Skip to main content

CWE archive

CWE-918 CVEs

Programmatic archive

3,163 CVEs tagged with CWE-918408 Critical, 1,026 High, 1,442 Medium, 279 Low, 8 Unrated.

CVE-2022-30049

Published May 15, 2022

A Server-Side Request Forgery (SSRF) in Rebuild v2.8.3 allows attackers to obtain the real IP address and scan Intranet information via the fileurl parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-1379

Published May 14, 2022

URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-22983

Published May 13, 2022

A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers to conduct a server-side request forge…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29848

Published May 11, 2022

In Progress Ipswitch WhatsUp Gold 17.0.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke an API transaction that would allow them to read sensitive…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29847

Published May 11, 2022

In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to invoke an API transaction that would allow them to relay enc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29180

Published May 7, 2022

A vulnerability in which attackers could forge HTTP requests to manipulate the `charm` data directory to access or delete anything on the server. This has been patched and is avai…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1592

Published May 5, 2022

Server-Side Request Forgery in scout in GitHub repository clinical-genomics/scout prior to v4.42. An attacker could make the application perform arbitrary requests to fishing stea…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29942

Published May 4, 2022

Talend Administration Center has a vulnerability that allows an authenticated user to use the Service Registry 'Add' functionality to perform SSRF HTTP GET requests on URLs in the…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-28090

Published May 4, 2022

Jspxcms v10.2.0 allows attackers to execute a Server-Side Request Forgery (SSRF) via /cmscp/ext/collect/fetch_url.do?url=.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1239

Published May 2, 2022

The HubSpot WordPress plugin before 8.8.15 does not validate the proxy URL given to the proxy REST endpoint, which could allow users with the edit_posts capability (by default con…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-40822

Published May 2, 2022

GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-25850

Published May 1, 2022

The package github.com/hoppscotch/proxyscotch before 1.0.0 are vulnerable to Server-side Request Forgery (SSRF) when interceptor mode is set to proxy. It occurs when an HTTP reque…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29556

Published Apr 28, 2022

The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub integration provides several SSRF primitives that can exec…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-28117

Published Apr 28, 2022

A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the application to make arbitrary requests via injection of arbit…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-27469

Published Apr 26, 2022

Monstaftp v2.10.3 was discovered to allow attackers to execute Server-Side Request Forgery (SSRF).

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-27429

Published Apr 25, 2022

Jizhicms v1.9.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via /admin.php/Plugins/update.html.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-27311

Published Apr 25, 2022

Gibbon v3.4.4 and below allows attackers to execute a Server-Side Request Forgery (SSRF) via a crafted URL.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-24871

Published Apr 20, 2022

Shopware is an open commerce platform based on Symfony Framework and Vue. In affected versions an attacker can abuse the Admin SDK functionality on the server to read or update in…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24862

Published Apr 20, 2022

Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has Server-Side Request Forgery vulnerability. During the download verification…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24825

Published Apr 19, 2022

Smokescreen is a simple HTTP proxy that fogs over naughty URLs. The primary use case for Smokescreen is to prevent server-side request forgery (SSRF) attacks in which external att…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29153

Published Apr 19, 2022

HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP healt…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 2,551-2,575 of 3,163 CVEsPage 103 of 127