Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2021-02-19 CVE-2021-27214 Server-Side Request Forgery (SSRF) vulnerability in Zohocorp Manageengine Adselfservice Plus 6.0
A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP requests or perform a Cross-site scripting (XSS) attack against the administrative interface via an HTTP request, a different vulnerability than CVE-2019-3905.
network
low complexity
zohocorp CWE-918
6.1
2021-02-19 CVE-2021-3204 Server-Side Request Forgery (SSRF) vulnerability in Webware Webdesktop 5.1.15
SSRF in the document conversion component of Webware Webdesktop 5.1.15 allows an attacker to read all files from the server.
network
low complexity
webware CWE-918
6.5
2021-02-19 CVE-2020-10252 Server-Side Request Forgery (SSRF) vulnerability in Owncloud
An issue was discovered in ownCloud before 10.4.
network
low complexity
owncloud CWE-918
8.3
2021-02-18 CVE-2021-27329 Server-Side Request Forgery (SSRF) vulnerability in Frendi Frendica 2021.01
Friendica 2021.01 allows SSRF via parse_url?binurl= for DNS lookups or HTTP requests to arbitrary domain names.
network
low complexity
frendi CWE-918
critical
10.0
2021-02-18 CVE-2020-28463 Server-Side Request Forgery (SSRF) vulnerability in multiple products
All versions of package reportlab are vulnerable to Server-side Request Forgery (SSRF) via img tags.
network
low complexity
reportlab fedoraproject CWE-918
6.5
2021-02-16 CVE-2021-27103 Server-Side Request Forgery (SSRF) vulnerability in Accellion FTA
Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html.
network
low complexity
accellion CWE-918
critical
9.8
2021-02-16 CVE-2020-35561 Server-Side Request Forgery (SSRF) vulnerability in multiple products
An issue was discovered MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2.
network
low complexity
mbconnectline helmholz CWE-918
5.3
2021-02-16 CVE-2020-35558 Server-Side Request Forgery (SSRF) vulnerability in multiple products
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2.
network
low complexity
mbconnectline helmholz CWE-918
7.5
2021-02-04 CVE-2021-25241 Server-Side Request Forgery (SSRF) vulnerability in Trendmicro Apex ONE and Worry-Free Business Security
A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to locate online agents via a sweep.
network
low complexity
trendmicro CWE-918
5.3
2021-02-04 CVE-2021-25236 Server-Side Request Forgery (SSRF) vulnerability in Trendmicro Officescan and Worry-Free Business Security
A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro OfficeScan XG SP1 and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to locate online agents via a specific sweep.
network
low complexity
trendmicro CWE-918
5.3