CWE-918
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
2,758 vulnerabilities with CWE-918
CVE-2019-12633
HIGH
Cisco Unified Contact Center Express - Unauthenticated Server-Side Request Forgery
CVSS 7.5
CVE-2019-12632
HIGH
Cisco Finesse - Unauthenticated Server-Side Request Forgery
CVSS 7.5
CVE-2019-13020
CRITICAL
Tightrope Media Carousel < 7.1.3 - Unauthenticated Server-Side Request Forgery via Fetch API
CVSS 10.0
CVE-2019-15494
CRITICAL
openITCOCKPIT < 3.7.1 - Server-Side Request Forgery
CVSS 9.8
CVE-2019-11897
HIGH
ProSyst mBS SDK <8.2.6 & Bosch IoT Gateway Software <9.3.0 - SSRF
CVSS 8.6
CVE-2019-0345
CRITICAL
SAP NetWeaver Application Server Java 7.30, 7.31, 7.40, 7.50 - Unauthenticated Server-Side Request Forgery via XML File
CVSS 9.8
CVE-2019-12994
CRITICAL
ManageEngine AssetExplorer 6.2.0 - Server-Side Request Forgery via AJaxServlet Parameter
CVSS 9.1
CVE-2019-12959
HIGH
ManageEngine AssetExplorer < 6.2.0 - Server-Side Request Forgery via ClientUtilServlet URL Parameter
CVSS 8.8
CVE-2019-14255
CRITICAL
go-camo < 1.1.4 - Server-Side Request Forgery
CVSS 9.8
CVE-2019-14704
CRITICAL
MicroDigital N-series <6400.0.8.5 - SSRF
CVSS 9.8
CVE-2019-7923
HIGH
Magento 2.1.0-2.1.17, 2.2.0-2.2.8, 2.3.0-2.3.1 - Authenticated Server-Side Request Forgery in Shipment Settings
CVSS 7.2
CVE-2019-7913
HIGH
Magento 2.1.0-2.1.17 - Authenticated Server-Side Request Forgery via Shipment Method Manipulation
CVSS 7.2
CVE-2019-7911
HIGH
Magento <1.9.4.2, <1.14.4.2, <2.1.18, <2.2.9, <2.3.2 - SSRF
CVSS 7.2
CVE-2019-7892
HIGH
Magento 2.1-2.1.17, 2.2-2.2.8, 2.3-2.3.1 - Authenticated Remote Code Execution via Server-Side Request Forgery
CVSS 7.2
CVE-2019-7616
MEDIUM
Kibana < 6.8.2 - Authenticated Server-Side Request Forgery via Timelion Graphite URL Configuration
CVSS 4.9
CVE-2019-9827
CRITICAL
Hawt Hawtio < 2.5.0 - Server-Side Request Forgery via Proxy URI
CVSS 9.8
CVE-2019-12852
CRITICAL
JetBrains YouTrack < 2018.4.49168 - Server-Side Request Forgery
CVSS 9.8
CVE-2019-12153
CRITICAL
RealObjects PDFreactor <10.1.10722 - SSRF
CVSS 10.0
CVE-2019-9187
HIGH
ikiwiki < 3.20170111.1, 3.2018x, < 3.20190228 - Server-Side Request Forgery via Aggregate Plugin
CVSS 7.5
CVE-2019-1872
MEDIUM
Cisco TelePresence Video Communication Server - DoS
CVSS 5.3
CVE-2019-6981
MEDIUM
Zimbra Collaboration Suite <8.9 - Blind SSRF
CVSS 6.5
CVE-2019-12161
HIGH
webpagetest 19.04 - Server-Side Request Forgery via Octal IP Address Encoding
CVSS 8.8
CVE-2019-6516
MEDIUM
WSO2 Dashboard Server 2.0.0 - Server-Side Request Forgery
CVSS 5.8
CVE-2019-6512
MEDIUM
WSO2 API Manager 2.6.0 - Server-Side Request Forgery via file:// Wrapper
CVSS 4.1
CVE-2019-11066
CRITICAL
LightOpenID < 1.3.1 - Server-Side Request Forgery via OpenID 2.0 Assertion Request
CVSS 9.8
Details
Vulnerabilities
2,758