Skip to content
Noroxi

CWE-918 · 3,408 records

Server-Side Request Forgery (SSRF)

CVEs in this class

3,413 records

  • The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check pl

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    vmware · vcenter serverMay 26, 2021

  • On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    f5 · big-ip access policy managerMar 31, 2021

  • Microsoft Exchange Server Remote Code Execution Vulnerability

    CriticalCVSS 9.1KEVWeaponizedEPSS 100%

    microsoft · exchange serverJul 14, 2021

  • A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.

    CriticalCVSS 9.0KEVWeaponizedEPSS 100%

    resf · rocky linuxSep 16, 2021

  • Microsoft Exchange Server Remote Code Execution Vulnerability

    CriticalCVSS 9.1KEVWeaponizedEPSS 100%

    microsoft · exchange serverMar 2, 2021

  • Microsoft Exchange Server Elevation of Privilege Vulnerability

    HighCVSS 8.8KEVWeaponizedEPSS 100%

    microsoft · exchange serverOct 2, 2022

  • Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.

    CriticalCVSS 9.8KEVWeaponizedEPSS 84%

    synacor · zimbra collaboration suiteFeb 18, 2020

  • A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x)

    HighCVSS 8.2KEVWeaponizedEPSS 100%

    ivanti · connect secureJan 31, 2024

  • VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    vmware · workspace one uem consoleDec 17, 2021

  • Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability

    HighCVSS 8.6KEVWeaponizedEPSS 88%

    cisco · unified communications managerJun 3, 2026

  • Adminer is an open-source database management in a single PHP file.

    HighCVSS 7.2KEVWeaponizedEPSS 98%

    adminer · adminerFeb 11, 2021

  • When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions

    CriticalCVSS 9.8KEVWeaponizedEPSS 53%

    gitlab · gitlabJun 11, 2021

  • Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3

    HighCVSS 7.5KEVWeaponizedEPSS 81%

    synacor · zimbra collaboration suiteApr 30, 2019

  • Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access

    HighCVSS 7.5KEVWeaponizedEPSS 78%

    vmware · cloud foundationMar 31, 2021

  • CVE-2023-41763
    78This week

    Skype for Business Elevation of Privilege Vulnerability

    MediumCVSS 5.3KEVWeaponizedEPSS 90%

    microsoft · skype for business serverOct 10, 2023

  • CVE-2021-21973
    77This week

    The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Serv

    MediumCVSS 5.3KEVWeaponizedEPSS 88%

    vmware · cloud foundationFeb 24, 2021

  • CVE-2016-3718
    75This week

    The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request

    MediumCVSS 5.5KEVWeaponizedEPSS 77%

    imagemagick · imagemagickMay 5, 2016

  • CVE-2021-27103
    72This week

    Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html.

    CriticalCVSS 9.8KEVWeaponizedEPSS 11%

    accellion · ftaFeb 16, 2021

  • CVE-2026-15409
    72This week

    A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface.

    CriticalCVSS 10.0KEVWeaponizedEPSS 7%

    sonicwall · sma6210 firmwareJul 14, 2026

  • CVE-2021-39935
    71This week

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before

    HighCVSS 7.5KEVWeaponizedEPSS 36%

    gitlab · gitlabDec 13, 2021

  • CVE-2026-64849
    70This week

    MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)

    CriticalCVSS 9.3KEVWeaponizedEPSS 10%

    lfprojects · mlflowAug 17, 2026

  • CVE-2023-51467
    68This week

    Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability

    CriticalCVSS 9.8WeaponizedEPSS 96%

    apache · ofbizDec 26, 2023

  • CVE-2021-27905
    67This week

    SSRF vulnerability with the Replication handler

    CriticalCVSS 9.8Proof of conceptEPSS 93%

    apache · solrApr 13, 2021

  • CVE-2020-26948
    65This week

    Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.

    CriticalCVSS 9.8WeaponizedEPSS 87%

    emby · embyOct 10, 2020

  • CVE-2023-48022
    64This week

    Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API.

    CriticalCVSS 9.8WeaponizedEPSS 84%

    anyscale · rayNov 28, 2023

All vulnerability classes