Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2023-06-20 CVE-2023-26431 Server-Side Request Forgery (SSRF) vulnerability in Open-Xchange Appsuite Backend
IPv4-mapped IPv6 addresses did not get recognized as "local" by the code and a connection attempt is made.
network
low complexity
open-xchange CWE-918
4.3
2023-06-20 CVE-2023-26435 Server-Side Request Forgery (SSRF) vulnerability in Open-Xchange Appsuite Backend
It was possible to call filesystem and network references using the local LibreOffice instance using manipulated ODT documents.
network
low complexity
open-xchange CWE-918
5.0
2023-06-16 CVE-2023-24243 Server-Side Request Forgery (SSRF) vulnerability in Cdata ARC 22.0.8336
CData RSB Connect v22.0.8336 was discovered to contain a Server-Side Request Forgery (SSRF).
network
low complexity
cdata CWE-918
7.5
2023-06-13 CVE-2023-25609 Server-Side Request Forgery (SSRF) vulnerability in Fortinet Fortianalyzer and Fortimanager
A server-side request forgery (SSRF) vulnerability [CWE-918] in FortiManager and FortiAnalyzer GUI 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.8 through 6.4.11 may allow a remote and authenticated attacker to access unauthorized files and services on the system via specially crafted web requests.
network
low complexity
fortinet CWE-918
6.5
2023-06-08 CVE-2023-32750 Server-Side Request Forgery (SSRF) vulnerability in Pydio Cells
Pydio Cells through 4.1.2 allows SSRF.
network
low complexity
pydio CWE-918
6.5
2023-06-08 CVE-2023-34959 Server-Side Request Forgery (SSRF) vulnerability in Chamilo LMS
An issue in Chamilo v1.11.* up to v1.11.18 allows attackers to execute a Server-Side Request Forgery (SSRF) and obtain information on the services running on the server via crafted requests in the social and links tools.
network
low complexity
chamilo CWE-918
5.3
2023-06-06 CVE-2023-3121 Server-Side Request Forgery (SSRF) vulnerability in Dahuasecurity Smart Parking Management
A vulnerability has been found in Dahua Smart Parking Management up to 20230528 and classified as problematic.
low complexity
dahuasecurity CWE-918
4.6
2023-06-01 CVE-2023-28824 Server-Side Request Forgery (SSRF) vulnerability in Contec Conprosys HMI System
Server-side request forgery vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3.
network
low complexity
contec CWE-918
4.9
2023-06-01 CVE-2023-23955 Server-Side Request Forgery (SSRF) vulnerability in Broadcom Advanced Secure Gateway and Content Analysis
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Server-Side Request Forgery vulnerability.
network
low complexity
broadcom CWE-918
8.1
2023-05-27 CVE-2023-33184 Server-Side Request Forgery (SSRF) vulnerability in Nextcloud Mail
Nextcloud Mail is a mail app in Nextcloud.
network
low complexity
nextcloud CWE-918
5.3