Vulnerability index

Browse CVEs

72 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 7.5 CVE-2024-40898 SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF… HTTP Server 2.4.62+ Fix from $1,9502024-07-18 HIGH 7.5 CVE-2024-38472EPSS 69% SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users … HTTP Server 2.4.60+ Fix from $1,9502024-07-01 HIGH 7.5 CVE-2024-36471 Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL.  Project administrators can run these imp… Allura 1.17.0+ Fix from $1,9502024-06-10 MEDIUM 5.3 CVE-2024-27347 Server-Side Request Forgery (SSRF) vulnerability in Apache HugeGraph-Hubble.This issue affects Apache HugeGraph-Hubble: from 1.0.0 before 1.3.0. Use… Hugegraph Hubble 1.3.0+ Fix from $1,6002024-04-22 HIGH 7.3 CVE-2024-29007 The CloudStack management server and secondary storage VM could be tricked into making requests to restricted or random resources by means of followi… Cloudstack 4.18.1.1+ Fix from $1,9502024-04-04 CRITICAL 9.3 CVE-2024-28752 A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style att… Cxf 3.5.8 / 3.6.3+ Fix from $2,3002024-03-15 HIGH 7.5 CVE-2023-44313 Server-Side Request Forgery (SSRF) vulnerability in Apache ServiceComb Service-Center. Attackers can obtain sensitive server information through spec… Servicecomb 2.2.0+ Fix from $1,9502024-01-31 HIGH 7.2 CVE-2023-51441 ** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Axis allowed users with access to the admin service to perform poss… Axis after 1.3 Fix from $1,9502024-01-06 CRITICAL 9.8 CVE-2023-51467EPSS 96% The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code Ofbiz 18.12.11+ Fix from $2,3002023-12-26 HIGH 7.5 CVE-2023-50968EPSS 63% Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations. Th… Ofbiz 18.12.11+ Fix from $1,9502023-12-26 MEDIUM 6.5 CVE-2023-25753 There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint. This vulnerability allows us to manip… Shenyu Mitigation only Fix from $1,6002023-10-19 MEDIUM 5.4 CVE-2023-36388 Improper REST API permission in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma users to test network connections, possib… Superset after 2.1.0 Fix from $1,6002023-09-06 HIGH 8.1 CVE-2023-37379 Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection ed… Airflow 2.7.0+ Fix from $1,9502023-08-23 HIGH 7.1 CVE-2022-44729 Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik… Xml Graphics Batik after 1.16 Fix from $1,9502023-08-22 MEDIUM 6.5 CVE-2023-25504 A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import dataset feature in order to condu… Superset after 2.0.1 Fix from $1,6002023-04-17 HIGH 8.1 CVE-2023-25195 Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache Fineract. Authorized users with limited permissions can gain ac… Fineract after 1.8.3 Fix from $1,9502023-03-28 CRITICAL 9.8 CVE-2022-46364 A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attack… Cxf 3.4.10 / 3.5.5+ Fix from $2,3002022-12-13 HIGH 7.5 CVE-2022-41704 A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics pri… Batik 1.16+ Fix from $1,9502022-10-25 HIGH 7.5 CVE-2022-42890 A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML … Batik 1.16+ Fix from $1,9502022-10-25 HIGH 7.5 CVE-2022-40146EPSS 6% Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affec… Batik Mitigation only Fix from $1,9502022-09-22 MEDIUM 5.3 CVE-2022-38398 Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue a… Batik Mitigation only Fix from $1,6002022-09-22 MEDIUM 5.3 CVE-2022-38648 Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects A… Batik Mitigation only Fix from $1,6002022-09-22 MEDIUM 6.1 CVE-2022-24969 bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check whic… Dubbo 2.6.12 / 2.7.15+ Fix from $1,6002022-06-09 HIGH 7.5 CVE-2022-23206 In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted… Traffic Control 5.1.6 / 6.1.0+ Fix from $1,9502022-02-06 HIGH 7.5 CVE-2021-27738 All request mappings in `StreamingCoordinatorController.java` handling `/kylin/api/streaming_coordinator/*` REST API endpoints did not include any se… Kylin 3.1.2+ Fix from $1,9502022-01-06 MEDIUM 6.1 CVE-2021-25640 In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or S… Dubbo 2.6.9 / 2.7.9+ Fix from $1,6002021-06-01 CRITICAL 9.8 CVE-2021-27905EPSS 93% The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter … Solr 8.8.2+ Fix from $2,3002021-04-13 HIGH 7.5 CVE-2021-22696EPSS 7% CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization F… Cxf 3.3.10 / 3.4.3+ Fix from $1,9502021-04-02 HIGH 8.6 CVE-2021-21349EPSS 47% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $1,9502021-03-23 CRITICAL 9.1 CVE-2021-21342EPSS 50% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed … Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23