CWE-918
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
2,758 vulnerabilities with CWE-918
CVE-2020-35970
HIGH
YzmCMS 5.8 - Server-Side Request Forgery Allows Arbitrary File Read
CVSS 7.5
CVE-2020-14328
LOW
Ansible Tower < 3.7.2 - Server-Side Request Forgery via URL Processing
CVSS 3.3
CVE-2020-14327
MEDIUM
Ansible Tower < 3.6.5 - Server-Side Request Forgery via Lookup Credential Test Feature
CVSS 5.5
CVE-2020-29445
MEDIUM
Confluence Server <7.4.8 & <7.5.0-7.11.0 - SSRF
CVSS 4.3
CVE-2020-28943
MEDIUM
Open-xchange Appsuite < 7.10.4 - SSRF
CVSS 6.5
CVE-2020-22002
HIGH
Inim Smartliving SmartLAN/G/SI <=6.x - Unauthenticated Server-Side Request Forgery via GetImage Host Parameter
CVSS 7.5
CVE-2020-35313
CRITICAL
WonderCMS 3.1.3 - Code Execution via Theme Installer SSRF
CVSS 9.8
CVE-2020-24140
HIGH
wcms 0.3.2 - Server-Side Request Forgery via pagename Parameter
CVSS 8.3
CVE-2020-24139
HIGH
wcms 0.3.2 - Server-Side Request Forgery via wex/cssjs.php Path Parameter
CVSS 8.3
CVE-2020-19613
HIGH
FlyCMS 20190503 - Server-Side Request Forgery via saveUrlAs Function
CVSS 7.5
CVE-2020-15809
MEDIUM
SpinetiX DSOS HMP350 HMP300 DiVA HMP400 HMP400W < 4.5.2 - Server-Side Request Forgery and Path Traversal
CVSS 6.5
CVE-2020-4882
MEDIUM
IBM Planning Analytics 2.0 - Server-Side Request Forgery via User-Controlled URL
CVSS 6.1
CVE-2020-5014
MEDIUM
IBM DataPower Gateway 10.0.0.0-10.0.1.0 - Authenticated Remote Code Execution via Server-Side Request Forgery
CVSS 6.7
CVE-2020-12529
MEDIUM
mbCONNECT24 and mymbCONNECT24 - LDAP Access Check Server-Side Request Forgery
CVSS 5.8
CVE-2020-23534
CRITICAL
masterlab 2.1.5 - Server-Side Request Forgery via Upgrade.php Source Parameter
CVSS 9.8
CVE-2020-11988
HIGH
Apache XmlGraphics Commons < 2.4 - Server-Side Request Forgery via XMPParser
CVSS 8.2
CVE-2020-11987
HIGH
Apache Batik < 1.13 - Server-Side Request Forgery via NodePickerPanel
CVSS 8.2
CVE-2020-8902
LOW
Rendertron < 3.0.0 - Server-Side Request Forgery via Headless Chrome Process
CVSS 3.5
CVE-2020-36232
MEDIUM
atlassian-gadgets < 4.2.37, 4.3.0-4.3.13, 4.3.2.0-4.3.2.3, 4.4.0-4.4.11, 5.0.0 SSRF via MessageBundleWhiteList
CVSS 5.0
CVE-2020-10252
HIGH
owncloud < 10.4.0 - Authenticated Server-Side Request Forgery via Files Sharing External Remote Parameter
CVSS 8.3
CVE-2020-28463
MEDIUM
reportlab < 3.5.55 - Server-Side Request Forgery via IMG Tag
CVSS 6.5
CVE-2020-35561
MEDIUM
mbconnect24, mymbconnect24, myrex24, and myrex24.virtual < 2.11.2 - SSRF in HA Module
CVSS 5.3
CVE-2020-35558
HIGH
Mbconnectline Mbconnect24 < 2.11.2 - SSRF
CVSS 7.5
CVE-2020-35667
HIGH
JetBrains TeamCity < 2020.2.85695 - Server-Side Request Forgery
CVSS 7.5
CVE-2020-4787
LOW
IBM QRadar SIEM 7.3.0-7.3.3, 7.4.0-7.4.2 SSRF
CVSS 2.3
Details
Vulnerabilities
2,758