Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2021-07-19 CVE-2021-31216 Server-Side Request Forgery (SSRF) vulnerability in Siren Investigate
Siren Investigate before 11.1.1 contains a server side request forgery (SSRF) defect in the built-in image proxy route (which is enabled by default).
network
low complexity
siren CWE-918
5.5
2021-07-15 CVE-2021-29749 Server-Side Request Forgery (SSRF) vulnerability in IBM products
IBM Secure External Authentication Server 6.0.2 and IBM Secure Proxy 6.0.2 is vulnerable to server-side request forgery (SSRF).
network
low complexity
ibm CWE-918
5.4
2021-07-14 CVE-2021-34473 Server-Side Request Forgery (SSRF) vulnerability in Microsoft Exchange Server 2013/2016/2019
Microsoft Exchange Server Remote Code Execution Vulnerability
network
low complexity
microsoft CWE-918
critical
9.1
2021-07-14 CVE-2021-33213 Server-Side Request Forgery (SSRF) vulnerability in Element-It Http Commander 5.3.3
An SSRF vulnerability in the "Upload from URL" feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated users to retrieve HTTP and FTP files from the internal server network by inserting an internal address.
network
low complexity
element-it CWE-918
4.0
2021-07-12 CVE-2020-23079 Server-Side Request Forgery (SSRF) vulnerability in Halo
SSRF vulnerability in Halo <=1.3.2 exists in the SMTP configuration, which can detect the server intranet.
network
low complexity
halo CWE-918
5.0
2021-07-11 CVE-2021-29102 Server-Side Request Forgery (SSRF) vulnerability in Esri Arcgis Server 10.6.1/10.7.1/10.8.1
A Server-Side Request Forgery (SSRF) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote, unauthenticated attacker to forge GET requests to arbitrary URLs from the system, potentially leading to network enumeration or facilitating other attacks.
network
low complexity
esri CWE-918
critical
9.1
2021-07-08 CVE-2020-20582 Server-Side Request Forgery (SSRF) vulnerability in Mipcms 5.0.1
A server side request forgery (SSRF) vulnerability in /ApiAdminDomainSettings.php of MipCMS 5.0.1 allows attackers to access sensitive information.
network
low complexity
mipcms CWE-918
5.0
2021-07-07 CVE-2020-24141 Server-Side Request Forgery (SSRF) vulnerability in Wp-Downloadmanager Project Wp-Downloadmanager 1.68.4
Server-side request forgery in the WP-DownloadManager plugin 1.68.4 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the file_remote parameter to download-add.php.
network
low complexity
wp-downloadmanager-project CWE-918
5.0
2021-07-07 CVE-2020-24142 Server-Side Request Forgery (SSRF) vulnerability in Ninjateam Video Downloader for Tiktok 1.3
Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the njt-tk-download-video parameter.
network
low complexity
ninjateam CWE-918
7.5
2021-07-07 CVE-2020-24147 Server-Side Request Forgery (SSRF) vulnerability in Xylusthemes WP Smart Import 1.0.0
Server-side request forgery (SSR) vulnerability in the WP Smart Import (wp-smart-import) plugin 1.0.0 for WordPress via the file field.
network
low complexity
xylusthemes CWE-918
critical
9.1