Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2023-06-13 CVE-2023-25609 Server-Side Request Forgery (SSRF) vulnerability in Fortinet Fortianalyzer and Fortimanager
A server-side request forgery (SSRF) vulnerability [CWE-918] in FortiManager and FortiAnalyzer GUI 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.8 through 6.4.11 may allow a remote and authenticated attacker to access unauthorized files and services on the system via specially crafted web requests.
network
low complexity
fortinet CWE-918
6.5
2023-06-08 CVE-2023-32750 Server-Side Request Forgery (SSRF) vulnerability in Pydio Cells
Pydio Cells through 4.1.2 allows SSRF.
network
low complexity
pydio CWE-918
6.5
2023-06-08 CVE-2023-34959 Server-Side Request Forgery (SSRF) vulnerability in Chamilo LMS
An issue in Chamilo v1.11.* up to v1.11.18 allows attackers to execute a Server-Side Request Forgery (SSRF) and obtain information on the services running on the server via crafted requests in the social and links tools.
network
low complexity
chamilo CWE-918
5.3
2023-06-06 CVE-2023-3121 Server-Side Request Forgery (SSRF) vulnerability in Dahuasecurity Smart Parking Management
A vulnerability has been found in Dahua Smart Parking Management up to 20230528 and classified as problematic.
low complexity
dahuasecurity CWE-918
4.6
2023-06-01 CVE-2023-28824 Server-Side Request Forgery (SSRF) vulnerability in Contec Conprosys HMI System
Server-side request forgery vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3.
network
low complexity
contec CWE-918
4.9
2023-06-01 CVE-2023-23955 Server-Side Request Forgery (SSRF) vulnerability in Broadcom Advanced Secure Gateway and Content Analysis
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Server-Side Request Forgery vulnerability.
network
low complexity
broadcom CWE-918
8.1
2023-05-27 CVE-2023-33184 Server-Side Request Forgery (SSRF) vulnerability in Nextcloud Mail
Nextcloud Mail is a mail app in Nextcloud.
network
low complexity
nextcloud CWE-918
5.3
2023-05-17 CVE-2023-31848 Server-Side Request Forgery (SSRF) vulnerability in Davinci Project Davinci 0.3.0
davinci 0.3.0-rc is vulnerable to Server-side request forgery (SSRF).
network
low complexity
davinci-project CWE-918
8.8
2023-05-12 CVE-2023-23169 Server-Side Request Forgery (SSRF) vulnerability in Synapsoft Pdfocus 1.17
Synapsoft pdfocus 1.17 is vulnerable to local file inclusion and server-side request forgery Directory Traversal.
network
low complexity
synapsoft CWE-918
6.5
2023-05-10 CVE-2022-29840 Server-Side Request Forgery (SSRF) vulnerability in Westerndigital MY Cloud OS
Server-Side Request Forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL to point back to the loopback adapter was addressed in Western Digital My Cloud OS 5 devices.
local
low complexity
westerndigital CWE-918
5.5