Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2022-06-24 CVE-2021-20544 Server-Side Request Forgery (SSRF) vulnerability in IBM Jazz Team Server
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF).
network
low complexity
ibm CWE-918
4.3
2022-06-23 CVE-2022-34011 Server-Side Request Forgery (SSRF) vulnerability in Zhyd Oneblog 2.3.4
OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the parameter entryUrls.
network
low complexity
zhyd CWE-918
4.3
2022-06-23 CVE-2022-34013 Server-Side Request Forgery (SSRF) vulnerability in Zhyd Oneblog 2.3.4
OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Logo parameter under the Link module.
network
low complexity
zhyd CWE-918
4.3
2022-06-21 CVE-2021-36761 Server-Side Request Forgery (SSRF) vulnerability in Qlik Sense April2020
The GeoAnalytics feature in Qlik Sense April 2020 patch 4 allows SSRF.
network
low complexity
qlik CWE-918
5.3
2022-06-15 CVE-2021-41403 Server-Side Request Forgery (SSRF) vulnerability in Flatcore Flatcore-Cms 2.0.8
flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities.
network
low complexity
flatcore CWE-918
critical
9.8
2022-06-13 CVE-2021-40604 Server-Side Request Forgery (SSRF) vulnerability in Invisioncommunity IPS Community Suite
A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users to request arbitrary URLs or trigger deserialization via phar protocol when generating class names dynamically.
network
low complexity
invisioncommunity CWE-918
critical
9.1
2022-06-09 CVE-2022-24969 Server-Side Request Forgery (SSRF) vulnerability in Apache Dubbo
bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check which can cause open redirect or SSRF vulnerability.
network
low complexity
apache CWE-918
6.1
2022-06-09 CVE-2022-31386 Server-Side Request Forgery (SSRF) vulnerability in Nbnbk Project Nbnbk 3
A Server-Side Request Forgery (SSRF) in the getFileBinary function of nbnbk cms 3 allows attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the URL parameter.
network
low complexity
nbnbk-project CWE-918
critical
9.1
2022-06-09 CVE-2022-31390 Server-Side Request Forgery (SSRF) vulnerability in Jizhicms 2.2.5
Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Update function in app/admin/c/TemplateController.php.
network
low complexity
jizhicms CWE-918
critical
9.1
2022-06-09 CVE-2022-31393 Server-Side Request Forgery (SSRF) vulnerability in Jizhicms 2.2.5
Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Index function in app/admin/c/PluginsController.php.
network
low complexity
jizhicms CWE-918
critical
9.1