Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2023-02-01 CVE-2022-37033 Server-Side Request Forgery (SSRF) vulnerability in Dotcms
In dotCMS 5.x-22.06, TempFileAPI allows a user to create a temporary file based on a passed in URL, while attempting to block any SSRF access to local IP addresses or private subnets.
network
low complexity
dotcms CWE-918
6.5
2023-02-01 CVE-2022-47872 Server-Side Request Forgery (SSRF) vulnerability in Maccms 10.0
A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a crafted payload injected into the Name parameter under the Interface address module.
network
low complexity
maccms CWE-918
8.8
2023-01-30 CVE-2023-24622 Server-Side Request Forgery (SSRF) vulnerability in Includesecurity Safeurl-Python 1.0
isInList in the safeurl-python package before 1.2 for Python has an insufficiently restrictive regular expression for external domains, leading to SSRF.
network
low complexity
includesecurity CWE-918
5.3
2023-01-30 CVE-2023-24623 Server-Side Request Forgery (SSRF) vulnerability in Paranoidhttp Project Paranoidhttp 0.1.0/0.2.0
Paranoidhttp before 0.3.0 allows SSRF because [::] is equivalent to the 127.0.0.1 address, but does not match the filter for private addresses.
network
low complexity
paranoidhttp-project CWE-918
7.5
2023-01-27 CVE-2022-4201 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
A blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 allows an attacker to connect to local addresses when configuring a malicious GitLab Runner.
network
low complexity
gitlab CWE-918
5.3
2023-01-27 CVE-2022-4335 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
A blind SSRF vulnerability was identified in all versions of GitLab EE prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which allows an attacker to connect to a local host.
network
low complexity
gitlab CWE-918
4.3
2023-01-27 CVE-2023-24060 Server-Side Request Forgery (SSRF) vulnerability in Havenweb Haven 5D15944
Haven 5d15944 allows Server-Side Request Forgery (SSRF) via the feed[url]= Feeds functionality.
network
low complexity
havenweb CWE-918
5.0
2023-01-26 CVE-2022-46998 Server-Side Request Forgery (SSRF) vulnerability in Taogogo Taocms 3.0.2
An issue in the website background of taocms v3.0.2 allows attackers to execute a Server-Side Request Forgery (SSRF).
network
low complexity
taogogo CWE-918
critical
9.8
2023-01-26 CVE-2023-24495 Server-Side Request Forgery (SSRF) vulnerability in Tenable Tenable.Sc
A Server Side Request Forgery (SSRF) vulnerability exists in Tenable.sc due to improper validation of session & user-accessible input data.
network
low complexity
tenable CWE-918
6.5
2023-01-23 CVE-2023-23560 Server-Side Request Forgery (SSRF) vulnerability in Lexmark products
In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.
network
low complexity
lexmark CWE-918
critical
9.8