← Back
CWE-918

3,430 CVEs • Abstraction: Base

Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

JSON object

Loading...

CVEs (3,430)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Neliosoftware
1Nelio Ab Testing
Nov 21, 2024
Aug 22, 2019
N/A· v4
10.0 CRITICAL· v3
6.4 MEDIUM· v2
The nelio-ab-testing plugin before 4.5.9 for WordPress has SSRF in ajax/iesupport.php.
1Bosch
2Iot Gateway Software
Prosyst Mbs Sdk
Jun 17, 2026
Aug 21, 2019
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
A Server-Side Request Forgery (SSRF) vulnerability in the backup & restore functionality in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.3.0 allows a remote attacker to forge GET requests...Show more
A Server-Side Request Forgery (SSRF) vulnerability in the backup & restore functionality in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.3.0 allows a remote attacker to forge GET requests to arbitrary URLs. In addition, this could potentially allow an attacker to read sensitive zip files from the local server.Show less
1Sap
1Netweaver Application Server Java
Jun 17, 2026
Aug 14, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Java (Administrator System Overview), versions 7.30, 7.31, 7.40, 7.50, by sending a specially crafted XML file and trick t...Show more
A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Java (Administrator System Overview), versions 7.30, 7.31, 7.40, 7.50, by sending a specially crafted XML file and trick the application server into leaking authentication credentials for its own SAP Management console, resulting in Server-Side Request Forgery.Show less
1Zohocorp
1Manageengine Assetexplorer
Jun 17, 2026
Aug 8, 2019
N/A· v4
9.1 CRITICAL· v3
6.5 MEDIUM· v2
Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet via a parameter in a URL.
1Zohocorp
1Manageengine Assetexplorer
Jun 17, 2026
Aug 8, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer 6.2.0 and before for the ClientUtilServlet servlet via a URL in a parameter.
1Go Camo Project
1Go Camo
Jun 17, 2026
Aug 8, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Server Side Request Forgery (SSRF) vulnerability in go-camo up to version 1.1.4 allows a remote attacker to perform HTTP requests to internal endpoints.
1Microdigital
3Mdc N2190v Firmware
Mdc N4090 FirmwareMdc N4090w Firmware
Jun 17, 2026
Aug 6, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SSRF issue was discovered in HTTPD on MicroDigital N-series cameras with firmware through 6400.0.8.5 via FTP commands following a newline character in the uploadfile field.
1Magento
1Magento
Jun 17, 2026
Aug 2, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A server-side request forgery (SSRF) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by authenticated user with admin privileges to manip...Show more
A server-side request forgery (SSRF) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by authenticated user with admin privileges to manipulate shipment settings to execute arbitrary code.Show less
1Magento
1Magento
Jun 17, 2026
Aug 2, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A server-side request forgery (SSRF) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with admin privileges to ma...Show more
A server-side request forgery (SSRF) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with admin privileges to manipulate shipment methods to execute arbitrary code.Show less
1Magento
1Magento
Jun 17, 2026
Aug 2, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A server-side request forgery (SSRF) vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3...Show more
A server-side request forgery (SSRF) vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with access to the admin panel to manipulate system configuration and execute arbitrary code.Show less
1Magento
1Magento
Jun 17, 2026
Aug 2, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with administrator privileges to access shipment settings can exe...Show more
A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with administrator privileges to access shipment settings can execute arbitrary code via server-side request forgery.Show less
1Elastic
1Kibana
Jun 17, 2026
Jul 30, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Kibana versions before 6.8.2 and 7.2.1 contain a server side request forgery (SSRF) flaw in the graphite integration for Timelion visualizer. An attacker with administrative Kibana access could set the timelion:graphite....Show more
Kibana versions before 6.8.2 and 7.2.1 contain a server side request forgery (SSRF) flaw in the graphite integration for Timelion visualizer. An attacker with administrative Kibana access could set the timelion:graphite.url configuration option to an arbitrary URL. This could possibly lead to an attacker accessing external URL resources as the Kibana process on the host system.Show less
1Gitlab
1Gitlab
Nov 21, 2024
Jul 10, 2019
N/A· v4
7.7 HIGH· v3
4.0 MEDIUM· v2
GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an SSRF vulnerability in webhooks.
1Gitlab
1Gitlab
Nov 21, 2024
Jul 10, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an SSRF vulnerability in the Prometheus integration.
1Hawt
1Hawtio
Jun 17, 2026
Jul 3, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host via the initial /proxy/ substring of a URI.
1Jetbrains
1Youtrack
Jun 17, 2026
Jul 3, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SSRF attack was possible on a JetBrains YouTrack server. The issue (1 of 2) was fixed in JetBrains YouTrack 2018.4.49168.
1Realobjects
1Pdfreactor
Jun 17, 2026
Jun 11, 2019
N/A· v4
10.0 CRITICAL· v3
6.4 MEDIUM· v2
Lack of validation in the HTML parser in RealObjects PDFreactor before 10.1.10722 leads to SSRF, allowing attackers to access network or file resources on behalf of the server by supplying malicious HTML content.
1Ikiwiki
1Ikiwiki
Jun 17, 2026
Jun 5, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ikiwiki before 3.20170111.1 and 3.2018x and 3.2019x before 3.20190228 allows SSRF via the aggregate plugin. The impact also includes reading local files via file: URIs.
1Cisco
1Telepresence Video Communication Server
Jun 17, 2026
Jun 5, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway Series software could allow an unauthenticated, remote attacker to cause an affected system to send arbitrary network requests....Show more
A vulnerability in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway Series software could allow an unauthenticated, remote attacker to cause an affected system to send arbitrary network requests. The vulnerability is due to improper restrictions on network services in the affected software. An attacker could exploit this vulnerability by sending malicious requests to the affected system. A successful exploit could allow the attacker to send arbitrary network requests sourced from the affected system.Show less
1Synacor
1Zimbra Collaboration Suite
Jun 17, 2026
May 29, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Zimbra Collaboration Suite 8.7.x through 8.8.11 allows Blind SSRF in the Feed component.