Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2019-05-23 CVE-2017-13667 Server-Side Request Forgery (SSRF) vulnerability in Open-Xchange Appsuite
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF.
network
low complexity
open-xchange CWE-918
critical
9.9
2019-05-23 CVE-2017-15029 Server-Side Request Forgery (SSRF) vulnerability in Open-Xchange Appsuite
Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF.
network
low complexity
open-xchange CWE-918
4.3
2019-05-17 CVE-2019-12161 Server-Side Request Forgery (SSRF) vulnerability in Webpagetest 19.04
WPO WebPageTest 19.04 allows SSRF because ValidateURL in www/runtest.php does not consider octal encoding of IP addresses (such as 0300.0250 as a replacement for 192.168).
network
low complexity
webpagetest CWE-918
8.8
2019-05-14 CVE-2019-6516 Server-Side Request Forgery (SSRF) vulnerability in Wso2 Dashboard Server 2.0.0
An issue was discovered in WSO2 Dashboard Server 2.0.0.
network
low complexity
wso2 CWE-918
5.8
2019-05-14 CVE-2019-6512 Server-Side Request Forgery (SSRF) vulnerability in Wso2 API Manager 2.6.0
An issue was discovered in WSO2 API Manager 2.6.0.
network
low complexity
wso2 CWE-918
4.1
2019-05-10 CVE-2019-11066 Server-Side Request Forgery (SSRF) vulnerability in Lightopenid Project Lightopenid 1.3.0/1.3.1
openid.php in LightOpenID through 1.3.1 allows SSRF via a crafted OpenID 2.0 assertion request using the HTTP GET method.
network
low complexity
lightopenid-project CWE-918
critical
9.8
2019-05-09 CVE-2019-7652 Server-Side Request Forgery (SSRF) vulnerability in Thehive-Project Cortex-Analyzers
TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF.
network
low complexity
thehive-project CWE-918
7.7
2019-05-05 CVE-2019-11767 Server-Side Request Forgery (SSRF) vulnerability in PHPbb
Server side request forgery (SSRF) in phpBB before 3.2.6 allows checking for the existence of files and services on the local network of the host through the remote avatar upload function.
network
low complexity
phpbb CWE-918
5.8
2019-05-01 CVE-2019-0227 Server-Side Request Forgery (SSRF) vulnerability in multiple products
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006.
high complexity
apache oracle CWE-918
7.5
2019-04-30 CVE-2019-9621 Server-Side Request Forgery (SSRF) vulnerability in Zimbra Collaboration Server
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.
network
low complexity
zimbra CWE-918
7.5