Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2024-06-04 CVE-2024-36675 Server-Side Request Forgery (SSRF) vulnerability in Lylme Spage 1.9.5
LyLme_spage v1.9.5 is vulnerable to Server-Side Request Forgery (SSRF) via the get_head function.
network
low complexity
lylme CWE-918
critical
9.1
2024-06-04 CVE-2024-4219 Server-Side Request Forgery (SSRF) vulnerability in Beyondtrust Beyondinsight 23.1
Prior to 23.2, it is possible to perform arbitrary Server-Side requests via HTTP-based connectors within BeyondInsight, resulting in a server-side request forgery vulnerability.
network
low complexity
beyondtrust CWE-918
critical
9.1
2024-05-14 CVE-2024-4561 Server-Side Request Forgery (SSRF) vulnerability in Progress Whatsup Gold
In WhatsUp Gold versions released before 2023.1.2 , a blind SSRF vulnerability exists in Whatsup Gold's FaviconController that allows an attacker to send arbitrary HTTP requests on behalf of the vulnerable server.
network
low complexity
progress CWE-918
5.3
2024-05-14 CVE-2024-4562 Server-Side Request Forgery (SSRF) vulnerability in Progress Whatsup Gold
In WhatsUp Gold versions released before 2023.1.2 , an SSRF vulnerability exists in Whatsup Gold's Issue exists in the HTTP Monitoring functionality.  Due to the lack of proper authorization, any authenticated user can access the HTTP monitoring functionality, what leads to the Server Side Request Forgery.
network
low complexity
progress CWE-918
5.4
2024-04-19 CVE-2024-29029 Server-Side Request Forgery (SSRF) vulnerability in Usememos Memos
memos is a privacy-first, lightweight note-taking service.
network
low complexity
usememos CWE-918
6.1
2024-03-18 CVE-2024-27098 Server-Side Request Forgery (SSRF) vulnerability in Glpi-Project Glpi
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.
network
low complexity
glpi-project CWE-918
critical
9.6
2024-02-14 CVE-2023-5122 Server-Side Request Forgery (SSRF) vulnerability in Grafana
Grafana is an open-source platform for monitoring and observability.
network
low complexity
grafana CWE-918
5.3
2024-02-14 CVE-2024-23788 Server-Side Request Forgery (SSRF) vulnerability in Sharp Jh-Rv11 Firmware and Jh-Rvb1 Firmware
Server-side request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to send an arbitrary HTTP request (GET) from the affected product.
low complexity
sharp CWE-918
8.1
2024-02-12 CVE-2024-23761 Server-Side Request Forgery (SSRF) vulnerability in Gambio 4.9.2.0
Server Side Template Injection in Gambio 4.9.2.0 allows attackers to run arbitrary code via crafted smarty email template.
network
low complexity
gambio CWE-918
critical
9.8
2024-02-12 CVE-2023-6294 Server-Side Request Forgery (SSRF) vulnerability in Sygnoos Popup Builder
The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could allow users with the administrator role to perform SSRF attack in Multisite WordPress configurations.
network
low complexity
sygnoos CWE-918
7.2