Vulnerability index

Browse CVEs

2,859 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
CRITICAL 10.0 CVE-2017-12905 Server Side Request Forgery vulnerability in Vebto Pixie Image Editor 1.4 and 1.7 allows remote attackers to disclose information or execute arbitrar… Pixie Image Editor Mitigation only Fix from $2,3002017-09-25 MEDIUM 6.5 CVE-2017-12071 Server-side request forgery (SSRF) vulnerability in file_upload.php in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authentica… Photo Station after 6.7.3-3432 Fix from $1,6002017-09-08 CRITICAL 9.8 CVE-2017-9458 XML external entity (XXE) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.… Pan Os after 6.1.17 Fix from $2,3002017-09-07 MEDIUM 6.1 CVE-2017-9506EPSS 72% The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote a… Oauth No fix yet Fix from $1,6002017-08-23 MEDIUM 6.5 CVE-2017-11149 Server-side request forgery (SSRF) vulnerability in Downloader in Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 allows re… Download Station Mitigation only Fix from $1,6002017-08-14 MEDIUM 6.5 CVE-2017-11148 Server-side request forgery (SSRF) vulnerability in link preview in Synology Chat before 1.1.0-0806 allows remote authenticated users to access intra… Chat after 1.0.2-0159 Fix from $1,6002017-08-11 HIGH 8.8 CVE-2017-1000017 phpMyAdmin 4.0, 4.4 and 4.6 are vulnerable to a weakness where a user with appropriate permissions is able to connect to an arbitrary MySQL server phpMyAdmin 4.0.10.19+ Fix from $1,9502017-07-17 MEDIUM 6.5 CVE-2017-10973 In FineCMS before 2017-07-06, application/lib/ajax/get_image_data.php has SSRF, related to requests for non-image files with a modified HTTP Host hea… Finecms after 2017-05-12 Fix from $1,6002017-07-06 MEDIUM 6.5 CVE-2017-6036 A Server-Side Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web server … Gecko Lite Managed Switch Firmware after 2.0.00 Fix from $1,6002017-06-30 HIGH 7.4 CVE-2017-9355EPSS 27% XML external entity (XXE) vulnerability in the import playlist feature in Subsonic 6.1.1 might allow remote attackers to conduct server-side request … Subsonic No fix yet Fix from $1,9502017-06-07 MEDIUM 6.5 CVE-2017-9307 SSRF vulnerability in remotedownload.php in Allen Disk 1.6 allows remote authenticated users to conduct port scans and access intranet servers via a … Allen Disk Mitigation only Fix from $1,6002017-05-31 HIGH 8.6 CVE-2017-9066 In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF. WordPress after 4.7.4 Fix from $1,9502017-05-18 CRITICAL 10.0 CVE-2017-8794 An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because a regular expression (intended to match local https URLs) lacks an init… File Transfer Appliance after 9_12_40 Fix from $2,3002017-05-05 MEDIUM 6.5 CVE-2017-3546EPSS 10% Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: MultiChannel Framework). Supported vers… Peoplesoft Enterprise Peopletools Patch available Fix from $1,6002017-04-24 HIGH 7.2 CVE-2015-7570EPSS 6% Multiple server-side request forgery (SSRF) vulnerabilities in Yeager CMS 1.2.1 allow remote attackers to trigger outbound requests and enumerate ope… Yeager Cms Patch available Fix from $1,9502017-04-24 HIGH 8.6 CVE-2016-7051 XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct… Jackson Dataformat Xml 2.7.8+ Fix from $1,9502017-04-14 HIGH 8.6 CVE-2017-7569 In vBulletin before 5.3.0, remote attackers can bypass the CVE-2016-6483 patch and conduct SSRF attacks by leveraging the behavior of the PHP parse_u… Vbulletin after 5.2.6 Fix from $1,9502017-04-06 HIGH 7.7 CVE-2017-7566 MyBB before 1.8.11 allows remote attackers to bypass an SSRF protection mechanism. Mybb after 1.8.10 Fix from $1,9502017-04-06 HIGH 7.4 CVE-2017-6130 F5 SSL Intercept iApp 1.5.0 - 1.5.7 and SSL Orchestrator 2.0 is vulnerable to a Server-Side Request Forgery (SSRF) attack when deployed using the Dyn… Ssl Intercept Iapp Mitigation only Fix from $1,9502017-04-06 HIGH 7.4 CVE-2017-7272 PHP through 7.1.11 enables potential SSRF in applications that accept an fsockopen or pfsockopen hostname argument with an expectation that the port … PHP after 7.1.3 Fix from $1,9502017-03-27 MEDIUM 5.8 CVE-2017-7200 An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform ma… Glance Mitigation only Fix from $1,6002017-03-21 HIGH 7.4 CVE-2017-5617 The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attackers to conduct server-side request forgery (SSRF)… Debian Linux Patch available Fix from $1,9502017-03-16 HIGH 7.4 CVE-2017-5643EPSS 6% Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE. Camel after 2.16.0 Fix from $1,9502017-03-16 HIGH 8.2 CVE-2015-8813EPSS 11% The Page_Load function in Umbraco.Web/umbraco.presentation/umbraco/dashboard/FeedProxy.aspx.cs in Umbraco before 7.4.0 allows remote attackers to con… Umbraco after 7.3.8 Fix from $1,9502017-03-03 HIGH 7.4 CVE-2016-9417 The fetch_remote_file function in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to conduct serve… Merge System after 1.8.7 Fix from $1,9502017-01-31 HIGH 8.6 CVE-2016-6621 The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15.10, and 4.6.x before 4.6.6 allows remote attackers to conduct server-side reque… phpMyAdmin after 4.0.10.18 Fix from $1,9502017-01-31 HIGH 7.4 CVE-2016-7999 ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to conduct server side request forgery (SSRF) attacks via a URL in the … Spip after 3.1.2 Fix from $1,9502017-01-18 HIGH 7.4 CVE-2017-5518 The media-file upload feature in GeniXCMS through 0.0.8 allows remote attackers to conduct SSRF attacks via a URL, as demonstrated by a URL with an i… Genixcms after 0.0.8 Fix from $1,9502017-01-17 MEDIUM 5.8 CVE-2016-4046 An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. The API to configure external mail accounts can be abused to map and access … Open Xchange Appsuite after 7.8.1 Fix from $1,6002016-12-15 HIGH 8.6 CVE-2016-9752 In Serendipity before 2.0.5, an attacker can bypass SSRF protection by using a malformed IP address (e.g., http://127.1) or a 30x (aka Redirection) H… Serendipity after 2.0.4 Fix from $1,9502016-12-01