Filtered by vendor
Subscriptions
Total
1324 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2018-8801 | 1 Gitlab | 1 Gitlab | 2024-11-21 | N/A |
GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component. | ||||
CVE-2018-7667 | 1 Adminer | 1 Adminer | 2024-11-21 | N/A |
Adminer through 4.3.1 has SSRF via the server parameter. | ||||
CVE-2018-7516 | 1 Geutebrueck | 4 G-cam\/efd-2250, G-cam\/efd-2250 Firmware, Topfd-2125 and 1 more | 2024-11-21 | N/A |
A server-side request forgery vulnerability has been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 IP cameras, which could lead to proxied network scans. | ||||
CVE-2018-7055 | 1 Steelcase | 2 Roomwizard, Roomwizard Firmware | 2024-11-21 | N/A |
GroupViewProxyServlet in RoomWizard before 4.4.x allows SSRF via the url parameter. | ||||
CVE-2018-6186 | 1 Citrix | 1 Netscaler | 2024-11-21 | N/A |
Citrix NetScaler VPX through NS12.0 53.13.nc allows an SSRF attack via the /rapi/read_url URI by an authenticated attacker who has a webapp account. The attacker can gain access to the nsroot account, and execute remote commands with root privileges. | ||||
CVE-2018-6029 | 1 5none | 1 Nonecms | 2024-11-21 | N/A |
The copy function in application/admin/controller/Article.php in NoneCms 1.3.0 allows remote attackers to access the content of internal and external network resources via Server Side Request Forgery (SSRF), because URL validation only considers whether the URL contains the "csdn" substring. | ||||
CVE-2018-5752 | 1 Open-xchange | 1 Open-xchange Appsuite | 2024-11-21 | N/A |
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors involving non-decimal representations of IP addresses and special IPv6 related addresses. | ||||
CVE-2018-5006 | 1 Adobe | 1 Experience Manager | 2024-11-21 | N/A |
Adobe Experience Manager versions 6.4 and earlier have a Server-Side Request Forgery vulnerability. Successful exploitation could lead to sensitive information disclosure. | ||||
CVE-2018-5004 | 1 Adobe | 1 Experience Manager | 2024-11-21 | N/A |
Adobe Experience Manager versions 6.2 and 6.3 have a Server-Side Request Forgery vulnerability. Successful exploitation could lead to sensitive information disclosure. | ||||
CVE-2018-3774 | 2 Redhat, Url-parse Project | 2 Quay, Url-parse | 2024-11-21 | 9.8 Critical |
Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol. | ||||
CVE-2018-2463 | 1 Sap | 1 Hybris | 2024-11-21 | N/A |
The Omni Commerce Connect API (OCC) of SAP Hybris Commerce, versions 6.*, is vulnerable to server-side request forgery (SSRF) attacks. This is due to a misconfiguration of XML parser that is used in the server-side implementation of OCC. | ||||
CVE-2018-2445 | 1 Sap | 1 Businessobjects Business Intelligence | 2024-11-21 | N/A |
AdminTools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the application, resulting in a Server-Side Request Forgery (SSRF) vulnerability. | ||||
CVE-2018-2370 | 1 Sap | 1 Bi Launchpad | 2024-11-21 | N/A |
Server Side Request Forgery (SSRF) vulnerability in SAP Central Management Console, BI Launchpad and Fiori BI Launchpad, 4.10, from 4.20, from 4.30, could allow a malicious user to use common techniques to determine which ports are in use on the backend server. | ||||
CVE-2018-25031 | 1 Smartbear | 1 Swagger Ui | 2024-11-21 | 4.3 Medium |
Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3. However, third parties have indicated this is not resolved in 4.1.3 and even occurs in that version and possibly others. | ||||
CVE-2018-20596 | 1 Jspxcms | 1 Jspxcms | 2024-11-21 | N/A |
Jspxcms v9.0.0 allows SSRF. | ||||
CVE-2018-20528 | 1 Jeecms | 1 Jeecms | 2024-11-21 | N/A |
JEECMS 9 has SSRF via the ueditor/getRemoteImage.jspx upfile parameter. | ||||
CVE-2018-20499 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 7.2 High |
An issue was discovered in GitLab Community and Enterprise Edition before 11.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF. | ||||
CVE-2018-20497 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 5.0 Medium |
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF. | ||||
CVE-2018-20436 | 1 Telegram | 2 Telegram, Web | 2024-11-21 | N/A |
The "secret chat" feature in Telegram 4.9.1 for Android has a "side channel" in which Telegram servers send GET requests for URLs typed while composing a chat message, before that chat message is sent. There are also GET requests to other URLs on the same web server. This also affects one or more other Telegram products, such as Telegram Web-version 0.7.0. In addition, it can be interpreted as an SSRF issue. NOTE: a third party has reported that potentially unwanted behavior is caused by misconfiguration of the "Secret chats > Preview links" setting | ||||
CVE-2018-20228 | 1 Subsonic | 1 Subsonic | 2024-11-21 | N/A |
Subsonic V6.1.5 allows internetRadioSettings.view streamUrl CSRF, with resultant SSRF. |