Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2020-02-04 CVE-2020-3938 Server-Side Request Forgery (SSRF) vulnerability in Sysjust Syuan-Gu-Da-Shin
SysJust Syuan-Gu-Da-Shih, versions before 20191223, contain vulnerability of Request Forgery, allowing attackers to launch inquiries into network architecture or system files of the server via forged inquests.
network
low complexity
sysjust CWE-918
7.5
2020-01-28 CVE-2013-4864 Server-Side Request Forgery (SSRF) vulnerability in Micasaverde Veralite Firmware 1.5.408
MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url parameter to cgi-bin/cmh/proxy.sh, related to a Server-Side Request Forgery (SSRF) issue.
network
low complexity
micasaverde CWE-918
critical
9.8
2020-01-28 CVE-2019-5464 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF where the library is utilized.
network
low complexity
gitlab CWE-918
critical
9.8
2020-01-23 CVE-2007-6758 Server-Side Request Forgery (SSRF) vulnerability in Sencha EXT JS 5.0.0
Server-side request forgery (SSRF) vulnerability in feed-proxy.php in extjs 5.0.0.
network
low complexity
sencha CWE-918
7.5
2020-01-23 CVE-2019-19835 Server-Side Request Forgery (SSRF) vulnerability in Ruckuswireless Unleashed and Zonedirector 1200 Firmware
SSRF in AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote denial of service via the server attribute to the tools/_rcmdstat.jsp URI.
network
low complexity
ruckuswireless CWE-918
7.5
2020-01-09 CVE-2020-1925 Server-Side Request Forgery (SSRF) vulnerability in Apache Olingo
Apache Olingo versions 4.0.0 to 4.7.0 provide the AsyncRequestWrapperImpl class which reads a URL from the Location header, and then sends a GET or DELETE request to this URL.
network
low complexity
apache CWE-918
7.5
2020-01-03 CVE-2019-19261 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
GitLab Enterprise Edition (EE) 6.7 and later through 12.5 allows SSRF.
network
low complexity
gitlab CWE-918
8.8
2019-12-30 CVE-2018-20499 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition before 11.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1.
network
low complexity
gitlab CWE-918
7.2
2019-12-30 CVE-2018-20497 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1.
network
low complexity
gitlab CWE-918
5.0
2019-12-29 CVE-2019-20055 Server-Side Request Forgery (SSRF) vulnerability in Liquidpixels Liquifire OS 4.8.0
LuquidPixels LiquiFire OS 4.8.0 allows SSRF via the call%3Durl substring followed by a URL in square brackets.
network
low complexity
liquidpixels CWE-918
6.5