CWE-918
3,430 CVEs • Abstraction: Base
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
CVEs (3,430)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Adobe 2Adobe Commerce Magento Open SourceJun 17, 2026 Sep 1, 2021 N/A· v4 6.6 MEDIUM· v3 6.0 MEDIUM· v2 Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a blind SSRF vulnerability in the bundled dotmailer extension. An attacker with admin privileges could abuse t...Show more |
1Vmware 3Cloud Foundation Vrealize Operations ManagerVrealize Suite Lifecycle ManagerJun 17, 2026 Aug 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a S...Show more |
1Vmware 3Cloud Foundation Vrealize Operations ManagerVrealize Suite Lifecycle ManagerJun 17, 2026 Aug 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a S...Show more |
An SSRF vulnerability in Gotenberg through 6.2.1 exists in the remote URL to PDF conversion, which results in a remote attacker being able to read local files or fetch intranet resources. |
Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by a Server-side Request Forgery. An authenticated attacker could leverage this vulnerability to contact systems blocke...Show more |
5Debian FedoraprojectNetapp+2 more15Business Activity Monitoring Commerce Guided SearchCommunications Billing And Revenue Management Elastic Charging Engine+12 moreJun 17, 2026 Aug 23, 2021 N/A· v4 8.5 HIGH· v3 6.0 MEDIUM· v2 XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by...Show more |
5Debian FedoraprojectNetapp+2 more15Business Activity Monitoring Commerce Guided SearchCommunications Billing And Revenue Management Elastic Charging Engine+12 moreJun 17, 2026 Aug 23, 2021 N/A· v4 8.5 HIGH· v3 6.0 MEDIUM· v2 XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by...Show more |
A server-side request forgery (SSRF) vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability allowed remote authenticated attackers to open a connection to the machine via the deviceIpAddr and connPor...Show more |
SSRF in URL file upload in Baserow <1.1.0 allows remote authenticated users to retrieve files from the internal server network exposed over HTTP by inserting an internal address. |
Versions prior to 6.4.3.1 contain an authenticated server-side request forgery vulnerability in file upload via URL. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding...Show more |
1Nagios 1Nagios Xi Docker Wizard Jun 17, 2026 Aug 13, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Nagios XI Docker Wizard before version 1.1.3 is vulnerable to SSRF due to improper sanitation in table_population.php. |
1Fortinet 2Fortianalyzer FortimanagerJun 17, 2026 Aug 5, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A server-side request forgery (SSRF) (CWE-918) vulnerability in FortiManager and FortiAnalyser GUI 7.0.0, 6.4.5 and below, 6.2.7 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker...Show more |
1Qantumthemes 2Kentharadio Onair2Jun 17, 2026 Aug 2, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users, sending requests to this proxy functionality will have the web server...Show more |
The Import feature of the RSVPMaker WordPress plugin before 8.7.3 (/wp-admin/tools.php?page=rsvpmaker_export_screen) takes an URL input and calls curl on it, without first validating it to ensure it's a remote one. As a...Show more |
1Groupsession 3Groupsession Groupsession BycloudGroupsession ZionJun 17, 2026 Jul 30, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Server-side request forgery (SSRF) vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSe...Show more |
1Ibm 9Engineering Lifecycle Optimization Engineering Insights Engineering Requirements Quality Assistant On PremisesEngineering Test Management+6 moreJun 17, 2026 Jul 28, 2021 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or fac...Show more |
1Open Xchange 1Open Xchange Appsuite Jun 17, 2026 Jul 22, 2021 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled by the imageconverter component when the .png extension is used. |
1Schneider Electric 6Evlink City Evc1s22p4 Firmware Evlink City Evc1s7p4 FirmwareEvlink Parking Ev.2 Firmware+3 moreJun 17, 2026 Jul 21, 2021 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 A CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlin...Show more |
Siren Investigate before 11.1.1 contains a server side request forgery (SSRF) defect in the built-in image proxy route (which is enabled by default). An attacker with access to the Investigate installation can specify an...Show more |
1Ibm 2Secure External Authentication Server Sterling Secure ProxyJun 17, 2026 Jul 15, 2021 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 IBM Secure External Authentication Server 6.0.2 and IBM Secure Proxy 6.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, pote...Show more |