CWE-918
3,430 CVEs • Abstraction: Base
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
CVEs (3,430)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/detail.php?subdomain=SSRF. |
1Microstrategy 1Microstrategy Jul 9, 2026 Nov 24, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2 allows authenticated users to access the content of internal network resources or le...Show more |
1Private Ip Project 1Private Ip Jun 17, 2026 Nov 23, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Insufficient RegEx in private-ip npm package v1.0.5 and below insufficiently filters reserved IP ranges resulting in indeterminate SSRF. An attacker can perform a large range of requests to ARIN reserved IP ranges, resul...Show more |
JetBrains YouTrack before 2020.3.5333 was vulnerable to SSRF. |
JetBrains YouTrack before 2020.3.888 was vulnerable to SSRF. |
2Apache Oracle18Api Gateway BatikBusiness Intelligence+15 moreJun 17, 2026 Nov 12, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause...Show more |
Server-side request forgery vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers trigger server-side DNS requests to arbitrary domains via carefully constructed XML files l...Show more |
External entity attack vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers to gain control of a resource or trigger arbitrary code execution via improper input validation...Show more |
The Canto plugin 1.3.0 for WordPress allows includes/lib/download.php?subdomain= SSRF. |
1Sap 1Fiori Launchpad (news Tile Application) Jun 17, 2026 Nov 10, 2020 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send a crafted request to a vulnerable web application. It is usually used to target internal systems be...Show more |
1Sap 1Commerce Cloud (accelerator Payment Mock) Jun 17, 2026 Nov 10, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over a network to a particular SAP Commerce module URL which will be proces...Show more |
1Trendmicro 1Interscan Messaging Security Virtual Appliance Jun 17, 2026 Nov 9, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a server side request forgery vulnerability which could allow an authenticated attacker to abuse the product's web server and grant...Show more |
1Bitdefender 1Update Server Jun 17, 2026 Nov 9, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Insufficient validation in the Bitdefender Update Server and BEST Relay components of Bitdefender Endpoint Security Tools versions prior to 6.6.20.294 allows an unprivileged attacker to bypass the in-place mitigations an...Show more |
2Axios Siemens2Axios Sinec InsJun 17, 2026 Nov 6, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address. |
MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL. |
2Enhancesoft Osticket2Osticket OsticketJul 10, 2026 Nov 2, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning. |
Gophish before 0.11.0 allows SSRF attacks. |
1Arubanetworks 1Airwave Glass Jun 17, 2026 Oct 26, 2020 N/A· v4 5.8 MEDIUM· v3 5.0 MEDIUM· v2 A remote server-side request forgery (ssrf) vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. |
A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code. |
1Open Xchange 1Open Xchange Appsuite Jun 17, 2026 Oct 23, 2020 N/A· v4 5.0 MEDIUM· v3 4.0 MEDIUM· v2 OX App Suite through 7.10.3 allows SSRF via the the /ajax/messaging/message message API. |