,3002018-03-13 CRITICAL 9.8 CVE-2018-7667 Adminer through 4.3.1 has SSRF via the server parameter. Adminer after 4.3.1 Fix from $2,3002018-03-05 MEDIUM 5.3 CVE-2018-1000067 An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to have Jen… Jenkins after 2.106 Fix from $1,6002018-02-16 HIGH 7.5 CVE-2018-7055 GroupViewProxyServlet in RoomWizard before 4.4.x allows SSRF via the url parameter. Roomwizard Firmware 4.4.0+ Fix from $1,9502018-02-15 MEDIUM 5.3 CVE-2018-2370 Server Side Request Forgery (SSRF) vulnerability in SAP Central Management Console, BI Launchpad and Fiori BI Launchpad, 4.10, from 4.20, from 4.30, … Bi Launchpad Mitigation only Fix from $1,6002018-02-14 HIGH 8.3 CVE-2018-1000056 Jenkins JUnit Plugin 1.23 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user p… Junit after 1.23 Fix from $1,9502018-02-09 HIGH 8.3 CVE-2018-1000054 Jenkins CCM Plugin 3.1 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user perm… Ccm after 3.1 Fix from $1,9502018-02-09 HIGH 8.3 CVE-2018-1000055 Jenkins Android Lint Plugin 2.5 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with … Android Lint after 2.5 Fix from $1,9502018-02-09 HIGH 8.1 CVE-2017-6201 A Server Side Request Forgery vulnerability exists in the install app process in Sandstorm before build 0.203. A remote attacker may exploit this iss… Sandstorm 0.203+ Fix from $1,9502018-02-06 HIGH 8.8 CVE-2018-6186 Citrix NetScaler VPX through NS12.0 53.13.nc allows an SSRF attack via the /rapi/read_url URI by an authenticated attacker who has a webapp account. … Netscaler Mitigation only Fix from $1,9502018-02-01 HIGH 7.5 CVE-2018-6029 The copy function in application/admin/controller/Article.php in NoneCms 1.3.0 allows remote attackers to access the content of internal and external… Nonecms No fix yet Fix from $1,9502018-01-23 MEDIUM 6.5 CVE-2018-1042EPSS 16% Moodle 3.x has Server Side Request Forgery in the filepicker. Moodle after 3.1.9 Fix from $1,6002018-01-22 MEDIUM 5.3 CVE-2017-16865 The Trello importer in Atlassian Jira before version 7.6.1 allows remote attackers to access the content of internal network resources via a Server S… Jira 7.6.1+ Fix from $1,6002018-01-17 HIGH 7.5 CVE-2017-1000419 phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting internal … Phpbb No fix yet Fix from $1,9502018-01-02 MEDIUM 6.5 CVE-2017-15886 Server-side request forgery (SSRF) vulnerability in Link Preview in Synology Chat before 2.0.0-1124 allows remote authenticated users to download arb… Chat 2.0.0-1124+ Fix from $1,6002017-12-28 HIGH 8.6 CVE-2017-17697 The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/ping. Harbor 1.3.0+ Fix from $1,9502017-12-15 MEDIUM 5.3 CVE-2017-15943 The configuration file import for applications, spyware and vulnerability objects functionality in the web interface in Palo Alto Networks PAN-OS bef… Pan Os 6.1.19 / 7.0.19+ Fix from $1,6002017-12-11 CRITICAL 10.0 CVE-2017-11291EPSS 6% An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A Server-Side Request Forgery (SSRF) vulnerability exists that could be abused t… Connect after 9.6.2 Fix from $2,3002017-12-09 HIGH 7.2 CVE-2017-14585 A Server Side Request Forgery (SSRF) vulnerability could lead to remote code execution for authenticated administrators. This issue was introduced in… Hipchat Data Center 2.2.6 / 3.1.0+ Fix from $1,9502017-11-27 HIGH 7.5 CVE-2017-4928 The flash-based vSphere Web Client (6.0 prior to 6.0 U3c and 5.5 prior to 5.5 U3f) i.e. not the new HTML5-based vSphere Client, contains SSRF and CRL… Vcenter Server Patch available Fix from $1,9502017-11-17 HIGH 8.1 CVE-2017-16870 The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugins/updraftplus/admin.php via a… Updraftplus after 1.13.12 Fix from $1,9502017-11-17 CRITICAL 9.8 CVE-2017-1000237 I, Librarian version <=4.6 & 4.7 is vulnerable to Server-Side Request Forgery in the ajaxsupplement.php resulting in the attacker being able to reset… I\, Librarian after 4.6 Fix from $2,3002017-11-17 CRITICAL 9.8 CVE-2017-0889 Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter class. Attack… Paperclip 5.2.0+ Fix from $2,3002017-11-13 CRITICAL 9.8 CVE-2017-0905 The Recurly Client Ruby Library before 2.0.13, 2.1.11, 2.2.5, 2.3.10, 2.4.11, 2.5.4, 2.6.3, 2.7.8, 2.8.2, 2.9.2, 2.10.4, 2.11.3 is vulnerable to a Se… Recurly Client Ruby Patch available Fix from $2,3002017-11-13 CRITICAL 9.8 CVE-2017-0906 The Recurly Client Python Library before 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1, 2.6.2 is vulnerable to a Server-Side Request Forgery vulnerabili… Recurly Client Python after 2.4.4 Fix from $2,3002017-11-13 CRITICAL 9.8 CVE-2017-0907 The Recurly Client .NET Library before 1.0.1, 1.1.10, 1.2.8, 1.3.2, 1.4.14, 1.5.3, 1.6.2, 1.7.1, 1.8.1 is vulnerable to a Server-Side Request Forgery… Recurly Client .net Patch available Fix from $2,3002017-11-13 HIGH 8.0 CVE-2017-1000139 Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to server-side request forgery attacks as… Mahara Patch available Fix from $1,9502017-11-03 HIGH 8.6 CVE-2017-15644EPSS 9% SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:8000. Webmin after 1.850 Fix from $1,9502017-10-19 MEDIUM 6.3 CVE-2017-7553 The external_request api call in App Studio (millicore) allows server side request forgery (SSRF). An attacker could use this flaw to probe the netwo… Mobile Application Platform after 4.4.3 Fix from $1,6002017-09-29