Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
server-side request forgery vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-27163
request-baskets up to v1.2.1 exists to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This vulnerability allows malicious users to access network resources and sensitive information via a crafted API request.
Rbaskets Request Baskets
21 Github repositories
NA
CVE-2022-31188
CVAT is an opensource interactive video and image annotation tool for computer vision. Versions before 2.0.0 were found to be subject to a Server-side request forgery (SSRF) vulnerability. Validation has been added to urls used in the affected code path in version 2.0.0. Users ar...
Cvat Cvat
1 EDB exploit
1 Github repository
685
VMScore
CVE-2017-9413
Multiple cross-site request forgery (CSRF) vulnerabilities in the Podcast feature in Subsonic 6.1.1 allow remote malicious users to hijack the authentication of users for requests that (1) subscribe to a podcast via the add parameter to podcastReceiverAdmin.view or (2) update Int...
Subsonic Subsonic 6.1.1
1 EDB exploit
405
VMScore
CVE-2018-1042
Moodle 3.x has Server Side Request Forgery in the filepicker.
Moodle Moodle 3.2.2
Moodle Moodle 3.2.4
Moodle Moodle 3.4.0
Moodle Moodle 3.2.6
Moodle Moodle 3.3.0
Moodle Moodle 3.3.1
Moodle Moodle 3.3.2
Moodle Moodle
Moodle Moodle 3.2.0
Moodle Moodle 3.2.1
Moodle Moodle 3.2.3
Moodle Moodle 3.2.5
Moodle Moodle 3.3.3
1 EDB exploit
1 Github repository
570
VMScore
CVE-2017-14611
SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote malicious users to read arbitrary files or send TCP traffic to intranet hosts via the url parameter, related to use of the discontinued aheinze/fetch_url_contents component.
Agentejo Cockpit 0.13.0
578
VMScore
CVE-2020-4294
IBM QRadar 7.3.0 to 7.3.3 Patch 2 is vulnerable to Server Side Request Forgery (SSRF). This may allow an authenticated malicious user to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-ForceID: 176404.
Ibm Qradar Security Information And Event Manager 7.3.3
Ibm Qradar Security Information And Event Manager
645
VMScore
CVE-2018-9302
SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 up to and including 0.5.5 allows remote malicious users to read arbitrary files or send TCP traffic to intranet hosts via the url parameter. NOTE: this vulnerability exists because of an incomplete fix ...
Getcockpit Cockpit
1 EDB exploit
405
VMScore
CVE-2019-7652
TheHive Project UnshortenLink analyzer prior to 1.1, included in Cortex-Analyzers prior to 1.15.2, has SSRF. To exploit the vulnerability, an attacker must create a new analysis, select URL for Data Type, and provide an SSRF payload like "http://127.0.0.1:22" in the Dat...
Thehive-project Cortex-analyzers
1 EDB exploit
668
VMScore
CVE-2020-24881
SSRF exists in osTicket prior to 1.14.3, where an attacker can add malicious file to server or perform port scanning.
Osticket Osticket
668
VMScore
CVE-2021-33318
An Input Validation Vulnerability exists in Joel Christner .NET C# packages WatsonWebserver, IpMatcher 1.0.4.1 and below (IpMatcher) and 4.1.3 and below (WatsonWebserver) due to insufficient validation of input IP addresses and netmasks against the internal Matcher list of IP add...
Watsonwebserver Project Watsonwebserver
Ipmatcher Project Ipmatcher
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4040
privilege escalation
CVE-2024-4112
CVE-2024-32872
man-in-the-middle
CVE-2024-32788
bypass
CVE-2024-3400
CVE-2024-28976
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »