Vulnerabilities > Server-Side Request Forgery (SSRF)
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-11-06 | CVE-2020-28168 | Server-Side Request Forgery (SSRF) vulnerability in multiple products Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address. | 5.9 |
2020-11-02 | CVE-2020-28043 | Server-Side Request Forgery (SSRF) vulnerability in Misp MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL. | 5.0 |
2020-11-02 | CVE-2020-24881 | Server-Side Request Forgery (SSRF) vulnerability in Osticket SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning. | 7.5 |
2020-10-28 | CVE-2020-24710 | Server-Side Request Forgery (SSRF) vulnerability in Getgophish Gophish Gophish before 0.11.0 allows SSRF attacks. | 5.0 |
2020-10-26 | CVE-2020-7126 | Server-Side Request Forgery (SSRF) vulnerability in Arubanetworks Airwave Glass 1.2.1/1.3.0/1.3.1 A remote server-side request forgery (ssrf) vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. | 5.0 |
2020-10-23 | CVE-2020-25466 | Server-Side Request Forgery (SSRF) vulnerability in Crmeb 3.0 A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code. | 7.5 |
2020-10-23 | CVE-2020-15002 | Server-Side Request Forgery (SSRF) vulnerability in Open-Xchange Appsuite OX App Suite through 7.10.3 allows SSRF via the the /ajax/messaging/message message API. | 4.0 |
2020-10-21 | CVE-2020-25820 | Server-Side Request Forgery (SSRF) vulnerability in Bigbluebutton BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document that has a crafted URL in an ODF xlink field. | 4.0 |
2020-10-20 | CVE-2020-6308 | Server-Side Request Forgery (SSRF) vulnerability in SAP Businessobjects Business Intelligence Platform 4.1/4.2/4.3 SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible externally. | 5.0 |
2020-10-20 | CVE-2020-7749 | Server-Side Request Forgery (SSRF) vulnerability in Osm-Static-Maps Project Osm-Static-Maps This affects all versions of package osm-static-maps. | 6.5 |