Skip to main content

CWE archive

CWE-918 CVEs

Programmatic archive

3,138 CVEs tagged with CWE-918407 Critical, 1,016 High, 1,437 Medium, 275 Low, 3 Unrated.

CVE-2022-0870

Published Mar 11, 2022

Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.5.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-25031

Published Mar 11, 2022

Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24739

Published Mar 8, 2022

alltube is an html front end for youtube-dl. On releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Req…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-0767

Published Mar 7, 2022

Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-0766

Published Mar 7, 2022

Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-0528

Published Mar 3, 2022

Server-Side Request Forgery (SSRF) in GitHub repository transloadit/uppy prior to 3.3.1.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-25260

Published Feb 25, 2022

JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF).

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-24980

Published Feb 19, 2022

An issue was discovered in the Kitodo.Presentation (aka dif) extension before 2.3.2, 3.x before 3.2.3, and 3.3.x before 3.3.4 for TYPO3. A missing access check in an eID script al…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-0671

Published Feb 18, 2022

A flaw was found in vscode-xml in versions prior to 0.19.0. Schema download could lead to blind SSRF or DoS via a large file.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-20325

Published Feb 18, 2022

Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regression compared to the versions s…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-23644

Published Feb 16, 2022

BookWyrm is a decentralized social network for tracking reading habits and reviewing books. The functionality to load a cover via url is vulnerable to a server-side request forger…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24568

Published Feb 10, 2022

Novel-plus v3.6.0 was discovered to be vulnerable to Server-Side Request Forgery (SSRF) via user-supplied crafted input.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-25939

Published Feb 9, 2022

In ArangoDB, versions v3.7.0 through v3.9.0-alpha.1 have a feature which allows downloading a Foxx service from a publicly available URL. This feature does not enforce proper filt…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-45325

Published Feb 8, 2022

Server Side Request Forgery (SSRF) vulneraility exists in Gitea before 1.7.0 using the OpenID URL.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-0508

Published Feb 8, 2022

Server-Side Request Forgery (SSRF) in GitHub repository chocobozzz/peertube prior to f33e515991a32885622b217bf2ed1d1b0d9d6832

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23206

Published Feb 6, 2022

In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted POST request to /user/login/o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24129

Published Feb 4, 2022

The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insufficient restriction of the request_uri parameter. This allow…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-42637

Published Feb 2, 2022

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server Side Request Forgery (SSRF) vulnerability.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2022-22993

Published Jan 28, 2022

A limited SSRF vulnerability was discovered on Western Digital My Cloud devices that could allow an attacker to impersonate a server and reach any page on the server by bypassing…

CVSS 7.8 · High

CVE-2022-21697

Published Jan 25, 2022

Jupyter Server Proxy is a Jupyter notebook server extension to proxy web services. Versions of Jupyter Server Proxy prior to 3.2.1 are vulnerable to Server-Side Request Forgery (S…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 2,576-2,600 of 3,138 CVEsPage 104 of 126