Show filters
745 Total Results
Displaying 71-80 of 745
Sort by:
Attacker Value
Unknown

CVE-2022-27622

Disclosure Date: October 24, 2022 (last updated February 24, 2025)
Server-Side Request Forgery (SSRF) vulnerability in Package Center functionality in Synology DiskStation Manager (DSM) before 7.1-42661 allows remote authenticated users to access intranet resources via unspecified vectors.
Attacker Value
Unknown

CVE-2022-41609

Disclosure Date: October 21, 2022 (last updated February 24, 2025)
Auth. (subscriber+) Server-Side Request Forgery (SSRF) vulnerability in Better Messages plugin 1.9.10.68 on WordPress.
Attacker Value
Unknown

CVE-2022-3203

Disclosure Date: October 21, 2022 (last updated February 24, 2025)
On ORing net IAP-420(+) with FW version 2.0m a telnet server is enabled by default and cannot permanently be disabled. You can connect to the device via LAN or WiFi with hardcoded credentials and get an administrative shell. These credentials are reset to defaults with every reboot.
Attacker Value
Unknown

CVE-2022-39055

Disclosure Date: October 18, 2022 (last updated February 24, 2025)
RAVA certificate validation system has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform SSRF attack to discover internal network topology base on query response.
Attacker Value
Unknown

CVE-2022-42149

Disclosure Date: October 17, 2022 (last updated February 24, 2025)
kkFileView 4.0 is vulnerable to Server-side request forgery (SSRF) via controller\OnlinePreviewController.java.
Attacker Value
Unknown

CVE-2022-41477

Disclosure Date: October 14, 2022 (last updated February 24, 2025)
A security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.php file allows remote attackers to inject payloads via theme parameters to read files across directories.
Attacker Value
Unknown

CVE-2022-41497

Disclosure Date: October 13, 2022 (last updated February 24, 2025)
ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the pkg_url parameter at /manager/index.php.
Attacker Value
Unknown

CVE-2022-41496

Disclosure Date: October 13, 2022 (last updated February 24, 2025)
iCMS v7.0.16 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php.
Attacker Value
Unknown

CVE-2022-41495

Disclosure Date: October 13, 2022 (last updated February 24, 2025)
ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the rss_url_news parameter at /manager/index.php.
Attacker Value
Unknown

CVE-2022-22244

Disclosure Date: October 12, 2022 (last updated February 24, 2025)
An XPath Injection vulnerability in the J-Web component of Juniper Networks Junos OS allows an unauthenticated attacker sending a crafted POST to reach the XPath channel, which may allow chaining to other unspecified vulnerabilities, leading to a partial loss of confidentiality. This issue affects Juniper Networks Junos OS: all versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S7; 19.4 versions prior to 19.4R3-S9; 20.1 versions prior to 20.1R3-S5; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S5; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S3; 21.2 versions prior to 21.2R3-S1; 21.3 versions prior to 21.3R3; 21.4 versions prior to 21.4R1-S2, 21.4R2; 22.1 versions prior to 22.1R1-S1, 22.1R2.