Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 15.597 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 169 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Search results for: SSRF

Displaying 1 - 25 results out of 151

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
Stirling-PDF SSRF via MarkdownNetwork Scanner

High(8.6)

No
Memos 0.13.2 - Server-Side Request ForgeryNetwork Scanner

Medium(6.1)

No
Memos 0.13.2 - Cross-Site Scripting & SSRFNetwork Scanner

Medium(6.1)

No
Next.js Middleware - Server-Side Request ForgeryNetwork Scanner

Medium(6.5)

No
Memos 0.13.2 - Server-Side Request ForgeryNetwork Scanner

Medium(5.3)

No
Portal API - Server Side Request ForgeryNetwork Scanner

High

No
Request-Baskets <= 1.2.1 - Server Side Request ForgeryNetwork Scanner

Medium(6.5)

No
Apache Druid - Server-Side Request ForgeryNetwork Scanner

High(5.4)

No
TiTiler - Blind Server Side Request ForgeryNetwork Scanner

High

No
OneNav v0.9.35-20240318 - Server-Side Request Forgery (SSRF)Network Scanner

Medium(6.5)

No
GeoServer Demo Request Endpoint - Server Side Request ForgeryNetwork Scanner

High(7.5)

No
LyLme spage v1.9.5 - Server-Side Request ForgeryNetwork Scanner

Critical(9.1)

No
WordPress Broken Link Notifier < 1.3.1 - Unauthenticated SSRFNetwork Scanner

High(7.5)

No
Gradio - Server-Side Request ForgeryNetwork Scanner

High(8.6)

No
GeoServer WFS - XXE Processing VulnerabilityNetwork Scanner

Critical(9.9)

No
Grafana - XSS / Open Redirect / SSRF via Client Path TraversalNetwork Scanner

High(7.6)

No
draw.io < 18.0.5 - Server Side Request Forgery (SSRF)Network Scanner

High(7.5)

No
Cybersecurity Infrastructure Security Agency (CISA)Commvault - SSRF via /commandcenter/deployWebpackage.doNetwork Scanner

Critical(10)

No
WordPress WPB Show Core <= 2.2 - Server-Side Request ForgeryNetwork Scanner

Critical(9.8)

No
WordPress CAS Theme <= 1.0.0 - Server-Side Request ForgeryNetwork Scanner

Critical(9.1)

No
QNAP QTS SSRF Vulnerability (QSA-24-53)Network Scanner
N/A
No
QNAP QuTS hero SSRF Vulnerability (QSA-24-53)Network Scanner
N/A
No
WordPress TablePress Plugin < 2.2.5 SSRF VulnerabilityNetwork Scanner

Medium(4.9)

No
WordPress TablePress Plugin < 2.3.2 SSRF VulnerabilityNetwork Scanner

Medium(6.4)

No
Elestio Memos <= v0.24.0 - Server-Side Request ForgeryNetwork Scanner

Critical(9.8)

No