CWE-918
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
2,756 vulnerabilities with CWE-918
CVE-2021-27312
CRITICAL
Gleez CMS 1.2.0 - Server-Side Request Forgery via Request Handler
CVSS 9.4
CVE-2021-35391
HIGH
Deskpro Support Desk <v2021.21.6 - SSRF
CVSS 7.2
CVE-2021-42079
MEDIUM
QuantaStor < 6.0.0.355 - Authenticated Server-Side Request Forgery via Alert Configuration
CVSS 6.2
CVE-2021-36396
HIGH
Moodle - Blind Server-Side Request Forgery via Redirect Handling Bypass
CVSS 7.5
CVE-2021-33926
HIGH
Plone 4.3.2-5.2.4 - Server-Side Request Forgery via RSS Feed Portlet
CVSS 8.8
CVE-2021-43449
HIGH
ONLYOFFICE Server - Server-Side Request Forgery via Document Editor URL Fetch
CVSS 8.1
CVE-2021-37498
MEDIUM
Reprise License Manager < 17.0 - Server-Side Request Forgery via License Activation actserver Parameter
CVSS 6.5
CVE-2021-27693
CRITICAL
PublicCMS < 4.0.202011.b - Server-Side Request Forgery via UEditor Catchimage Action
CVSS 9.8
CVE-2021-43959
MEDIUM
Atlassian Jira Service Management Server & Data Center <4.13.20 - SSRF
CVSS 5.7
CVE-2021-20544
MEDIUM
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, 7.0.2 - Authenticated Server-Side Request Forgery
CVSS 4.3
CVE-2021-20421
MEDIUM
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, 7.0.2 - Authenticated Server-Side Request Forgery
CVSS 4.3
CVE-2021-36761
MEDIUM
Qlik Sense - Server-Side Request Forgery
CVSS 5.3
CVE-2021-41403
CRITICAL
flatCore-CMS 2.0.8 - Server-Side Request Forgery via Dangerous Function Calls
CVSS 9.8
CVE-2021-40604
CRITICAL
IPS Community Suite < 4.6.2 - Authenticated Server-Side Request Forgery via Dynamic Class Name Generation
CVSS 9.1
CVE-2021-40186
MEDIUM
DNN CMS - Server-Side Request Forgery
CVSS 6.5
CVE-2021-40822
HIGH
GeoServer <= 2.18.5 and 2.19.x <= 2.19.2 - Server-Side Request Forgery via Proxy Host Configuration
CVSS 7.5
CVE-2021-36203
MEDIUM
Metasys System Configuration Tool < 14.2.2 - Server-Side Request Forgery
CVSS 5.3
CVE-2021-36202
HIGH
Johnson Controls Metasys <10.1.5, <11.0.2 - SSRF
CVSS 8.4
CVE-2021-33581
HIGH
MashZone NextGen < 10.7 - Server-Side Request Forgery via PPM Connection Availability Check
CVSS 7.2
CVE-2021-44139
HIGH
Sentinel 1.8.2 - Server-Side Request Forgery
CVSS 7.5
CVE-2021-45968
HIGH
Jive XMPP Server - Server-Side Request Forgery via Backend Tomcat Endpoint
CVSS 7.5
CVE-2021-46107
HIGH
Ligeo Archives Ligeo Basics - Server-Side Request Forgery via Download Feature
CVSS 7.5
CVE-2021-45851
HIGH
FUXA 1.1.3 - Server-Side Request Forgery
CVSS 7.5
CVE-2021-39051
MEDIUM
IBM Spectrum Copy Data Management 2.2.0.0-2.2.14.3 - Server-Side Request Forgery via Application Server Registration
CVSS 6.5
CVE-2021-43954
MEDIUM
Atlassian Crucible and Fisheye < 4.8.9 - Server-Side Request Forgery via DefaultRepositoryAdminService
CVSS 4.3
Details
Vulnerabilities
2,756