Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2020-10-19 CVE-2020-15822 Server-Side Request Forgery (SSRF) vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2020.2.10514, SSRF is possible because URL filtering can be escaped.
network
low complexity
jetbrains CWE-918
7.5
2020-10-17 CVE-2020-27197 Server-Side Request Forgery (SSRF) vulnerability in multiple products
TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser.
network
low complexity
libtaxii-project eclecticiq CWE-918
critical
9.8
2020-10-10 CVE-2020-26948 Server-Side Request Forgery (SSRF) vulnerability in Emby
Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.
network
low complexity
emby CWE-918
critical
9.8
2020-10-06 CVE-2020-7739 Server-Side Request Forgery (SSRF) vulnerability in Phantomjs-Seo Project Phantomjs-Seo 1.0.0
This affects all versions of package phantomjs-seo.
network
low complexity
phantomjs-seo-project CWE-918
6.4
2020-10-01 CVE-2020-5784 Server-Side Request Forgery (SSRF) vulnerability in Teltonika-Networks Trb245 Firmware 00.02.04.03
Server-Side Request Forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a low privileged user to cause the application to perform HTTP GET requests to arbitrary URLs.
network
low complexity
teltonika-networks CWE-918
4.0
2020-09-22 CVE-2020-14023 Server-Side Request Forgery (SSRF) vulnerability in Ozeki NG SMS Gateway
Ozeki NG SMS Gateway through 4.17.6 allows SSRF via SMS WCF or RSS To SMS.
network
low complexity
ozeki CWE-918
4.0
2020-09-21 CVE-2020-16171 Server-Side Request Forgery (SSRF) vulnerability in Acronis Cyber Backup 12.5
An issue was discovered in Acronis Cyber Backup before 12.5 Build 16342.
network
low complexity
acronis CWE-918
6.4
2020-09-18 CVE-2020-15772 Server-Side Request Forgery (SSRF) vulnerability in Gradle Enterprise
An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4.
network
low complexity
gradle CWE-918
4.9
2020-09-14 CVE-2020-13309 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4.
network
low complexity
gitlab CWE-918
6.5
2020-09-04 CVE-2020-4632 Server-Side Request Forgery (SSRF) vulnerability in IBM Infosphere Metadata Asset Manager 11.7
IBM InfoSphere Metadata Asset Manager 11.7 is vulnerable to server-side request forgery.
network
low complexity
ibm CWE-918
4.0