Show filters
493 Total Results
Displaying 81-90 of 493
Sort by:
Attacker Value
Unknown

CVE-2022-1977

Disclosure Date: June 27, 2022 (last updated February 24, 2025)
The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL before making an HTTP request to it, which could allow high privilege users such as admin to perform Blind SSRF attacks
Attacker Value
Unknown

CVE-2022-34013

Disclosure Date: June 23, 2022 (last updated February 23, 2025)
OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Logo parameter under the Link module.
Attacker Value
Unknown

CVE-2022-34011

Disclosure Date: June 23, 2022 (last updated February 23, 2025)
OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the parameter entryUrls.
Attacker Value
Unknown

CVE-2022-23080

Disclosure Date: June 22, 2022 (last updated February 23, 2025)
In directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media upload functionality which allows a low privileged user to perform internal network port scans.
Attacker Value
Unknown

CVE-2021-20421

Disclosure Date: June 22, 2022 (last updated February 24, 2025)
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Attacker Value
Unknown

CVE-2021-20544

Disclosure Date: June 22, 2022 (last updated February 24, 2025)
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 198931.
Attacker Value
Unknown

CVE-2021-36761

Disclosure Date: June 21, 2022 (last updated February 23, 2025)
The GeoAnalytics feature in Qlik Sense April 2020 patch 4 allows SSRF.
Attacker Value
Unknown

CVE-2022-23071

Disclosure Date: June 19, 2022 (last updated February 23, 2025)
In Recipes, versions 0.9.1 through 1.2.5 are vulnerable to Server Side Request Forgery (SSRF), in the “Import Recipe” functionality. When an attacker enters the localhost URL, a low privileged attacker can access/read the internal file system to access sensitive information.
Attacker Value
Unknown

CVE-2021-41403

Disclosure Date: June 15, 2022 (last updated February 23, 2025)
flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities.
Attacker Value
Unknown

CVE-2022-29612

Disclosure Date: June 14, 2022 (last updated February 23, 2025)
SAP NetWeaver, ABAP Platform and SAP Host Agent - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, 8.04, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, 8.04, SAPHOSTAGENT 7.22, allows an authenticated user to misuse a function of sapcontrol webfunctionality(startservice) in Kernel which enables malicious users to retrieve information. On successful exploitation, an attacker can obtain technical information like system number or physical address, which is otherwise restricted, causing a limited impact on the confidentiality of the application.