CWE-918
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
2,758 vulnerabilities with CWE-918
CVE-2021-20347
MEDIUM
IBM Engineering Lifecycle Management - Authenticated Server-Side Request Forgery
CVSS 5.4
CVE-2021-20346
MEDIUM
IBM Jazz Foundation & IBM Engineering - SSRF
CVSS 5.4
CVE-2021-20345
MEDIUM
IBM Jazz Foundation & IBM Engineering - SSRF
CVSS 5.4
CVE-2021-20343
MEDIUM
IBM Jazz Foundation/Engineering - SSRF
CVSS 5.4
CVE-2021-33184
HIGH
Synology Download Station <3.8.15-3563 - SSRF
CVSS 7.7
CVE-2021-33181
MEDIUM
Synology Video Station <2.4.10-1632 - SSRF
CVSS 6.6
CVE-2021-25640
MEDIUM
Apache Dubbo 2.5.0-2.6.8 and 2.7.0-2.7.9 - Server-Side Request Forgery via parseURL Host Check Bypass
CVSS 6.1
CVE-2021-21985
CRITICAL
KEV
VMware vCenter Server - Remote Code Execution via Virtual SAN Health Check Plugin
CVSS 9.8
CVE-2021-30108
CRITICAL
Feehi CMS 2.1.1 - Server-Side Request Forgery via HTTP Referer Header
CVSS 9.1
CVE-2021-33511
HIGH
Plone < 5.2.4 - Server-Side Request Forgery via lxml Parser
CVSS 7.5
CVE-2021-33510
MEDIUM
Plone < 5.2.4 - Authenticated Server-Side Request Forgery via Event iCal URL
CVSS 4.3
CVE-2021-20535
MEDIUM
IBM Jazz Reporting Service <7.0.2 - SSRF
CVSS 5.4
CVE-2021-31910
HIGH
JetBrains TeamCity < 2020.2.3 - Server-Side Request Forgery
CVSS 7.5
CVE-2021-31828
HIGH
Amazon Open Distro for Elasticsearch < 1.13.1.0 - Authenticated Server-Side Request Forgery via Alerting Plugin
CVSS 7.1
CVE-2021-29490
MEDIUM
jellyfin < 10.7.3 - Unauthenticated Server-Side Request Forgery via imageUrl Parameter
CVSS 5.8
CVE-2021-29145
CRITICAL
Aruba ClearPass 6.7.0-6.7.14 - Server-Side Request Forgery
CVSS 9.8
CVE-2021-31779
MEDIUM
Yoast SEO < 7.2.1 - Authenticated Server-Side Request Forgery
CVSS 6.4
CVE-2021-29475
CRITICAL
HedgeDoc < 1.5.0 - Server-Side Request Forgery via PDF Export
CVSS 10.0
CVE-2021-29431
HIGH
Sydent < 2.3.0 - Server-Side Request Forgery via HTTP GET Request
CVSS 7.7
CVE-2021-28060
MEDIUM
Group Office 6.4.196 - Server-Side Request Forgery via URL Parameter
CVSS 5.3
CVE-2021-27905
CRITICAL
Apache Solr < 8.8.2 - Server-Side Request Forgery via ReplicationHandler masterUrl Parameter
CVSS 9.8
CVE-2021-29357
HIGH
OutSystems Platform Server SSRF via ECT Provider (10 < 10.0.1104.0, 11 < 11.9.0, LifeTime < 11.7.0)
CVSS 8.6
CVE-2021-20480
MEDIUM
IBM WebSphere Application Server <8.6 - SSRF
CVSS 6.5
CVE-2021-24150
HIGH
LikeBtn WordPress Like Button < 2.6.32 - Unauthenticated Server-Side Request Forgery
CVSS 7.5
CVE-2021-28941
MEDIUM
MagpieRSS 0.72 - Server-Side Request Forgery via Snoopy curl Request
CVSS 5.3
Details
Vulnerabilities
2,758