Show filters
752 Total Results
Displaying 211-220 of 752
Sort by:
Attacker Value
Unknown

CVE-2021-36396

Disclosure Date: March 06, 2023 (last updated February 24, 2025)
In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF risk.
Attacker Value
Unknown

CVE-2023-26492

Disclosure Date: March 03, 2023 (last updated February 24, 2025)
Directus is a real-time API and App dashboard for managing SQL database content. Directus is vulnerable to Server-Side Request Forgery (SSRF) when importing a file from a remote web server (POST to `/files/import`). An attacker can bypass the security controls by performing a DNS rebinding attack and view sensitive data from internal servers or perform a local port scan. An attacker can exploit this vulnerability to access highly sensitive internal server(s) and steal sensitive information. This issue was fixed in version 9.23.0.
Attacker Value
Unknown

CVE-2022-46973

Disclosure Date: March 03, 2023 (last updated February 24, 2025)
Report v0.9.8.6 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability.
Attacker Value
Unknown

CVE-2023-20062

Disclosure Date: March 01, 2023 (last updated February 24, 2025)
Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system. Cisco plans to release software updates that address these vulnerabilities.
Attacker Value
Unknown

CVE-2022-37938

Disclosure Date: March 01, 2023 (last updated February 24, 2025)
Unauthenticated server side request forgery in HPE Serviceguard Manager
Attacker Value
Unknown

CVE-2023-1046

Disclosure Date: February 26, 2023 (last updated February 24, 2025)
A vulnerability classified as critical has been found in MuYuCMS 2.2. This affects an unknown part of the file /admin.php/update/getFile.html. The manipulation of the argument url leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-221805 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-48321

Disclosure Date: February 20, 2023 (last updated February 24, 2025)
Limited Server-Side Request Forgery (SSRF) in agent-receiver in Tribe29's Checkmk <= 2.1.0p11 allows an attacker to communicate with local network restricted endpoints by use of the host registration API.
Attacker Value
Unknown

CVE-2021-33926

Disclosure Date: February 17, 2023 (last updated February 24, 2025)
An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1, 5.1.7, 5.1.6, 5.1.5, 5.1.4, 5.1.2, 5.1.1 5.1, 5.0rc3, 5.0rc2, 5.0rc1, 5.0.9, 5.0.8, 5.0.7, 5.0.6, 5.0.5, 5.0.4, 5.0.3, 5.0.2, 5.0.10, 5.0.1, 5.0, 4.3.9, 4.3.8, 4.3.7, 4.3.6, 4.3.5, 4.3.4, 4.3.3, 4.3.20, 4 allows attacker to access sensitive information via the RSS feed protlet.
Attacker Value
Unknown

CVE-2022-27234

Disclosure Date: February 16, 2023 (last updated February 24, 2025)
Server-side request forgery in the CVAT software maintained by Intel(R) before version 2.0.1 may allow an authenticated user to potentially enable information disclosure via network access.
Attacker Value
Unknown

CVE-2023-22936

Disclosure Date: February 14, 2023 (last updated February 24, 2025)
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘search_listener’ parameter in a search allows for a blind server-side request forgery (SSRF) by an authenticated user. The initiator of the request cannot see the response without the presence of an additional vulnerability within the environment.