Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2020-11-06 CVE-2020-28168 Server-Side Request Forgery (SSRF) vulnerability in multiple products
Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.
network
high complexity
axios siemens CWE-918
5.9
2020-11-02 CVE-2020-28043 Server-Side Request Forgery (SSRF) vulnerability in Misp
MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL.
network
low complexity
misp CWE-918
5.0
2020-11-02 CVE-2020-24881 Server-Side Request Forgery (SSRF) vulnerability in Osticket
SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.
network
low complexity
osticket CWE-918
7.5
2020-10-28 CVE-2020-24710 Server-Side Request Forgery (SSRF) vulnerability in Getgophish Gophish
Gophish before 0.11.0 allows SSRF attacks.
network
low complexity
getgophish CWE-918
5.0
2020-10-26 CVE-2020-7126 Server-Side Request Forgery (SSRF) vulnerability in Arubanetworks Airwave Glass 1.2.1/1.3.0/1.3.1
A remote server-side request forgery (ssrf) vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
network
low complexity
arubanetworks CWE-918
5.0
2020-10-23 CVE-2020-25466 Server-Side Request Forgery (SSRF) vulnerability in Crmeb 3.0
A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.
network
low complexity
crmeb CWE-918
7.5
2020-10-23 CVE-2020-15002 Server-Side Request Forgery (SSRF) vulnerability in Open-Xchange Appsuite
OX App Suite through 7.10.3 allows SSRF via the the /ajax/messaging/message message API.
network
low complexity
open-xchange CWE-918
4.0
2020-10-21 CVE-2020-25820 Server-Side Request Forgery (SSRF) vulnerability in Bigbluebutton
BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document that has a crafted URL in an ODF xlink field.
network
low complexity
bigbluebutton CWE-918
4.0
2020-10-20 CVE-2020-6308 Server-Side Request Forgery (SSRF) vulnerability in SAP Businessobjects Business Intelligence Platform 4.1/4.2/4.3
SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible externally.
network
low complexity
sap CWE-918
5.0
2020-10-20 CVE-2020-7749 Server-Side Request Forgery (SSRF) vulnerability in Osm-Static-Maps Project Osm-Static-Maps
This affects all versions of package osm-static-maps.
network
low complexity
osm-static-maps-project CWE-918
6.5