Show filters
1,156 Total Results
Displaying 321-330 of 1,156
Sort by:
Attacker Value
Unknown
CVE-2024-27898
Disclosure Date: April 09, 2024 (last updated February 26, 2025)
SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vulnerable web application targeting internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability. Thus, having a low impact on confidentiality.
0
Attacker Value
Unknown
CVE-2024-31288
Disclosure Date: April 07, 2024 (last updated February 26, 2025)
Server-Side Request Forgery (SSRF) vulnerability in RapidLoad RapidLoad Power-Up for Autoptimize.This issue affects RapidLoad Power-Up for Autoptimize: from n/a through 2.2.11.
0
Attacker Value
Unknown
CVE-2024-27620
Disclosure Date: April 06, 2024 (last updated February 26, 2025)
An issue in Ladder v.0.0.1 thru v.0.0.21 allows a remote attacker to obtain sensitive information via a crafted request to the API.
0
Attacker Value
Unknown
CVE-2024-31215
Disclosure Date: April 04, 2024 (last updated February 26, 2025)
Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile.
A SSRF vulnerability in firebase database check logic. The attacker can cause the server to make a connection to internal-only services within the organization’s infrastructure. When a malicious app is uploaded to Static analyzer, it is possible to make internal requests. This vulnerability has been patched in version 3.9.8.
0
Attacker Value
Unknown
CVE-2024-29007
Disclosure Date: April 04, 2024 (last updated February 26, 2025)
The CloudStack management server and secondary storage VM could be tricked into making requests to restricted or random resources by means of following 301 HTTP redirects presented by external servers when downloading templates or ISOs. Users are recommended to upgrade to version 4.18.1.1 or 4.19.0.1, which fixes this issue.
0
Attacker Value
Unknown
CVE-2024-20332
Disclosure Date: April 03, 2024 (last updated February 26, 2025)
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device.
This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device. To successfully exploit this vulnerability, the attacker would need valid Super Admin credentials.
0
Attacker Value
Unknown
CVE-2021-27312
Disclosure Date: April 03, 2024 (last updated February 26, 2025)
Server Side Request Forgery (SSRF) vulnerability in Gleez Cms 1.2.0, allows remote attackers to execute arbitrary code and obtain sensitive information via modules/gleez/classes/request.php.
0
Attacker Value
Unknown
CVE-2024-30532
Disclosure Date: April 02, 2024 (last updated February 26, 2025)
Server-Side Request Forgery (SSRF) vulnerability in Builderall Team Builderall Builder for WordPress.This issue affects Builderall Builder for WordPress: from n/a through 2.0.1.
0
Attacker Value
Unknown
CVE-2024-30531
Disclosure Date: April 02, 2024 (last updated February 26, 2025)
Server-Side Request Forgery (SSRF) vulnerability in Nelio Software Nelio Content.This issue affects Nelio Content: from n/a through 3.2.0.
0
Attacker Value
Unknown
CVE-2024-24888
Disclosure Date: April 02, 2024 (last updated February 26, 2025)
Server-Side Request Forgery (SSRF) vulnerability in Kadence WP Gutenberg Blocks by Kadence Blocks.This issue affects Gutenberg Blocks by Kadence Blocks: from n/a through 3.2.25.
0