Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2023-08-01 CVE-2023-39110 Server-Side Request Forgery (SSRF) vulnerability in Rconfig 3.9.4
rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path parameter at /ajaxGetFileByPath.php.
network
low complexity
rconfig CWE-918
8.8
2023-07-31 CVE-2022-42183 Server-Side Request Forgery (SSRF) vulnerability in Precisely Spectrum Spatial Analyst 20.01
Precisely Spectrum Spatial Analyst 20.01 is vulnerable to Server-Side Request Forgery (SSRF).
network
low complexity
precisely CWE-918
critical
9.1
2023-07-27 CVE-2023-3981 Server-Side Request Forgery (SSRF) vulnerability in Omeka
Server-Side Request Forgery (SSRF) in GitHub repository omeka/omeka-s prior to 4.0.2.
network
low complexity
omeka CWE-918
4.9
2023-07-21 CVE-2021-35391 Server-Side Request Forgery (SSRF) vulnerability in Deskpro 2021.21.6
Server Side Request Forgery vulnerability found in Deskpro Support Desk v2021.21.6 allows attackers to execute arbitrary code via a crafted URL.
network
low complexity
deskpro CWE-918
7.2
2023-07-19 CVE-2023-29260 Server-Side Request Forgery (SSRF) vulnerability in IBM Sterling Connect:Express for Unix 1.5.0
IBM Sterling Connect:Express for UNIX 1.5 is vulnerable to server-side request forgery (SSRF).
network
low complexity
ibm CWE-918
5.4
2023-07-17 CVE-2023-3577 Server-Side Request Forgery (SSRF) vulnerability in Mattermost Server
Mattermost fails to properly restrict requests to localhost/intranet during the interactive dialog, which could allow an attacker to perform a limited blind SSRF.
network
low complexity
mattermost CWE-918
4.3
2023-07-10 CVE-2021-42079 Server-Side Request Forgery (SSRF) vulnerability in Osnexus Quantastor 4.3.0
An authenticated administrator is able to prepare an alert that is able to execute an SSRF attack.
network
low complexity
osnexus CWE-918
4.9
2023-06-30 CVE-2023-35175 Server-Side Request Forgery (SSRF) vulnerability in HP products
Certain HP LaserJet Pro print products are potentially vulnerable to Potential Remote Code Execution and/or Elevation of Privilege via Server-Side Request Forgery (SSRF) using the Web Service Eventing model.
network
low complexity
hp CWE-918
critical
9.8
2023-06-25 CVE-2023-36661 Server-Side Request Forgery (SSRF) vulnerability in multiple products
Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element.
network
low complexity
shibboleth debian CWE-918
7.5
2023-06-22 CVE-2023-35133 Server-Side Request Forgery (SSRF) vulnerability in Moodle
An issue in the logic used to check 0.0.0.0 against the cURL blocked hosts lists resulted in an SSRF risk.
network
low complexity
moodle CWE-918
7.5