CWE-918
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
2,742 vulnerabilities with CWE-918
CVE-2024-27564
MEDIUM
ChatGPT个人专用版 - Server Side Request Forgery
CVSS 5.8
CVE-2024-27563
MEDIUM
WonderCMS 3.1.3 - Server-Side Request Forgery via PluginThemeUrl Parameter
CVSS 5.3
CVE-2024-27561
HIGH
WonderCMS 3.1.3 - Server-Side Request Forgery via installUpdateThemePluginAction
CVSS 8.1
CVE-2024-2057
MEDIUM
LangChain Community 0.0.26 - Server-Side Request Forgery in TFIDFRetriever load_local
CVSS 6.3
CVE-2024-27949
MEDIUM
Sirv CDN and Image Hosting Sirv <= 7.2.0 - Server-Side Request Forgery
CVSS 5.4
CVE-2024-0403
MEDIUM
Recipes 1.5.10 - Server-Side Request Forgery
CVSS 6.5
CVE-2024-1978
MEDIUM
Friends <= 2.8.5 - Authenticated Server-Side Request Forgery via discover_available_feeds
CVSS 5.5
CVE-2024-26476
LOW
openemr < 7.0.2 - Server-Side Request Forgery via ereq_form.php formid Parameter
CVSS 3.5
CVE-2024-1965
MEDIUM
Haivision's Aviwest Manager & Aviwest Steamhub - SSRF
CVSS 6.5
CVE-2024-1568
MEDIUM
Seraphinite Accelerator <= 2.20.52 - Authenticated Server-Side Request Forgery via OnAdminApi_HtmlCheck
CVSS 6.4
CVE-2024-0759
HIGH
AnythingLLM - Manager-Level Server-Side Request Forgery via Link Scraper
CVSS 7.5
CVE-2024-22873
HIGH
Tencent Blueking CMDB 3.2.2-3.9.47 - Server-Side Request Forgery via Event Subscription Function
CVSS 8.1
CVE-2024-1758
MEDIUM
SuperFaktura WooCommerce <= 1.40.3 - Authenticated Server-Side Request Forgery via wc_sf_url_check Function
CVSS 5.4
CVE-2024-0455
HIGH
AnythingLLM - Authenticated Server-Side Request Forgery via Web Scraper URL Parameter
CVSS 7.5
CVE-2024-0440
MEDIUM
Mintplexlabs AnythingLLM - Server-Side Request Forgery
CVSS 6.5
CVE-2024-0243
HIGH
langchain < 0.1.0 - Server-Side Request Forgery via RecursiveUrlLoader
CVSS 8.1
CVE-2024-25915
MEDIUM
Pexels: Free Stock Photos <= 1.2.2 - Server-Side Request Forgery
CVSS 4.9
CVE-2024-23654
MEDIUM
discourse-ai < 2024-02-21 - Server-Side Request Forgery via AI Service Interaction
CVSS 4.1
CVE-2024-21498
MEDIUM
caddy-security - Server-Side Request Forgery via X-Forwarded-Host Header Manipulation
CVSS 5.3
CVE-2024-23788
HIGH
Sharp JH-RVB1/JH-RV11 Firmware < B0.1.9.1 - Unauthenticated Server-Side Request Forgery
CVSS 8.1
CVE-2024-23761
CRITICAL
Gambio 4.9.2.0 - Remote Code Execution via Smarty Email Template SSTI
CVSS 9.8
CVE-2024-24829
MEDIUM
Sentry 9.1.0-24.1.1 - Server-Side Request Forgery via Phabricator Integration
CVSS 4.3
CVE-2024-24113
HIGH
xxl-job <= 2.4.1 - Server-Side Request Forgery
CVSS 8.8
CVE-2024-24806
HIGH
libuv 1.24.0-1.47.0 - Server-Side Request Forgery via Hostname Truncation
CVSS 7.3
CVE-2024-0628
LOW
WP RSS Aggregator <= 4.23.5 - Authenticated Server-Side Request Forgery via RSS Feed Source
CVSS 3.8
Details
Vulnerabilities
2,742