Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2019-10-11 CVE-2017-18638 Server-Side Request Forgery (SSRF) vulnerability in Graphite Project Graphite
send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF.
network
low complexity
graphite-project CWE-918
7.5
2019-10-09 CVE-2019-15021 Server-Side Request Forgery (SSRF) vulnerability in Zingbox Inspector
A security vulnerability exists in the Zingbox Inspector versions 1.294 and earlier, that can allow an attacker to easily identify instances of Zingbox Inspectors in a local area network.
network
low complexity
zingbox CWE-918
5.3
2019-10-03 CVE-2019-15164 Server-Side Request Forgery (SSRF) vulnerability in Tcpdump Libpcap
rpcapd/daemon.c in libpcap before 1.9.1 allows SSRF because a URL may be provided as a capture source.
network
low complexity
tcpdump CWE-918
5.3
2019-10-02 CVE-2019-13335 Server-Side Request Forgery (SSRF) vulnerability in Salesagility Suitecrm
SalesAgility SuiteCRM 7.10.x 7.10.19 and 7.11.x before and 7.11.7 has SSRF.
network
low complexity
salesagility CWE-918
critical
9.8
2019-09-30 CVE-2019-16932 Server-Side Request Forgery (SSRF) vulnerability in Themeisle Visualizer
A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.
network
low complexity
themeisle CWE-918
critical
10.0
2019-09-26 CVE-2019-4262 Server-Side Request Forgery (SSRF) vulnerability in IBM Qradar Security Information and Event Manager
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to Server Side Request Forgery (SSRF).
network
low complexity
ibm CWE-918
5.3
2019-09-19 CVE-2019-15033 Server-Side Request Forgery (SSRF) vulnerability in Pydio 6.0.8
Pydio 6.0.8 allows Authenticated SSRF during a Remote Link Feature download.
network
low complexity
pydio CWE-918
7.7
2019-09-17 CVE-2019-6837 Server-Side Request Forgery (SSRF) vulnerability in Schneider-Electric products
A Server-Side Request Forgery (SSRF): CWE-918 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could cause server configuration data to be exposed when an attacker modifies a URL.
network
low complexity
schneider-electric CWE-918
critical
9.1
2019-09-16 CVE-2019-15731 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1.
network
low complexity
gitlab CWE-918
5.3
2019-09-16 CVE-2019-15730 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 8.14 through 12.2.1.
network
low complexity
gitlab CWE-918
7.5