Show filters
585 Total Results
Displaying 131-140 of 585
Sort by:
Attacker Value
Unknown

CVE-2022-38648

Disclosure Date: September 22, 2022 (last updated February 24, 2025)
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects Apache XML Graphics Batik 1.14.
Attacker Value
Unknown

CVE-2022-38398

Disclosure Date: September 22, 2022 (last updated February 24, 2025)
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14.
Attacker Value
Unknown

CVE-2022-40357

Disclosure Date: September 20, 2022 (last updated February 24, 2025)
A security issue was discovered in Z-BlogPHP <= 1.7.2. A Server-Side Request Forgery (SSRF) vulnerability in the zb_users/plugin/UEditor/php/action_crawler.php file allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the source parameter.
Attacker Value
Unknown

CVE-2022-38931

Disclosure Date: September 20, 2022 (last updated February 24, 2025)
A Server-Side Request Forgery (SSRF) in fetch_net_file_upload function of baijiacmsV4 v4.1.4 allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the url parameter.
Attacker Value
Unknown

CVE-2022-30579

Disclosure Date: September 20, 2022 (last updated February 24, 2025)
The Web Player component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a difficult to exploit vulnerability that allows a low privileged attacker with network access to execute blind Server Side Request Forgery (SSRF) on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: version 12.0.0 and TIBCO Spotfire Server: version 12.0.0.
Attacker Value
Unknown

CVE-2022-39211

Disclosure Date: September 16, 2022 (last updated February 24, 2025)
Nextcloud server is an open source personal cloud platform. In affected versions it was found that locally running webservices can be found and requested erroneously. It is recommended that the Nextcloud Server is upgraded to 23.0.8 or 24.0.4. It is recommended that the Nextcloud Enterprise Server is upgraded to 22.2.10.4, 23.0.8 or 24.0.4. There are no known workarounds for this issue.
Attacker Value
Unknown

CVE-2022-2912

Disclosure Date: September 16, 2022 (last updated February 24, 2025)
The Craw Data WordPress plugin through 1.0.0 does not implement nonce checks, which could allow attackers to make a logged in admin change the url value performing unwanted crawls on third-party sites (SSRF).
Attacker Value
Unknown

CVE-2022-36112

Disclosure Date: September 14, 2022 (last updated February 24, 2025)
GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Usage of RSS feeds or extenal calendar in planning is subject to SSRF exploit. Server-side requests can be used to scan server port or services opened on GLPI server or its private network. Queries responses are not exposed to end-user (blind SSRF). Users are advised to upgrade to version 10.0.3 to resolve this issue. There are no known workarounds.
Attacker Value
Unknown

CVE-2022-2900

Disclosure Date: September 14, 2022 (last updated February 24, 2025)
Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 8.1.0.
Attacker Value
Unknown

CVE-2022-38298

Disclosure Date: September 12, 2022 (last updated February 24, 2025)
Appsmith v1.7.11 was discovered to allow attackers to execute an authenticated Server-Side Request Forgery (SSRF) via redirecting incoming requests to the AWS internal metadata endpoint.