Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2023-10-25 CVE-2023-43795 Server-Side Request Forgery (SSRF) vulnerability in Osgeo Geoserver
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.
network
low complexity
osgeo CWE-918
critical
9.8
2023-10-25 CVE-2023-46124 Server-Side Request Forgery (SSRF) vulnerability in Ethyca Fides
Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in runtime environments, and the enforcement of privacy regulations in code.
network
low complexity
ethyca CWE-918
7.2
2023-10-23 CVE-2023-45966 Server-Side Request Forgery (SSRF) vulnerability in Remark42
umputun remark42 version 1.12.1 and before has a Blind Server-Side Request Forgery (SSRF) vulnerability.
network
low complexity
remark42 CWE-918
7.5
2023-10-22 CVE-2023-46303 Server-Side Request Forgery (SSRF) vulnerability in Calibre-Ebook Calibre
link_to_local_path in ebooks/conversion/plugins/html_input.py in calibre before 6.19.0 can, by default, add resources outside of the document root.
network
low complexity
calibre-ebook CWE-918
7.5
2023-10-20 CVE-2023-44256 Server-Side Request Forgery (SSRF) vulnerability in Fortinet Fortianalyzer and Fortimanager
A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 and FortiManager version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 allows a remote attacker with low privileges to view sensitive data from internal servers or perform a local port scan via a crafted HTTP request.
network
low complexity
fortinet CWE-918
6.5
2023-10-19 CVE-2023-41899 Server-Side Request Forgery (SSRF) vulnerability in Home-Assistant
Home assistant is an open source home automation.
network
low complexity
home-assistant CWE-918
7.2
2023-10-19 CVE-2023-45822 Server-Side Request Forgery (SSRF) vulnerability in Artifacthub HUB
Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for CNCF projects.
network
low complexity
artifacthub CWE-918
5.3
2023-10-19 CVE-2023-25753 Server-Side Request Forgery (SSRF) vulnerability in Apache Shenyu 2.5.1
There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint.
network
low complexity
apache CWE-918
6.5
2023-10-19 CVE-2023-46229 Server-Side Request Forgery (SSRF) vulnerability in Langchain
LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server.
network
low complexity
langchain CWE-918
8.8
2023-10-17 CVE-2023-45152 Server-Side Request Forgery (SSRF) vulnerability in Engelsystem
Engelsystem is a shift planning system for chaos events.
local
low complexity
engelsystem CWE-918
2.3