CWE-918
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
2,742 vulnerabilities with CWE-918
CVE-2023-35817
MEDIUM
DevExpress < 23.1.3 - Server-Side Request Forgery via AsyncDownloader
CVSS 5.0
CVE-2023-6195
LOW
GitLab CE/EE <16.9.7, <16.10.5, <16.11.2 - SSRF
CVSS 2.6
CVE-2023-50733
HIGH
Lexmark Web Services - Server-Side Request Forgery
CVSS 8.6
CVE-2023-50913
CRITICAL
Oxide control plane software < 5 - Server-Side Request Forgery
CVSS 9.1
CVE-2023-37230
HIGH
Loftware Spectrum < 5.1 - Server-Side Request Forgery via testDeviceConnection
CVSS 8.8
CVE-2023-37229
HIGH
Loftware Spectrum < 5.1 - Server-Side Request Forgery
CVSS 8.8
CVE-2023-31456
MEDIUM
Fluid Topics < 4.3 - Authenticated Server-Side Request Forgery
CVSS 5.4
CVE-2023-50952
MEDIUM
IBM InfoSphere Information Server 11.7 - Authenticated Server-Side Request Forgery
CVSS 5.4
CVE-2023-45195
MEDIUM
AdminerEvo < 4.8.4 - Unauthenticated Server-Side Request Forgery via Database Connection Fields
CVSS 5.3
CVE-2023-7073
MEDIUM
WordPress Auto Featured Image <4.0.0 - SSRF
CVSS 6.4
CVE-2023-46784
HIGH
ICS Calendar <10.12.0.3 - Path Traversal
CVSS 8.2
CVE-2023-46295
CRITICAL
Teledyne FLIR M300 2.00-19 - Unauthenticated Remote Code Execution via PHP Page
CVSS 9.8
CVE-2023-7253
MEDIUM
Import WP < 2.13.1 - Authenticated Server-Side Request Forgery
CVSS 6.1
CVE-2023-6805
MEDIUM
RSS Aggregator by Feedzy < 4.4.7 - Authenticated Blind Server-Side Request Forgery via fetch_feed
CVSS 6.4
CVE-2023-40148
MEDIUM
PingFederate 11.0-11.3 - Unauthenticated Server-Side Request Forgery
CVSS 6.5
CVE-2023-6964
HIGH
Kadence Blocks < 3.1.26 - Authenticated SSRF via kadence_import_get_new_connection_data
CVSS 8.5
CVE-2023-45705
LOW
HCL BigFix Platform 10.0.0-10.0.10 - Authenticated Server-Side Request Forgery via SMTP Configuration
CVSS 3.5
CVE-2023-50374
MEDIUM
CMP - Coming Soon & Maintenance < 4.1.10 - Server-Side Request Forgery
CVSS 5.5
CVE-2023-39313
HIGH
ThemeFusion Avada < 7.11.1 - Authenticated Server-Side Request Forgery
CVSS 7.7
CVE-2023-36679
HIGH
Brainstorm Force Spectra <= 2.6.6 - Server-Side Request Forgery
CVSS 7.1
CVE-2023-34370
HIGH
Brainstorm Force Starter Templates - SSRF
CVSS 7.1
CVE-2023-49785
CRITICAL
NextChat < 2.11.2 - Server-Side Request Forgery and Cross-Site Scripting
CVSS 9.1
CVE-2023-47635
MEDIUM
Decidim 0.23.0-0.27.4 - Server-Side Request Forgery via Questionnaire Templates Preview
CVSS 4.5
CVE-2023-5122
MEDIUM
Grafana CSV Datasource Plugin - Server-Side Request Forgery via Bare Host URL
CVSS 5.0
CVE-2023-6294
HIGH
Popup Builder < 4.2.6 - Authenticated Server-Side Request Forgery via Unvalidated Parameter
CVSS 7.2
Details
Vulnerabilities
2,742