VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,679)

page 1 of 184
  • CVE-2021-21985CriKEVMay 26, 2021
    risk 0.93cvss 9.8epss 1.00

    The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute…

  • CVE-2021-22986CriKEVMar 31, 2021
    risk 0.93cvss 9.8epss 1.00

    On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution…

  • CVE-2021-34473CriKEVJul 14, 2021
    risk 0.88cvss 9.1epss 1.00

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2021-26855CriKEVMar 3, 2021
    risk 0.88cvss 9.1epss 1.00

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2022-41040HigKEVOct 3, 2022
    risk 0.86cvss 8.8epss 1.00

    Microsoft Exchange Server Elevation of Privilege Vulnerability

  • CVE-2021-40438CriKEVSep 16, 2021
    risk 0.85cvss 9.0epss 1.00

    A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

  • CVE-2021-27103CriKEVFeb 16, 2021
    risk 0.83cvss 9.8epss 0.11

    Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later.

  • CVE-2024-21893HigKEVJan 31, 2024
    risk 0.82cvss 8.2epss 1.00

    A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

  • CVE-2026-83548CriKEVSep 1, 2026
    risk 0.77cvss 10.0epss 0.09

    A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and…

  • CVE-2021-21975HigKEVMar 31, 2021
    risk 0.76cvss 7.5epss 0.78

    Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.

  • CVE-2026-20230HigKEVJun 3, 2026
    risk 0.75cvss 8.6epss 0.88

    A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected…

  • CVE-2025-61884HigKEVOct 12, 2025
    risk 0.75cvss 7.5epss 0.96

    Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…

  • CVE-2020-7796CriKEVFeb 18, 2020
    risk 0.75cvss 9.8epss 0.84

    Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.

  • CVE-2023-51467CriDec 26, 2023
    risk 0.74cvss 9.8epss 0.96

    The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code

  • CVE-2020-26948CriOct 10, 2020
    risk 0.74cvss 9.8epss 0.87

    Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.

  • CVE-2020-24881CriNov 2, 2020
    risk 0.73cvss 9.8epss 0.73

    SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.

  • CVE-2018-14728CriAug 3, 2018
    risk 0.73cvss 9.8epss 0.77

    upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.

  • CVE-2021-27905CriApr 13, 2021
    risk 0.71cvss 9.8epss 0.93

    The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate another ReplicationHandler on another Solr core to replicate index data into the local core. To prevent…

  • CVE-2026-49869CriKEVJun 26, 2026
    risk 0.70cvss 10.0epss 0.02

    Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Because the check is a suffix match rather…

  • CVE-2021-33690CriSep 15, 2021
    risk 0.70cvss 9.9epss 0.69

    Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50The SAP NetWeaver Development Infrastructure Component Build Service allows a threat actor who…