CWE-918
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
2,749 vulnerabilities with CWE-918
CVE-2023-28111
MEDIUM
Discourse < 3.1.0 - Server-Side Request Forgery via IPv4-Mapped IPv6 Address Bypass
CVSS 5.7
CVE-2023-28155
MEDIUM
Request < 2.88.1 - Server-Side Request Forgery via Cross-Protocol Redirect
CVSS 6.1
CVE-2023-27896
MEDIUM
SAP BusinessObjects Business Intelligence Platform 420, 430 - Server-Side Request Forgery
CVSS 6.5
CVE-2023-27271
MEDIUM
SAP BusinessObjects Web Services <430 - DoS
CVSS 6.5
CVE-2023-26459
HIGH
SAP NetWeaver AS for ABAP and ABAP Platform <791 - Info Disclosure
CVSS 7.4
CVE-2023-27161
HIGH
Jellyfin < 10.7.7 - Server-Side Request Forgery via /Repositories Component
CVSS 7.5
CVE-2023-25230
MEDIUM
Loonflow r2.0.14 - Server-Side Request Forgery via hook_url Parameter
CVSS 4.9
CVE-2023-26492
MEDIUM
Directus <9.23.0 - Server-Side Request Forgery via File Import DNS Rebinding
CVSS 5.0
CVE-2023-20062
MEDIUM
Cisco Unified Intelligence Center - SSRF
CVSS 6.5
CVE-2023-1046
MEDIUM
MuYuCMS 2.2 - Server-Side Request Forgery via getFile url Parameter
CVSS 6.3
CVE-2023-22936
MEDIUM
Splunk Enterprise < 8.1.13, 8.2.10, 9.0.4 & Splunk Cloud < 9.0.2209.3 - SSRF via search_listener
CVSS 6.3
CVE-2023-25162
MEDIUM
Nextcloud Server < 23.0.12 - Server-Side Request Forgery via IP Filter Bypass
CVSS 5.3
CVE-2023-25557
HIGH
DataHub < 0.8.45 - Server-Side Request Forgery via Frontend Proxy
CVSS 7.5
CVE-2023-0574
MEDIUM
YugabyteDB Managed 2.0.0.0-2.13.0.0 - Server-Side Request Forgery
CVSS 6.8
CVE-2023-23943
MEDIUM
Nextcloud Mail < 1.15.0 - Server-Side Request Forgery via SMTP/IMAP/Sieve Host Fields
CVSS 5.0
CVE-2023-24623
HIGH
paranoidhttp < 0.3.0 - Server-Side Request Forgery via IPv6 Loopback Bypass
CVSS 7.5
CVE-2023-24622
MEDIUM
safeurl-python < 1.2 - Server-Side Request Forgery via isInList Regular Expression
CVSS 5.3
CVE-2023-24060
MEDIUM
Haven 5d15944 - Authenticated Server-Side Request Forgery via Feed URL Parameter
CVSS 5.0
CVE-2023-24495
MEDIUM
Tenable.sc 5.23.1 - Authenticated Server-Side Request Forgery
CVSS 6.5
CVE-2023-23560
CRITICAL
Lexmark B2236/B2338/B2442/B2546/B2650/B2865/B3340/B3442/C2240/C2325/C2326/C2425/C2535/C3224/C3326 Firmware SSRF
CVSS 9.8
CVE-2023-20002
MEDIUM
Cisco TelePresence CE - Auth Bypass
CVSS 4.4
CVE-2023-22493
HIGH
RSSHub < 2023-01-10 - Server-Side Request Forgery via Affected Routes
CVSS 8.8
CVE-2023-21761
HIGH
Microsoft Exchange Server - Info Disclosure
CVSS 7.5
CVE-2022-25777
MEDIUM
Mautic < 4.4.12 - Authenticated Server-Side Request Forgery
CVSS 6.5
CVE-2022-1751
HIGH
Skitter Slideshow <= 2.5.2 - Unauthenticated Server-Side Request Forgery via image.php
CVSS 7.2
Details
Vulnerabilities
2,749