CWE-918
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
2,748 vulnerabilities with CWE-918
CVE-2023-4624
LOW
bookstackapp/bookstack <v23.08 - SSRF
CVSS 2.4
CVE-2023-40017
HIGH
GeoNode 3.2.0-4.1.2 - Server-Side Request Forgery via Proxy Endpoint
CVSS 7.5
CVE-2023-37379
HIGH
Apache Airflow < 2.7.0 - Authenticated Denial of Service via Connection Test Feature
CVSS 8.1
CVE-2023-37440
MEDIUM
Aruba EdgeConnect SD-WAN Orchestrator < 9.3.1 - Unauthenticated Server-Side Request Forgery
CVSS 5.5
CVE-2023-24515
MEDIUM
Pandora FMS < 767 - Server-Side Request Forgery via API Checker URL Scheme
CVSS 5.2
CVE-2023-35011
MEDIUM
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 - Authenticated Server-Side Request Forgery
CVSS 5.4
CVE-2023-40033
HIGH
Flarum < 1.8.0 - Authenticated Server-Side Request Forgery via File Upload MIME Spoofing
CVSS 7.1
CVE-2023-3958
HIGH
WP Remote Users Sync <= 1.2.12 - Authenticated Server-Side Request Forgery via notify_ping_remote AJAX Function
CVSS 8.5
CVE-2023-26442
LOW
Open-Xchange App Suite Cacheservice - Sproxyd Redirect Server-Side Request Forgery
CVSS 3.2
CVE-2023-26438
MEDIUM
Open-Xchange App Suite - JDK DNS Cache Server-Side Request Forgery
CVSS 4.3
CVE-2023-39110
HIGH
rconfig v3.9.4 - Authenticated Server-Side Request Forgery via path parameter
CVSS 8.8
CVE-2023-39109
HIGH
rconfig v3.9.4 - Authenticated Server-Side Request Forgery via path_a Parameter
CVSS 8.8
CVE-2023-39108
HIGH
rconfig 3.9.4 - Authenticated Server-Side Request Forgery via path_b Parameter
CVSS 8.8
CVE-2023-3981
MEDIUM
Omeka < 4.0.2 - Server-Side Request Forgery
CVSS 4.9
CVE-2023-37290
HIGH
InfoDoc Document System - Unauthenticated SSRF via HTML to PDF Conversion
CVSS 7.5
CVE-2023-29260
MEDIUM
IBM Sterling Connect:Express for UNIX 1.5 - SSRF
CVSS 6.5
CVE-2023-3577
LOW
Mattermost 7.8.0-7.8.6 - Blind Server-Side Request Forgery via Interactive Dialog
CVSS 3.5
CVE-2023-32052
MEDIUM
Microsoft Power Apps < 9.2.23042 - Spoofing
CVSS 5.4
CVE-2023-36925
HIGH
SAP Solution Manager 7.20 - Unauthenticated Server-Side Request Forgery
CVSS 7.2
CVE-2023-3578
MEDIUM
dedecms 5.7.109 - Server-Side Request Forgery via co_do.php rssurl Parameter
CVSS 5.5
CVE-2023-37262
CRITICAL
CC: Tweaked < 1.16.5-1.101.3 - Server-Side Request Forgery via Unrestricted Cloud Metadata Endpoints
CVSS 9.6
CVE-2023-37261
CRITICAL
OpenComputers 1.2.0-1.8.3 - Server-Side Request Forgery via Internet Card Feature
CVSS 9.6
CVE-2023-35175
CRITICAL
HP LaserJet Pro MFP M478-M479 & M453-M454 < 002_2322c - RCE & Privilege Escalation via SSRF
CVSS 9.8
CVE-2023-3432
CRITICAL
PlantUML < 1.2023.9 - Server-Side Request Forgery
CVSS 10.0
CVE-2023-33176
MEDIUM
BigBlueButton <2.5.18 - Server-Side Request Forgery via insertDocument URL
CVSS 4.8
Details
Vulnerabilities
2,748