← Back
CWE-918

2,678 CVEs • Abstraction: Base

Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

JSON object

Loading...

CVEs (2,678)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zohocorp
1Manageengine Servicedesk Plus Msp
May 30, 2025
Jun 29, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF).
1Crmeb
1Crmeb
Nov 21, 2024
Jun 24, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In CRMEB 3.1.0+ strict domain name filtering leads to SSRF(Server-Side Request Forgery). The vulnerable code is in file /crmeb/app/admin/controller/store/CopyTaobao.php.
1Elabftw
1Elabftw
Nov 21, 2024
Jun 21, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
eLabFTW is an open source electronic lab notebook for research labs. This vulnerability allows an attacker to make GET requests on behalf of the server. It is "blind" because the attacker cannot see the result of the req...Show more
eLabFTW is an open source electronic lab notebook for research labs. This vulnerability allows an attacker to make GET requests on behalf of the server. It is "blind" because the attacker cannot see the result of the request. Issue has been patched in eLabFTW 4.0.0.Show less
1Synology
1Download Station
Nov 21, 2024
Jun 18, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Server-Side Request Forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to access intranet resources via unspecified vectors.
1Synology
1Media Server
Nov 21, 2024
Jun 18, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Server-Side Request Forgery (SSRF) vulnerability in cgi component in Synology Media Server before 1.8.3-2881 allows remote attackers to access intranet resources via unspecified vectors.
1Ibm
1Security Identity Manager
Nov 21, 2024
Jun 16, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM Security Identity Manager 6.0.2 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data....Show more
IBM Security Identity Manager 6.0.2 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 197591.Show less
1Std42
1Elfinder
Nov 21, 2024
Jun 14, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands o...Show more
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hosting the elFinder PHP connector, even with minimal configuration. The issues were patched in version 2.1.59. As a workaround, ensure the connector is not exposed without authentication.Show less
1Gitlab
1Gitlab
Feb 18, 2026
Jun 11, 2021
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even...Show more
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabledShow less
1Broadcom
1Sannav
Nov 21, 2024
Jun 9, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Webtools in Brocade SANnav before version 2.1.1 allows unauthenticated users to make requests to arbitrary hosts due to a misconfiguration; this is commonly referred to as Server-Side Request Forgery (SSRF).
1Microsoft
2Sharepoint Foundation
Sharepoint Server
Nov 21, 2024
Jun 8, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Microsoft SharePoint Server Spoofing Vulnerability
2Djangoproject
Fedoraproject
2Django
Fedora
Nov 21, 2024
Jun 8, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit leading zero characters in octal literals. This may allow a bypass of...Show more
In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit leading zero characters in octal literals. This may allow a bypass of access control that is based on IP addresses. (validate_ipv4_address and validate_ipv46_address are unaffected with Python 3.9.5+..) .Show less
1Gitlab
1Gitlab
Nov 21, 2024
Jun 8, 2021
N/A· v4
8.6 HIGH· v3
4.3 MEDIUM· v2
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacke...Show more
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limitedShow less
1Yzmcms
1Yzmcms
Nov 21, 2024
Jun 3, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in YzmCMS 5.8. There is a SSRF vulnerability in the background collection management that allows arbitrary file read.
1Ibm
9Collaborative Lifecycle Management
Engineering Lifecycle ManagementEngineering Lifecycle Optimization Engineering Insights+6 more
Nov 21, 2024
Jun 2, 2021
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to networ...Show more
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-ForceID: 194597.Show less
1Ibm
9Collaborative Lifecycle Management
Engineering Lifecycle ManagementEngineering Lifecycle Optimization Engineering Insights+6 more
Nov 21, 2024
Jun 2, 2021
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to networ...Show more
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194596.Show less
1Ibm
9Collaborative Lifecycle Management
Engineering Lifecycle ManagementEngineering Lifecycle Optimization Engineering Insights+6 more
Nov 21, 2024
Jun 2, 2021
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to networ...Show more
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194595.Show less
1Ibm
9Collaborative Lifecycle Management
Engineering Lifecycle ManagementEngineering Lifecycle Optimization Engineering Insights+6 more
Nov 21, 2024
Jun 2, 2021
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to networ...Show more
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194594.Show less
1Ibm
9Collaborative Lifecycle Management
Engineering Lifecycle ManagementEngineering Lifecycle Optimization Engineering Insights+6 more
Nov 21, 2024
Jun 2, 2021
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to networ...Show more
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194593.Show less
1Synology
1Download Station
Nov 21, 2024
Jun 1, 2021
N/A· v4
7.7 HIGH· v3
4.0 MEDIUM· v2
Server-Side request forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.15-3563 allows remote authenticated users to read arbitrary files via unspecified vectors.
1Synology
1Video Station
Nov 21, 2024
Jun 1, 2021
N/A· v4
9.1 CRITICAL· v3
6.5 MEDIUM· v2
Server-Side Request Forgery (SSRF) vulnerability in webapi component in Synology Video Station before 2.4.10-1632 allows remote authenticated users to send arbitrary request to intranet resources via unspecified vectors.