Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2022-10-17 CVE-2022-42149 Server-Side Request Forgery (SSRF) vulnerability in Keking Kkfileview 4.0.0
kkFileView 4.0 is vulnerable to Server-side request forgery (SSRF) via controller\OnlinePreviewController.java.
network
low complexity
keking CWE-918
critical
9.8
2022-10-14 CVE-2022-41477 Server-Side Request Forgery (SSRF) vulnerability in Webidsupport Webid
A security issue was discovered in WeBid <=1.2.2.
network
low complexity
webidsupport CWE-918
critical
9.1
2022-10-14 CVE-2022-36802 Server-Side Request Forgery (SSRF) vulnerability in Atlassian Jira Align
The ManageJiraConnectors API in Atlassian Jira Align before version 10.109.2 allows remote attackers to exploit this issue to access internal network resources via a Server-Side Request Forgery.
network
low complexity
atlassian CWE-918
4.9
2022-10-13 CVE-2022-41495 Server-Side Request Forgery (SSRF) vulnerability in Clippercms 1.3.3
ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the rss_url_news parameter at /manager/index.php.
network
low complexity
clippercms CWE-918
critical
9.8
2022-10-13 CVE-2022-41496 Server-Side Request Forgery (SSRF) vulnerability in Idreamsoft Icms 7.0.16
iCMS v7.0.16 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php.
network
low complexity
idreamsoft CWE-918
critical
9.8
2022-10-13 CVE-2022-41497 Server-Side Request Forgery (SSRF) vulnerability in Clippercms 1.3.3
ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the pkg_url parameter at /manager/index.php.
network
low complexity
clippercms CWE-918
critical
9.8
2022-10-03 CVE-2022-36551 Server-Side Request Forgery (SSRF) vulnerability in Heartex Label Studio
A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier allows an authenticated user to access arbitrary files on the system.
network
low complexity
heartex CWE-918
6.5
2022-09-28 CVE-2022-35282 Server-Side Request Forgery (SSRF) vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to server-side request forgery (SSRF).
low complexity
ibm CWE-918
6.5
2022-09-20 CVE-2022-40357 Server-Side Request Forgery (SSRF) vulnerability in Zblogcn Z-Blogphp
A security issue was discovered in Z-BlogPHP <= 1.7.2.
network
low complexity
zblogcn CWE-918
critical
9.8
2022-09-20 CVE-2022-38931 Server-Side Request Forgery (SSRF) vulnerability in Baijiacms Project Baijiacms 4.1.4
A Server-Side Request Forgery (SSRF) in fetch_net_file_upload function of baijiacmsV4 v4.1.4 allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the url parameter.
network
low complexity
baijiacms-project CWE-918
8.8