Show filters
1,156 Total Results
Displaying 321-330 of 1,156
Sort by:
Attacker Value
Unknown

CVE-2024-27898

Disclosure Date: April 09, 2024 (last updated February 26, 2025)
SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vulnerable web application targeting internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability. Thus, having a low impact on confidentiality.
Attacker Value
Unknown

CVE-2024-31288

Disclosure Date: April 07, 2024 (last updated February 26, 2025)
Server-Side Request Forgery (SSRF) vulnerability in RapidLoad RapidLoad Power-Up for Autoptimize.This issue affects RapidLoad Power-Up for Autoptimize: from n/a through 2.2.11.
0
Attacker Value
Unknown

CVE-2024-27620

Disclosure Date: April 06, 2024 (last updated February 26, 2025)
An issue in Ladder v.0.0.1 thru v.0.0.21 allows a remote attacker to obtain sensitive information via a crafted request to the API.
0
Attacker Value
Unknown

CVE-2024-31215

Disclosure Date: April 04, 2024 (last updated February 26, 2025)
Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. A SSRF vulnerability in firebase database check logic. The attacker can cause the server to make a connection to internal-only services within the organization’s infrastructure. When a malicious app is uploaded to Static analyzer, it is possible to make internal requests. This vulnerability has been patched in version 3.9.8.
0
Attacker Value
Unknown

CVE-2024-29007

Disclosure Date: April 04, 2024 (last updated February 26, 2025)
The CloudStack management server and secondary storage VM could be tricked into making requests to restricted or random resources by means of following 301 HTTP redirects presented by external servers when downloading templates or ISOs. Users are recommended to upgrade to version 4.18.1.1 or 4.19.0.1, which fixes this issue.
0
Attacker Value
Unknown

CVE-2024-20332

Disclosure Date: April 03, 2024 (last updated February 26, 2025)
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device. To successfully exploit this vulnerability, the attacker would need valid Super Admin credentials.
0
Attacker Value
Unknown

CVE-2021-27312

Disclosure Date: April 03, 2024 (last updated February 26, 2025)
Server Side Request Forgery (SSRF) vulnerability in Gleez Cms 1.2.0, allows remote attackers to execute arbitrary code and obtain sensitive information via modules/gleez/classes/request.php.
0
Attacker Value
Unknown

CVE-2024-30532

Disclosure Date: April 02, 2024 (last updated February 26, 2025)
Server-Side Request Forgery (SSRF) vulnerability in Builderall Team Builderall Builder for WordPress.This issue affects Builderall Builder for WordPress: from n/a through 2.0.1.
0
Attacker Value
Unknown

CVE-2024-30531

Disclosure Date: April 02, 2024 (last updated February 26, 2025)
Server-Side Request Forgery (SSRF) vulnerability in Nelio Software Nelio Content.This issue affects Nelio Content: from n/a through 3.2.0.
0
Attacker Value
Unknown

CVE-2024-24888

Disclosure Date: April 02, 2024 (last updated February 26, 2025)
Server-Side Request Forgery (SSRF) vulnerability in Kadence WP Gutenberg Blocks by Kadence Blocks.This issue affects Gutenberg Blocks by Kadence Blocks: from n/a through 3.2.25.