CWE-918
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
2,740 vulnerabilities with CWE-918
CVE-2024-30531
MEDIUM
Nelio Content < 3.2.0 - Server-Side Request Forgery
CVSS 4.9
CVE-2024-24888
MEDIUM
Kadence WP Gutenberg Blocks <3.2.25 - SSRF
CVSS 6.4
CVE-2024-25187
HIGH
71cms 1.0.0 - Unauthenticated Server-Side Request Forgery via getweather.html
CVSS 8.6
CVE-2024-30453
MEDIUM
Brave Popup Builder < 0.6.5 - Server-Side Request Forgery
CVSS 5.4
CVE-2024-27775
HIGH
SysAid < 23.2.14 b18 - Server-Side Request Forgery
CVSS 7.2
CVE-2024-29090
MEDIUM
Jordy Meow AI Engine: ChatGPT Chatbot <= 2.1.4 - Authenticated Server-Side Request Forgery
CVSS 6.8
CVE-2024-23500
HIGH
Gutenberg Blocks by Kadence Blocks <= 3.2.19 - Server-Side Request Forgery
CVSS 7.7
CVE-2024-0677
MEDIUM
Pz-LinkCard < 2.5.3 - Authenticated Server-Side Request Forgery via Shortcode
CVSS 5.1
CVE-2024-2206
MEDIUM
gradio < 4.18.0 - Server-Side Request Forgery via Proxy Route URL Validation
CVSS 6.5
CVE-2024-28435
MEDIUM
Twenty CRM 0.3.0 - Server-Side Request Forgery via File Upload
CVSS 5.4
CVE-2024-29190
HIGH
MobSF <= 3.9.5 Beta - android:host Server-Side Request Forgery
CVSS 7.5
CVE-2024-2828
MEDIUM
lakernote EasyAdmin < 2024-03-15 - Server-Side Request Forgery via Thumbnail URL Parameter
CVSS 6.3
CVE-2024-2827
MEDIUM
lakernote easyadmin < 2024-03-15 - Server-Side Request Forgery via /ureport/designer/saveReportFile
CVSS 6.3
CVE-2024-27927
MEDIUM
RSSHub <1.0.0-master.a429472 - Server-Side Request Forgery via Arbitrary HTTP Fetch
CVSS 6.5
CVE-2024-24028
MEDIUM
Likeshop < 2.5.7 - Server-Side Request Forgery via Avatar Parameter
CVSS 5.9
CVE-2024-25294
CRITICAL
REBUILD 3.5 - Server-Side Request Forgery via FileDownloader.java Proxy Download URL Parameter
CVSS 9.1
CVE-2024-27098
MEDIUM
GLPI 9.5.0-10.0.12 - Authenticated Server-Side Request Forgery via Arbitrary Object Instantiation
CVSS 6.4
CVE-2024-28752
CRITICAL
Apache CXF < 3.5.8 - Server-Side Request Forgery via Aegis DataBinding
CVSS 9.3
CVE-2024-1884
MEDIUM
PaperCut NG/MF < 20.1.10 - Server-Side Request Forgery
CVSS 6.5
CVE-2024-28668
MEDIUM
DedeCMS 5.7 - Cross-Site Request Forgery in mychannel_add.php
CVSS 6.1
CVE-2024-2049
MEDIUM
Citrix SD-WAN Standard/Premium Editions 11.4.0-11.4.4.46 - Server-Side Request Forgery via Management IP Access
CVSS 6.5
CVE-2024-27707
MEDIUM
Huly Platform 0.6.202 - Server-Side Request Forgery via SVG File Upload
CVSS 4.3
CVE-2024-27565
CRITICAL
ChatGPT-wechat-personal <a0857f6 - SSRF
CVSS 9.8
CVE-2024-27564
MEDIUM
ChatGPT个人专用版 - Server Side Request Forgery
CVSS 5.8
CVE-2024-27563
MEDIUM
WonderCMS 3.1.3 - Server-Side Request Forgery via PluginThemeUrl Parameter
CVSS 5.3
Details
Vulnerabilities
2,740