Show filters
514 Total Results
Displaying 31-40 of 514
Sort by:
Attacker Value
Unknown
CVE-2021-43954
Disclosure Date: March 07, 2022 (last updated February 23, 2025)
The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add repository permission', to enumerate the existence of internal network and filesystem resources via a Server-Side Request Forgery (SSRF) vulnerability.
0
Attacker Value
Unknown
CVE-2022-0528
Disclosure Date: March 03, 2022 (last updated February 23, 2025)
Server-Side Request Forgery (SSRF) in GitHub repository transloadit/uppy prior to 3.3.1.
0
Attacker Value
Unknown
CVE-2022-0768
Disclosure Date: February 28, 2022 (last updated February 23, 2025)
Server-Side Request Forgery (SSRF) in GitHub repository rudloff/alltube prior to 3.0.2.
0
Attacker Value
Unknown
CVE-2022-25260
Disclosure Date: February 25, 2022 (last updated February 23, 2025)
JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF).
0
Attacker Value
Unknown
CVE-2022-24333
Disclosure Date: February 25, 2022 (last updated February 23, 2025)
In JetBrains TeamCity before 2021.2, blind SSRF via an XML-RPC call was possible.
0
Attacker Value
Unknown
CVE-2022-25355
Disclosure Date: February 24, 2022 (last updated February 23, 2025)
EC-CUBE 3.0.0 to 3.0.18-p3 and EC-CUBE 4.0.0 to 4.1.1 improperly handle HTTP Host header values, which may lead a remote unauthenticated attacker to direct the vulnerable version of EC-CUBE to send an Email with some forged reissue-password URL to EC-CUBE users.
0
Attacker Value
Unknown
CVE-2021-24867
Disclosure Date: February 21, 2022 (last updated February 23, 2025)
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
0
Attacker Value
Unknown
CVE-2022-24980
Disclosure Date: February 19, 2022 (last updated February 23, 2025)
An issue was discovered in the Kitodo.Presentation (aka dif) extension before 2.3.2, 3.x before 3.2.3, and 3.3.x before 3.3.4 for TYPO3. A missing access check in an eID script allows an unauthenticated user to submit arbitrary URLs to this component. This results in SSRF, allowing attackers to view the content of any file or webpage the webserver has access to.
0
Attacker Value
Unknown
CVE-2022-0671
Disclosure Date: February 18, 2022 (last updated February 23, 2025)
A flaw was found in vscode-xml in versions prior to 0.19.0. Schema download could lead to blind SSRF or DoS via a large file.
0
Attacker Value
Unknown
CVE-2021-20325
Disclosure Date: February 18, 2022 (last updated February 23, 2025)
Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regression compared to the versions shipped in Red Hat Enterprise Linux 8.4. A user who installs or updates to Red Hat Enterprise Linux 8.5.0 would be vulnerable to the mentioned CVEs, even if they were properly fixed in Red Hat Enterprise Linux 8.4. CVE-2021-20325 was assigned to that Red Hat specific security regression and it does not affect the upstream versions of httpd.
0