CWE-918
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
2,756 vulnerabilities with CWE-918
CVE-2022-27311
CRITICAL
Gibbon < 3.4.4 - Server-Side Request Forgery via Crafted URL
CVSS 9.8
CVE-2022-24871
HIGH
Shopware < 6.4.10.1 - Server-Side Request Forgery via Admin SDK
CVSS 7.2
CVE-2022-24862
HIGH
Databasir 1.0.1 - Server-Side Request Forgery via JDBC Driver Download Check
CVSS 7.7
CVE-2022-24825
MEDIUM
stripe/smokescreen < 0.0.3 - Server-Side Request Forgery via Deny List Bypass
CVSS 5.8
CVE-2022-29153
HIGH
HashiCorp Consul <1.9.16-1.11.4 - SSRF
CVSS 7.5
CVE-2022-1037
HIGH
EXMAGE WordPress Plugin < 1.0.7 - Server-Side Request Forgery via Image URL
CVSS 7.2
CVE-2022-27426
HIGH
Chamilo LMS 1.11.0-1.11.15 - Server-Side Request Forgery via Crafted Phar File
CVSS 8.8
CVE-2022-26499
CRITICAL
Asterisk 16.15.0-19.x - Server-Side Request Forgery via STIR/SHAKEN Identity Header
CVSS 9.1
CVE-2022-22339
HIGH
IBM Planning Analytics 2.0 - Authenticated Server-Side Request Forgery
CVSS 7.3
CVE-2022-1213
HIGH
livehelperchat < 3.67 - Server-Side Request Forgery via Port 80/443 Filter Bypass
CVSS 8.1
CVE-2022-1188
LOW
GitLab 12.1-14.7.6, 14.8-14.8.4, 14.9-14.9.1 - Server-Side Request Forgery via Repository Mirroring
CVSS 3.7
CVE-2022-0990
CRITICAL
calibre-web < 0.6.18 - Server-Side Request Forgery
CVSS 9.1
CVE-2022-0939
CRITICAL
calibre-web < 0.6.18 - Server-Side Request Forgery
CVSS 9.9
CVE-2022-0425
MEDIUM
GitLab 7.9-14.7.1 - Server-Side Request Forgery via Irker DNS Rebinding
CVSS 5.4
CVE-2022-1191
HIGH
live_helper_chat < 3.96 - Server-Side Request Forgery via Cobrowse Proxy CSS Endpoint
CVSS 8.1
CVE-2022-27907
MEDIUM
Sonatype Nexus Repository Manager 3.0.0-3.37.0 - Server-Side Request Forgery
CVSS 4.3
CVE-2022-24789
HIGH
C1 CMS < 6.12 - Authenticated Server-Side Request Forgery and Denial of Service
CVSS 7.6
CVE-2022-0249
LOW
GitLab 12.0-14.5.3 - Server-Side Request Forgery via Shared Address Space
CVSS 3.1
CVE-2022-0136
MEDIUM
GitLab 10.5-14.5.4, 14.6-14.6.4, 14.7-14.7.1 - Server-Side Request Forgery via Project Import
CVSS 5.4
CVE-2022-0591
CRITICAL
FormCraft WP <3.8.28 - Server-Side Request Forgery via URL Parameter
CVSS 9.1
CVE-2022-27245
HIGH
MISP < 2.4.156 - Server-Side Request Forgery via generateServerSettings
CVSS 8.8
CVE-2022-0870
MEDIUM
Gogs < 0.12.5 - Server-Side Request Forgery
CVSS 5.3
CVE-2022-24739
HIGH
alltube <3.0.3 - SSRF/Open Redirect
CVSS 7.3
CVE-2022-0767
CRITICAL
janeczku/calibre-web <0.6.17 - SSRF
CVSS 9.9
CVE-2022-0766
CRITICAL
janeczku/calibre-web <0.6.17 - SSRF
CVSS 9.8
Details
Vulnerabilities
2,756