Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2022-04-07 CVE-2020-27375 Server-Side Request Forgery (SSRF) vulnerability in Drtrustusa Icheck Connect BP Monitor BP Testing 118 Firmware 1.2.1
Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Transmitting Write Requests and Chars.
low complexity
drtrustusa CWE-918
6.5
2022-04-04 CVE-2022-1188 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 where a blind SSRF attack through the repository mirroring feature was possible.
network
low complexity
gitlab CWE-918
5.3
2022-04-01 CVE-2022-0425 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Server Side Request Forgery (SSRF) attacks.
network
low complexity
gitlab CWE-918
7.6
2022-03-30 CVE-2021-33581 Server-Side Request Forgery (SSRF) vulnerability in Softwareag Mashzone Nextgen 10.7
MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP services, by abusing the feature to check the availability of a PPM connection.
network
low complexity
softwareag CWE-918
7.2
2022-03-30 CVE-2022-27907 Server-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository Manager
Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF.
network
low complexity
sonatype CWE-918
4.3
2022-03-28 CVE-2022-0136 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1.
network
low complexity
gitlab CWE-918
8.1
2022-03-28 CVE-2022-0249 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
A vulnerability was discovered in GitLab starting with version 12.
network
low complexity
gitlab CWE-918
critical
9.1
2022-03-23 CVE-2021-44139 Server-Side Request Forgery (SSRF) vulnerability in Hashicorp Sentinel 1.8.2
Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF).
network
low complexity
hashicorp CWE-918
7.5
2022-03-18 CVE-2022-27245 Server-Side Request Forgery (SSRF) vulnerability in Misp
An issue was discovered in MISP before 2.4.156.
network
low complexity
misp CWE-918
8.8
2022-03-18 CVE-2021-45968 Server-Side Request Forgery (SSRF) vulnerability in multiple products
An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Phone System before 7.20.x (and in other products).
network
low complexity
jivesoftware pascom CWE-918
7.5