Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 10.0
CVE-2017-12905
Server Side Request Forgery vulnerability in Vebto Pixie Image Editor 1.4 and 1.7 allows remote attackers to disclose information or execute arbitrar…
Pixie Image Editor
Mitigation only
MEDIUM 6.5
CVE-2017-12071
Server-side request forgery (SSRF) vulnerability in file_upload.php in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authentica…
Photo Station
after 6.7.3-3432
CRITICAL 9.8
CVE-2017-9458
XML external entity (XXE) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.…
Pan Os
after 6.1.17
MEDIUM 6.1
CVE-2017-9506EPSS 72%
The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote a…
Oauth
No fix yet
MEDIUM 6.5
CVE-2017-11149
Server-side request forgery (SSRF) vulnerability in Downloader in Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 allows re…
Download Station
Mitigation only
MEDIUM 6.5
CVE-2017-11148
Server-side request forgery (SSRF) vulnerability in link preview in Synology Chat before 1.1.0-0806 allows remote authenticated users to access intra…
Chat
after 1.0.2-0159
HIGH 8.8
CVE-2017-1000017
phpMyAdmin 4.0, 4.4 and 4.6 are vulnerable to a weakness where a user with appropriate permissions is able to connect to an arbitrary MySQL server
phpMyAdmin
4.0.10.19+
MEDIUM 6.5
CVE-2017-10973
In FineCMS before 2017-07-06, application/lib/ajax/get_image_data.php has SSRF, related to requests for non-image files with a modified HTTP Host hea…
Finecms
after 2017-05-12
MEDIUM 6.5
CVE-2017-6036
A Server-Side Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web server …
Gecko Lite Managed Switch Firmware
after 2.0.00
HIGH 7.4
CVE-2017-9355EPSS 27%
XML external entity (XXE) vulnerability in the import playlist feature in Subsonic 6.1.1 might allow remote attackers to conduct server-side request …
Subsonic
No fix yet
MEDIUM 6.5
CVE-2017-9307
SSRF vulnerability in remotedownload.php in Allen Disk 1.6 allows remote authenticated users to conduct port scans and access intranet servers via a …
Allen Disk
Mitigation only
HIGH 8.6
CVE-2017-9066
In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.
WordPress
after 4.7.4
CRITICAL 10.0
CVE-2017-8794
An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because a regular expression (intended to match local https URLs) lacks an init…
File Transfer Appliance
after 9_12_40
MEDIUM 6.5
CVE-2017-3546EPSS 10%
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: MultiChannel Framework). Supported vers…
Peoplesoft Enterprise Peopletools
Patch available
HIGH 7.2
CVE-2015-7570EPSS 6%
Multiple server-side request forgery (SSRF) vulnerabilities in Yeager CMS 1.2.1 allow remote attackers to trigger outbound requests and enumerate ope…
Yeager Cms
Patch available
HIGH 8.6
CVE-2016-7051
XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct…
Jackson Dataformat Xml
2.7.8+
HIGH 8.6
CVE-2017-7569
In vBulletin before 5.3.0, remote attackers can bypass the CVE-2016-6483 patch and conduct SSRF attacks by leveraging the behavior of the PHP parse_u…
Vbulletin
after 5.2.6
HIGH 7.7
CVE-2017-7566
MyBB before 1.8.11 allows remote attackers to bypass an SSRF protection mechanism.
Mybb
after 1.8.10
HIGH 7.4
CVE-2017-6130
F5 SSL Intercept iApp 1.5.0 - 1.5.7 and SSL Orchestrator 2.0 is vulnerable to a Server-Side Request Forgery (SSRF) attack when deployed using the Dyn…
Ssl Intercept Iapp
Mitigation only
HIGH 7.4
CVE-2017-7272
PHP through 7.1.11 enables potential SSRF in applications that accept an fsockopen or pfsockopen hostname argument with an expectation that the port …
PHP
after 7.1.3
MEDIUM 5.8
CVE-2017-7200
An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform ma…
Glance
Mitigation only
HIGH 7.4
CVE-2017-5617
The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attackers to conduct server-side request forgery (SSRF)…
Debian Linux
Patch available
HIGH 7.4
CVE-2017-5643EPSS 6%
Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.
Camel
after 2.16.0
HIGH 8.2
CVE-2015-8813EPSS 11%
The Page_Load function in Umbraco.Web/umbraco.presentation/umbraco/dashboard/FeedProxy.aspx.cs in Umbraco before 7.4.0 allows remote attackers to con…
Umbraco
after 7.3.8
HIGH 7.4
CVE-2016-9417
The fetch_remote_file function in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to conduct serve…
Merge System
after 1.8.7
HIGH 8.6
CVE-2016-6621
The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15.10, and 4.6.x before 4.6.6 allows remote attackers to conduct server-side reque…
phpMyAdmin
after 4.0.10.18
HIGH 7.4
CVE-2016-7999
ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to conduct server side request forgery (SSRF) attacks via a URL in the …
Spip
after 3.1.2
HIGH 7.4
CVE-2017-5518
The media-file upload feature in GeniXCMS through 0.0.8 allows remote attackers to conduct SSRF attacks via a URL, as demonstrated by a URL with an i…
Genixcms
after 0.0.8
MEDIUM 5.8
CVE-2016-4046
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. The API to configure external mail accounts can be abused to map and access …
Open Xchange Appsuite
after 7.8.1
HIGH 8.6
CVE-2016-9752
In Serendipity before 2.0.5, an attacker can bypass SSRF protection by using a malformed IP address (e.g., http://127.1) or a 30x (aka Redirection) H…
Serendipity
after 2.0.4