Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ssrf vulnerabilities and exploits
(subscribe to this query)
10
CVSSv3
CVE-2023-38490
Kirby is a content management system. A vulnerability in versions before 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 only affects Kirby sites that use the `Xml` data handler (e.g. `Data::decode($string, 'xml')`) or the `Xml::parse()` method in site or plugin code. The...
Getkirby Kirby
10
CVSSv3
CVE-2023-3432
Server-Side Request Forgery (SSRF) in GitHub repository plantuml/plantuml before 1.2023.9.
Plantuml Plantuml
Fedoraproject Fedora 39
10
CVSSv3
CVE-2021-27329
Friendica 2021.01 allows SSRF via parse_url?binurl= for DNS lookups or HTTP requests to arbitrary domain names.
Frendi Frendica 2021.01
10
CVSSv3
CVE-2019-16932
A blind SSRF vulnerability exists in the Visualizer plugin prior to 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.
Themeisle Visualizer
10
CVSSv3
CVE-2019-13020
The fetch API in Tightrope Media Carousel prior to 7.1.3 has CarouselAPI/v0/fetch?url= SSRF. This has two potential areas for abuse. First, a specially crafted URL could be used in a phishing attack to hijack the trust the user and the browser have with the website and could serv...
Trms Tightrope Media Carousel
10
CVSSv3
CVE-2016-10926
The nelio-ab-testing plugin prior to 4.5.9 for WordPress has SSRF in ajax/iesupport.php.
Neliosoftware Nelio Ab Testing
10
CVSSv3
CVE-2016-10927
The nelio-ab-testing plugin prior to 4.5.11 for WordPress has SSRF in ajax/iesupport.php.
Neliosoftware Nelio Ab Testing
10
CVSSv3
CVE-2019-12153
Lack of validation in the HTML parser in RealObjects PDFreactor prior to 10.1.10722 leads to SSRF, allowing malicious users to access network or file resources on behalf of the server by supplying malicious HTML content.
Realobjects Pdfreactor
10
CVSSv3
CVE-2019-9174
An issue exists in GitLab Community and Enterprise Edition prior to 11.6.10, 11.7.x prior to 11.7.6, and 11.8.x prior to 11.8.1. It allows SSRF.
Gitlab Gitlab
10
CVSSv3
CVE-2019-10686
An SSRF vulnerability was found in an API from Ctrip Apollo up to and including 1.4.0-SNAPSHOT. An attacker may use it to do an intranet port scan or raise a GET request via /system-info/health because the %23 substring is mishandled.
Ctrip Apollo
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5834
CVE-2024-30100
CVE-2024-4577
physical
dos
CVE-2024-30099
CVE-2024-27801
CVE-2024-32146
logic flaw
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »