Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2019-09-30 CVE-2019-16932 Server-Side Request Forgery (SSRF) vulnerability in Themeisle Visualizer
A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.
network
low complexity
themeisle CWE-918
critical
10.0
2019-09-26 CVE-2019-4262 Server-Side Request Forgery (SSRF) vulnerability in IBM Qradar Security Information and Event Manager
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to Server Side Request Forgery (SSRF).
network
low complexity
ibm CWE-918
5.3
2019-09-19 CVE-2019-15033 Server-Side Request Forgery (SSRF) vulnerability in Pydio 6.0.8
Pydio 6.0.8 allows Authenticated SSRF during a Remote Link Feature download.
network
low complexity
pydio CWE-918
7.7
2019-09-17 CVE-2019-6837 Server-Side Request Forgery (SSRF) vulnerability in Schneider-Electric products
A Server-Side Request Forgery (SSRF): CWE-918 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could cause server configuration data to be exposed when an attacker modifies a URL.
network
low complexity
schneider-electric CWE-918
critical
9.1
2019-09-16 CVE-2019-15731 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1.
network
low complexity
gitlab CWE-918
5.3
2019-09-16 CVE-2019-15730 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 8.14 through 12.2.1.
network
low complexity
gitlab CWE-918
7.5
2019-09-16 CVE-2019-15728 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 10.1 through 12.2.1.
network
low complexity
gitlab CWE-918
7.5
2019-09-11 CVE-2019-8451 Server-Side Request Forgery (SSRF) vulnerability in Atlassian Jira Server
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.
network
low complexity
atlassian CWE-918
6.5
2019-09-10 CVE-2019-12996 Server-Side Request Forgery (SSRF) vulnerability in Mendix
In Mendix 7.23.5 and earlier, issue in XML import mappings allow DOCTYPE declarations in the XML input that is potentially unsafe.
network
low complexity
mendix CWE-918
5.3
2019-09-09 CVE-2019-6793 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
An issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1.
network
high complexity
gitlab CWE-918
7.0