Show filters
469 Total Results
Displaying 21-30 of 469
Sort by:
Attacker Value
Unknown

CVE-2021-22054

Disclosure Date: December 17, 2021 (last updated February 23, 2025)
VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.
Attacker Value
Unknown

CVE-2021-34425

Disclosure Date: December 14, 2021 (last updated February 23, 2025)
The Zoom Client for Meetings before version 5.7.3 (for Android, iOS, Linux, macOS, and Windows) contain a server side request forgery vulnerability in the chat\'s "link preview" functionality. In versions prior to 5.7.3, if a user were to enable the chat\'s "link preview" feature, a malicious actor could trick the user into potentially sending arbitrary HTTP GET requests to URLs that the actor cannot reach directly.
Attacker Value
Unknown

CVE-2021-39935

Disclosure Date: December 13, 2021 (last updated February 23, 2025)
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API
Attacker Value
Unknown

CVE-2021-39057

Disclosure Date: December 10, 2021 (last updated February 23, 2025)
IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 214616.
Attacker Value
Unknown

CVE-2021-37940

Disclosure Date: December 07, 2021 (last updated February 23, 2025)
An information disclosure via GET request server-side request forgery vulnerability was discovered with the Workplace Search Github Enterprise Server integration. Using this vulnerability, a malicious Workplace Search admin could use the GHES integration to view hosts that might not be publicly accessible.
Attacker Value
Unknown

CVE-2021-4075

Disclosure Date: December 06, 2021 (last updated February 23, 2025)
snipe-it is vulnerable to Server-Side Request Forgery (SSRF)
Attacker Value
Unknown

CVE-2021-40091

Disclosure Date: December 06, 2021 (last updated February 23, 2025)
An SSRF issue was discovered in SquaredUp for SCOM 5.2.1.6654.
Attacker Value
Unknown

CVE-2021-23259

Disclosure Date: December 01, 2021 (last updated February 23, 2025)
Authenticated users with Administrator or Developer roles may execute OS commands by Groovy Script which uses Groovy lib to render a webpage. The groovy script does not have security restrictions, which will cause attackers to execute arbitrary commands remotely(RCE).
Attacker Value
Unknown

CVE-2021-23258

Disclosure Date: December 01, 2021 (last updated February 23, 2025)
Authenticated users with Administrator or Developer roles may execute OS commands by SPEL Expression in Spring beans. SPEL Expression does not have security restrictions, which will cause attackers to execute arbitrary commands remotely (RCE).
Attacker Value
Unknown

CVE-2021-23262

Disclosure Date: December 01, 2021 (last updated February 23, 2025)
Authenticated administrators may modify the main YAML configuration file and load a Java class resulting in RCE.