Show filters
244 Total Results
Displaying 21-30 of 244
Sort by:
Attacker Value
Unknown

CVE-2021-22726

Disclosure Date: July 21, 2021 (last updated February 23, 2025)
A CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could allow an attacker to perform unintended actions or access to data when crafted malicious parameters are submitted to the charging station web server.
Attacker Value
Unknown

CVE-2021-31216

Disclosure Date: July 19, 2021 (last updated February 23, 2025)
Siren Investigate before 11.1.1 contains a server side request forgery (SSRF) defect in the built-in image proxy route (which is enabled by default). An attacker with access to the Investigate installation can specify an arbitrary URL in the parameters of the image proxy route and fetch external URLs as the Investigate process on the host.
Attacker Value
Unknown

CVE-2021-33213

Disclosure Date: July 14, 2021 (last updated February 23, 2025)
An SSRF vulnerability in the "Upload from URL" feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated users to retrieve HTTP and FTP files from the internal server network by inserting an internal address.
Attacker Value
Unknown

CVE-2021-29749

Disclosure Date: July 13, 2021 (last updated February 23, 2025)
IBM Secure External Authentication Server 6.0.2 and IBM Secure Proxy 6.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 201777.
Attacker Value
Unknown

CVE-2020-23079

Disclosure Date: July 12, 2021 (last updated February 23, 2025)
SSRF vulnerability in Halo <=1.3.2 exists in the SMTP configuration, which can detect the server intranet.
Attacker Value
Unknown

CVE-2021-29102

Disclosure Date: July 09, 2021 (last updated February 23, 2025)
A Server-Side Request Forgery (SSRF) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote, unauthenticated attacker to forge GET requests to arbitrary URLs from the system, potentially leading to network enumeration or facilitating other attacks.
Attacker Value
Unknown

CVE-2020-20582

Disclosure Date: July 08, 2021 (last updated February 23, 2025)
A server side request forgery (SSRF) vulnerability in /ApiAdminDomainSettings.php of MipCMS 5.0.1 allows attackers to access sensitive information.
Attacker Value
Unknown

CVE-2020-24148

Disclosure Date: July 07, 2021 (last updated February 23, 2025)
Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the data parameter in a moove_read_xml action.
Attacker Value
Unknown

CVE-2020-24142

Disclosure Date: July 07, 2021 (last updated February 23, 2025)
Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the njt-tk-download-video parameter. It can help identify open ports, local network hosts and execute command on services
Attacker Value
Unknown

CVE-2020-24147

Disclosure Date: July 07, 2021 (last updated February 23, 2025)
Server-side request forgery (SSR) vulnerability in the WP Smart Import (wp-smart-import) plugin 1.0.0 for WordPress via the file field.