Skip to main content

CWE archive

CWE-918 CVEs

Programmatic archive

3,131 CVEs tagged with CWE-918407 Critical, 1,014 High, 1,434 Medium, 273 Low, 3 Unrated.

CVE-2021-27738

Published Jan 6, 2022

All request mappings in `StreamingCoordinatorController.java` handling `/kylin/api/streaming_coordinator/*` REST API endpoints did not include any security checks, which allowed a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-44659

Published Dec 22, 2021

Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve a Server Side Request Forgery (SSRF).…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-22054

Published Dec 17, 2021

VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. Th…

CVSS 7.5 · High
evidence mentions
6
Buzz score
52.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2021-3959

Published Dec 16, 2021

A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security Tools allows an attacker to proxy requests to the relay serve…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39935

Published Dec 13, 2021

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.…

CVSS 6.8 · Medium
evidence mentions
3
Buzz score
45.4
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2021-37940

Published Dec 7, 2021

An information disclosure via GET request server-side request forgery vulnerability was discovered with the Workplace Search Github Enterprise Server integration. Using this vulne…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-40809

Published Dec 1, 2021

An issue was discovered in Jamf Pro before 10.32.0, aka PI-009921. An account can be granted incorrect privileges in response to authentication that uses specific sign-on workflow…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36327

Published Nov 30, 2021

Dell EMC Streaming Data Platform versions before 1.3 contain a Server Side Request Forgery Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerabil…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22049

Published Nov 24, 2021

The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A malicious actor with network access to…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-43780

Published Nov 24, 2021

Redash is a package for data visualization and sharing. In versions 10.0 and priorm the implementation of URL-loading data sources like JSON, CSV, or Excel is vulnerable to advanc…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23718

Published Nov 22, 2021

The package ssrf-agent before 1.0.5 are vulnerable to Server-side Request Forgery (SSRF) via the defaultIpChecker function. It fails to properly validate if the IP requested is pr…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22970

Published Nov 19, 2021

Concrete CMS (formerly concrete5) versions 8.5.6 and below and version 9.0.0 allow local IP importing causing the system to be vulnerable toa. SSRF attacks on the private LAN serv…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22969

Published Nov 19, 2021

Concrete CMS (formerly concrete5) versions below 8.5.7 has a SSRF mitigation bypass using DNS Rebind attack giving an attacker the ability to fetch cloud IAAS (ex AWS) IAM keys.To…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39303

Published Nov 12, 2021

The server in Jamf Pro before 10.32.0 has an SSRF vulnerability, aka PI-006352. NOTE: Jamf Nation will also publish an article about this vulnerability.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-43562

Published Nov 10, 2021

An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The extension fails to restrict the image download to the configured pixx.…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 2,601-2,625 of 3,131 CVEsPage 105 of 126