Total
1502 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-43562 | 1 Pixxio | 1 Pixx.io | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The extension fails to restrict the image download to the configured pixx.io DAM URL, resulting in SSRF. As a result, an attacker can download various content from a remote location and save it to a user-controlled filename, which may result in Remote Code Execution. A TYPO3 backend user account is required to exploit this. | |||||
CVE-2021-43296 | 1 Zohocorp | 1 Manageengine Supportcenter Plus | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to an SSRF attack in ActionExecutor. | |||||
CVE-2021-43293 | 1 Sonatype | 1 Nexus Repository Manager | 2024-11-21 | 4.0 MEDIUM | 4.3 MEDIUM |
Sonatype Nexus Repository Manager 3.x before 3.36.0 allows a remote authenticated attacker to potentially perform network enumeration via Server Side Request Forgery (SSRF). | |||||
CVE-2021-42637 | 1 Printerlogic | 1 Web Stack | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server Side Request Forgery (SSRF) vulnerability. | |||||
CVE-2021-42091 | 1 Zammad | 1 Zammad | 2024-11-21 | 6.4 MEDIUM | 9.1 CRITICAL |
An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration. | |||||
CVE-2021-42079 | 1 Osnexus | 1 Quantastor | 2024-11-21 | N/A | 6.2 MEDIUM |
An authenticated administrator is able to prepare an alert that is able to execute an SSRF attack. This is exclusively with POST requests. | |||||
CVE-2021-41809 | 1 M-files | 1 M-files Server | 2024-11-21 | 4.0 MEDIUM | 3.5 LOW |
SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, in a preview function allowed making queries from the server with certain document types referencing external entities. | |||||
CVE-2021-41792 | 1 Alfresco | 2 Alfresco Content Services, Alfresco Transform Services | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
An issue was discovered in Hyland org.alfresco:alfresco-content-services through 6.2.2.18 and org.alfresco:alfresco-transform-services through 1.3. A crafted HTML file, once uploaded, could trigger an unexpected request by the transformation engine. The response to the request is not available to the attacker, i.e., this is blind SSRF. | |||||
CVE-2021-41587 | 1 Gradle | 1 Gradle | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially discover credentials for other resources. | |||||
CVE-2021-41586 | 1 Gradle | 1 Gradle | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially reset the system user password. | |||||
CVE-2021-41403 | 1 Flatcore | 1 Flatcore-cms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities. | |||||
CVE-2021-41385 | 1 Securonix | 1 Snypr | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
The third party intelligence connector in Securonix SNYPR 6.3.1 Build 184295_0302 allows an authenticated user to obtain access to server configuration details via SSRF. | |||||
CVE-2021-40822 | 1 Osgeo | 1 Geoserver | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host. | |||||
CVE-2021-40809 | 1 Jamf | 1 Jamf | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
An issue was discovered in Jamf Pro before 10.32.0, aka PI-009921. An account can be granted incorrect privileges in response to authentication that uses specific sign-on workflows. | |||||
CVE-2021-40604 | 1 Invisioncommunity | 1 Ips Community Suite | 2024-11-21 | 6.4 MEDIUM | 9.1 CRITICAL |
A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users to request arbitrary URLs or trigger deserialization via phar protocol when generating class names dynamically. In some cases an exploitation is possible by an unauthenticated user. | |||||
CVE-2021-40537 | 1 Owncloud | 1 User Ldap | 2024-11-21 | 4.0 MEDIUM | 2.7 LOW |
Server Side Request Forgery (SSRF) vulnerability exists in owncloud/user_ldap < 0.15.4 in the settings of the user_ldap app. Administration role is necessary for exploitation. | |||||
CVE-2021-40186 | 1 Dnnsoftware | 1 Dotnetnuke | 2024-11-21 | 5.0 MEDIUM | 6.5 MEDIUM |
The AppCheck research team identified a Server-Side Request Forgery (SSRF) vulnerability within the DNN CMS platform, formerly known as DotNetNuke. SSRF vulnerabilities allow the attacker to exploit the target system to make network requests on their behalf, allowing a range of possible attacks. In the most common scenario, the attacker exploits SSRF vulnerabilities to attack systems behind the firewall and access sensitive information from Cloud Provider metadata services. | |||||
CVE-2021-40109 | 1 Concretecms | 1 Concrete Cms | 2024-11-21 | 5.5 MEDIUM | 6.4 MEDIUM |
A SSRF issue was discovered in Concrete CMS through 8.5.5. Users can access forbidden files on their local network. A user with permissions to upload files from external sites can upload a URL that redirects to an internal resource of any file type. The redirect is followed and loads the contents of the file from the redirected-to server. Files of disallowed types can be uploaded. | |||||
CVE-2021-40091 | 1 Squaredup | 1 Squaredup | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
An SSRF issue was discovered in SquaredUp for SCOM 5.2.1.6654. | |||||
CVE-2021-3959 | 1 Bitdefender | 1 Gravityzone | 2024-11-21 | 5.0 MEDIUM | 6.8 MEDIUM |
A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security Tools allows an attacker to proxy requests to the relay server. This issue affects: Bitdefender Bitdefender GravityZone versions prior to 3.3.8.272 |