İçeriğe atla
Noroxi

CWE-918 · 3.408 kayıt

Server-Side Request Forgery (SSRF)

Bu sınıftaki CVE’ler

3.413 kayıt

  • The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check pl

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    vmware · vcenter server26 May 2021

  • On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    f5 · big-ip access policy manager31 Mar 2021

  • Microsoft Exchange Server Remote Code Execution Vulnerability

    KritikCVSS 9,1KEVSilahlaştırılmışEPSS %100

    microsoft · exchange server14 Tem 2021

  • A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.

    KritikCVSS 9,0KEVSilahlaştırılmışEPSS %100

    resf · rocky linux16 Eyl 2021

  • Microsoft Exchange Server Remote Code Execution Vulnerability

    KritikCVSS 9,1KEVSilahlaştırılmışEPSS %100

    microsoft · exchange server2 Mar 2021

  • Microsoft Exchange Server Elevation of Privilege Vulnerability

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %100

    microsoft · exchange server2 Eki 2022

  • Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %84

    synacor · zimbra collaboration suite18 Şub 2020

  • A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x)

    YüksekCVSS 8,2KEVSilahlaştırılmışEPSS %100

    ivanti · connect secure31 Oca 2024

  • VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100

    vmware · workspace one uem console17 Ara 2021

  • Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability

    YüksekCVSS 8,6KEVSilahlaştırılmışEPSS %88

    cisco · unified communications manager3 Haz 2026

  • Adminer is an open-source database management in a single PHP file.

    YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %98

    adminer · adminer11 Şub 2021

  • When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %53

    gitlab · gitlab11 Haz 2021

  • Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %81

    synacor · zimbra collaboration suite30 Nis 2019

  • Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %78

    vmware · cloud foundation31 Mar 2021

  • CVE-2023-41763
    78Bu hafta

    Skype for Business Elevation of Privilege Vulnerability

    OrtaCVSS 5,3KEVSilahlaştırılmışEPSS %90

    microsoft · skype for business server10 Eki 2023

  • CVE-2021-21973
    77Bu hafta

    The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Serv

    OrtaCVSS 5,3KEVSilahlaştırılmışEPSS %88

    vmware · cloud foundation24 Şub 2021

  • CVE-2016-3718
    75Bu hafta

    The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request

    OrtaCVSS 5,5KEVSilahlaştırılmışEPSS %77

    imagemagick · imagemagick5 May 2016

  • CVE-2021-27103
    72Bu hafta

    Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %11

    accellion · fta16 Şub 2021

  • CVE-2026-15409
    72Bu hafta

    A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface.

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %7

    sonicwall · sma6210 firmware14 Tem 2026

  • CVE-2021-39935
    71Bu hafta

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %36

    gitlab · gitlab13 Ara 2021

  • CVE-2026-64849
    70Bu hafta

    MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)

    KritikCVSS 9,3KEVSilahlaştırılmışEPSS %10

    lfprojects · mlflow17 Ağu 2026

  • CVE-2023-51467
    68Bu hafta

    Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability

    KritikCVSS 9,8SilahlaştırılmışEPSS %96

    apache · ofbiz26 Ara 2023

  • CVE-2021-27905
    67Bu hafta

    SSRF vulnerability with the Replication handler

    KritikCVSS 9,8Kavram kanıtıEPSS %93

    apache · solr13 Nis 2021

  • CVE-2020-26948
    65Bu hafta

    Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.

    KritikCVSS 9,8SilahlaştırılmışEPSS %87

    emby · emby10 Eki 2020

  • CVE-2023-48022
    64Bu hafta

    Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API.

    KritikCVSS 9,8SilahlaştırılmışEPSS %84

    anyscale · ray28 Kas 2023

Tüm zafiyet sınıfları