Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2022-11-17 CVE-2022-43183 Server-Side Request Forgery (SSRF) vulnerability in Xuxueli Xxl-Job
XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.
network
low complexity
xuxueli CWE-918
8.8
2022-11-17 CVE-2022-42894 Server-Side Request Forgery (SSRF) vulnerability in Siemens Syngo Dynamics Cardiovascular Imaging and Information System
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01).
network
low complexity
siemens CWE-918
7.5
2022-11-17 CVE-2022-43140 Server-Side Request Forgery (SSRF) vulnerability in Keking Kkfileview 4.1.0
kkFileView v4.1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component cn.keking.web.controller.OnlinePreviewController#getCorsFile.
network
low complexity
keking CWE-918
7.5
2022-11-16 CVE-2022-39383 Server-Side Request Forgery (SSRF) vulnerability in Linuxfoundation Kubevela
KubeVela is an open source application delivery platform.
network
low complexity
linuxfoundation CWE-918
6.5
2022-11-08 CVE-2022-42494 Server-Side Request Forgery (SSRF) vulnerability in Aioseo ALL in ONE SEO
Server Side Request Forgery (SSRF) vulnerability in All in One SEO Pro plugin <= 4.2.5.1 on WordPress.
network
low complexity
aioseo CWE-918
6.5
2022-11-04 CVE-2022-20951 Server-Side Request Forgery (SSRF) vulnerability in Cisco Broadworks Messaging Server 22.0
A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an authenticated, remote attacker to perform a server-side request forgery (SSRF) attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input.
network
low complexity
cisco CWE-918
6.5
2022-11-04 CVE-2022-20958 Server-Side Request Forgery (SSRF) vulnerability in Cisco Broadworks Commpilot Application
A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an unauthenticated, remote attacker to perform a server-side request forgery (SSRF) attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input.
network
low complexity
cisco CWE-918
8.8
2022-11-03 CVE-2022-39276 Server-Side Request Forgery (SSRF) vulnerability in Glpi-Project Glpi
GLPI stands for Gestionnaire Libre de Parc Informatique.
network
low complexity
glpi-project CWE-918
5.3
2022-11-02 CVE-2022-39241 Server-Side Request Forgery (SSRF) vulnerability in Discourse
Discourse is a platform for community discussion.
network
low complexity
discourse CWE-918
4.9
2022-11-01 CVE-2022-41552 Server-Side Request Forgery (SSRF) vulnerability in Hitachi products
Server-Side Request Forgery (SSRF) vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Data Center Analytics, Analytics probe components), Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer detail view, Hitachi Ops Center Analyzer probe components) allows Server Side Request Forgery. This issue affects Hitachi Infrastructure Analytics Advisor: from 2.0.0-00 through 4.4.0-00; Hitachi Ops Center Analyzer: from 10.0.0-00 before 10.9.0-00.
network
low complexity
hitachi CWE-918
critical
9.8