Vulnerability index

Browse CVEs

72 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HTTP Server HIGH 7.5
CVE-2024-40898

SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF…

Fix: 2.4.62+
Fix from $1,950 2024-07-18
HTTP Server HIGH 7.5
CVE-2024-38472EPSS 69%

SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users …

Fix: 2.4.60+
Fix from $1,950 2024-07-01
Allura HIGH 7.5
CVE-2024-36471

Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL.  Project administrators can run these imp…

Fix: 1.17.0+
Fix from $1,950 2024-06-10
Hugegraph Hubble MEDIUM 5.3
CVE-2024-27347

Server-Side Request Forgery (SSRF) vulnerability in Apache HugeGraph-Hubble.This issue affects Apache HugeGraph-Hubble: from 1.0.0 before 1.3.0. Use…

Fix: 1.3.0+
Fix from $1,600 2024-04-22
Cloudstack HIGH 7.3
CVE-2024-29007

The CloudStack management server and secondary storage VM could be tricked into making requests to restricted or random resources by means of followi…

Fix: 4.18.1.1+
Fix from $1,950 2024-04-04
Cxf CRITICAL 9.3
CVE-2024-28752

A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style att…

Fix: 3.5.8 / 3.6.3+
Fix from $2,300 2024-03-15
Servicecomb HIGH 7.5
CVE-2023-44313

Server-Side Request Forgery (SSRF) vulnerability in Apache ServiceComb Service-Center. Attackers can obtain sensitive server information through spec…

Fix: 2.2.0+
Fix from $1,950 2024-01-31
Axis HIGH 7.2
CVE-2023-51441

** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Axis allowed users with access to the admin service to perform poss…

Fix: after 1.3
Fix from $1,950 2024-01-06
Ofbiz CRITICAL 9.8
CVE-2023-51467EPSS 96%

The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code

Fix: 18.12.11+
Fix from $2,300 2023-12-26
Ofbiz HIGH 7.5
CVE-2023-50968EPSS 63%

Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations. Th…

Fix: 18.12.11+
Fix from $1,950 2023-12-26
Shenyu MEDIUM 6.5
CVE-2023-25753

There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint. This vulnerability allows us to manip…

Mitigation only
Fix from $1,600 2023-10-19
Superset MEDIUM 5.4
CVE-2023-36388

Improper REST API permission in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma users to test network connections, possib…

Fix: after 2.1.0
Fix from $1,600 2023-09-06
Airflow HIGH 8.1
CVE-2023-37379

Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection ed…

Fix: 2.7.0+
Fix from $1,950 2023-08-23
Xml Graphics Batik HIGH 7.1
CVE-2022-44729

Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik…

Fix: after 1.16
Fix from $1,950 2023-08-22
Superset MEDIUM 6.5
CVE-2023-25504

A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import dataset feature in order to condu…

Fix: after 2.0.1
Fix from $1,600 2023-04-17
Fineract HIGH 8.1
CVE-2023-25195

Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache Fineract. Authorized users with limited permissions can gain ac…

Fix: after 1.8.3
Fix from $1,950 2023-03-28
Cxf CRITICAL 9.8
CVE-2022-46364

A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attack…

Fix: 3.4.10 / 3.5.5+
Fix from $2,300 2022-12-13
Batik HIGH 7.5
CVE-2022-41704

A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics pri…

Fix: 1.16+
Fix from $1,950 2022-10-25
Batik HIGH 7.5
CVE-2022-42890

A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML …

Fix: 1.16+
Fix from $1,950 2022-10-25
Batik HIGH 7.5
CVE-2022-40146EPSS 6%

Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affec…

Mitigation only
Fix from $1,950 2022-09-22
Batik MEDIUM 5.3
CVE-2022-38398

Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue a…

Mitigation only
Fix from $1,600 2022-09-22
Batik MEDIUM 5.3
CVE-2022-38648

Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects A…

Mitigation only
Fix from $1,600 2022-09-22
Dubbo MEDIUM 6.1
CVE-2022-24969

bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check whic…

Fix: 2.6.12 / 2.7.15+
Fix from $1,600 2022-06-09
Traffic Control HIGH 7.5
CVE-2022-23206

In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted…

Fix: 5.1.6 / 6.1.0+
Fix from $1,950 2022-02-06
Kylin HIGH 7.5
CVE-2021-27738

All request mappings in `StreamingCoordinatorController.java` handling `/kylin/api/streaming_coordinator/*` REST API endpoints did not include any se…

Fix: 3.1.2+
Fix from $1,950 2022-01-06
Dubbo MEDIUM 6.1
CVE-2021-25640

In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or S…

Fix: 2.6.9 / 2.7.9+
Fix from $1,600 2021-06-01
Solr CRITICAL 9.8
CVE-2021-27905EPSS 93%

The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter …

Fix: 8.8.2+
Fix from $2,300 2021-04-13
Cxf HIGH 7.5
CVE-2021-22696EPSS 7%

CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization F…

Fix: 3.3.10 / 3.4.3+
Fix from $1,950 2021-04-02
Activemq HIGH 8.6
CVE-2021-21349EPSS 47%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $1,950 2021-03-23
Activemq CRITICAL 9.1
CVE-2021-21342EPSS 50%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed …

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23