Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2020-12-30 CVE-2020-35850 Server-Side Request Forgery (SSRF) vulnerability in Cockpit-Project Cockpit 234
An SSRF issue was discovered in cockpit-project.org Cockpit 234.
network
low complexity
cockpit-project CWE-918
6.5
2020-12-28 CVE-2020-26032 Server-Side Request Forgery (SSRF) vulnerability in Zammad
An SSRF issue was discovered in Zammad before 3.4.1.
network
low complexity
zammad CWE-918
7.5
2020-12-26 CVE-2020-35712 Server-Side Request Forgery (SSRF) vulnerability in Esri Arcgis Server
Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations.
network
low complexity
esri CWE-918
critical
9.8
2020-12-17 CVE-2020-8464 Server-Side Request Forgery (SSRF) vulnerability in Trendmicro Interscan web Security Virtual Appliance 6.5
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to send requests that appear to come from the localhost which could expose the product's admin interface to users who would not normally have access.
network
low complexity
trendmicro CWE-918
7.5
2020-12-16 CVE-2019-14476 Server-Side Request Forgery (SSRF) vulnerability in Adremsoft Netcrunch 10.6.0.4587
AdRem NetCrunch 10.6.0.4587 has a Server-Side Request Forgery (SSRF) vulnerability in the NetCrunch server.
network
low complexity
adremsoft CWE-918
6.5
2020-12-15 CVE-2020-10770 Server-Side Request Forgery (SSRF) vulnerability in Redhat Keycloak
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri.
network
low complexity
redhat CWE-918
5.3
2020-12-14 CVE-2020-17513 Server-Side Request Forgery (SSRF) vulnerability in Apache Airflow
In Apache Airflow versions prior to 1.10.13, the Charts and Query View of the old (Flask-admin based) UI were vulnerable for SSRF attack.
network
low complexity
apache CWE-918
5.3
2020-11-30 CVE-2020-28978 Server-Side Request Forgery (SSRF) vulnerability in Canto 1.3.0
The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability.
network
low complexity
canto CWE-918
5.3
2020-11-30 CVE-2020-28977 Server-Side Request Forgery (SSRF) vulnerability in Canto 1.3.0
The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability.
network
low complexity
canto CWE-918
5.3
2020-11-30 CVE-2020-28976 Server-Side Request Forgery (SSRF) vulnerability in Canto 1.3.0
The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability.
network
low complexity
canto CWE-918
5.3