CWE-918
3,430 CVEs • Abstraction: Base
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
CVEs (3,430)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Open Xchange 1Open Xchange Appsuite Jun 17, 2026 Jun 16, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 OX App Suite through 7.10.3 allows SSRF. |
An issue was discovered in DigDash 2018R2 before p20200210 and 2019R1 before p20200210. The login page is vulnerable to Server-Side Request Forgery (SSRF) that allows use of the application as a proxy. Sent to an externa...Show more |
OX Guard 2.10.3 and earlier allows SSRF. |
In Karaf, JMX authentication takes place using JAAS and authorization takes place using ACL files. By default, only an "admin" can actually invoke on an MBean. However there is a vulnerability there for someone who is no...Show more |
Adobe Experience Manager versions 6.5 and earlier have a blind server-side request forgery (ssrf) vulnerability. Successful exploitation could lead to sensitive information disclosure. |
Adobe Experience Manager versions 6.5 and earlier have a server-side request forgery (ssrf) vulnerability. Successful exploitation could lead to sensitive information disclosure. |
Havoc Research discovered an authenticated Server-Side Request Forgery (SSRF) via the "JSON" data source of Redash open-source 8.0.0 and prior. Possibly, other connectors are affected. The SSRF is potent and provides a l...Show more |
1Hcltech 1Hcl Digital Experience Jun 17, 2026 Jun 11, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 "HCL Digital Experience is susceptible to Server Side Request Forgery." |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Jun 10, 2020 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 SAP Netweaver AS ABAP, versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, are vulnerable for Server Side Request Forgery Attack where in an attacker can use inappropriate path names containing mali...Show more |
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enum...Show more |
2Fedoraproject Kubernetes2Fedora KubernetesJun 17, 2026 Jun 5, 2020 N/A· v4 6.3 MEDIUM· v3 3.5 LOW· v2 The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a Server Side Request Forgery (SSRF) that allows certain authorized users...Show more |
4Fedoraproject GrafanaNetapp+1 more5Backports Sle E Series Performance AnalyzerFedora+2 moreJun 17, 2026 Jun 3, 2020 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result...Show more |
Lexiglot through 2014-11-20 allows SSRF via the admin.php?page=projects svn_url parameter. |
WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this node's entire intranet. |
1Ibm 1Websphere Application Server Jun 17, 2026 May 14, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM WebSphere Application Server 8.5 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-...Show more |
1Commscope 1Ruckus Zoneflex R500 Firmware Jun 17, 2026 May 5, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other analysis via the SUBCA-1 field on the Wireless Admin screen. |
Server-side request forgery (SSRF) vulnerability in Cybozu Garoon 4.6.0 to 4.6.3 allows a remote attacker with an administrative privilege to issue arbitrary HTTP requests to other web servers via V-CUBE Meeting function...Show more |
WSO2 Enterprise Integrator through 6.6.0 has an XXE vulnerability where a user (with admin console access) can use the XML validator to make unintended network invocations such as SSRF via an uploaded file. |
1Ibm 1Qradar Security Information And Event Manager Jun 17, 2026 Apr 15, 2020 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 IBM QRadar 7.3.0 to 7.3.3 Patch 2 is vulnerable to Server Side Request Forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or...Show more |
GitLab EE/CE 8.0.rc1 to 12.9 is vulnerable to a blind SSRF in the FogBugz integration. |