Show filters
306 Total Results
Displaying 31-40 of 306
Sort by:
Attacker Value
Unknown

CVE-2021-29738

Disclosure Date: October 29, 2021 (last updated February 23, 2025)
IBM InfoSphere Data Flow Designer (IBM InfoSphere Information Server 11.7 ) is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 201302.
Attacker Value
Unknown

CVE-2021-29844

Disclosure Date: October 25, 2021 (last updated February 23, 2025)
IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Attacker Value
Unknown

CVE-2021-35512

Disclosure Date: October 21, 2021 (last updated February 23, 2025)
An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200.
Attacker Value
Unknown

CVE-2021-41792

Disclosure Date: October 21, 2021 (last updated February 23, 2025)
An issue was discovered in Hyland org.alfresco:alfresco-content-services through 6.2.2.18 and org.alfresco:alfresco-transform-services through 1.3. A crafted HTML file, once uploaded, could trigger an unexpected request by the transformation engine. The response to the request is not available to the attacker, i.e., this is blind SSRF.
Attacker Value
Unknown

CVE-2021-25972

Disclosure Date: October 20, 2021 (last updated February 23, 2025)
In Camaleon CMS, versions 2.1.2.0 to 2.6.0, are vulnerable to Server-Side Request Forgery (SSRF) in the media upload feature, which allows admin users to fetch media files from external URLs but fails to validate URLs referencing to localhost or other internal servers. This allows attackers to read files stored in the internal server.
Attacker Value
Unknown

CVE-2021-32663

Disclosure Date: October 19, 2021 (last updated February 23, 2025)
iTop is an open source web based IT Service Management tool. In affected versions an attacker can call the system setup without authentication. Given specific parameters this can lead to SSRF. This issue has been resolved in versions 2.6.5 and 2.7.5 and later
Attacker Value
Unknown

CVE-2021-22033

Disclosure Date: October 13, 2021 (last updated February 23, 2025)
Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulnerability.
Attacker Value
Unknown

CVE-2021-42091

Disclosure Date: October 07, 2021 (last updated February 23, 2025)
An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration.
Attacker Value
Unknown

CVE-2021-22958

Disclosure Date: October 07, 2021 (last updated February 23, 2025)
A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP address to bypass the limitations in place for localhost allowing interaction with local services. Impact can vary depending on services exposed.CVSSv2.0 AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
Attacker Value
Unknown

CVE-2020-21649

Disclosure Date: October 06, 2021 (last updated February 23, 2025)
Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploited via the sql() method.