VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,225)

page 1 of 162
  • CVE-2021-21985CriKEVMay 26, 2021
    risk 0.93cvss 9.8epss 1.00

    The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute…

  • CVE-2021-22986CriKEVMar 31, 2021
    risk 0.93cvss 9.8epss 1.00

    On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution…

  • CVE-2021-34473CriKEVJul 14, 2021
    risk 0.88cvss 9.1epss 1.00

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2021-26855CriKEVMar 3, 2021
    risk 0.88cvss 9.1epss 1.00

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2022-41040HigKEVOct 3, 2022
    risk 0.86cvss 8.8epss 1.00

    Microsoft Exchange Server Elevation of Privilege Vulnerability

  • CVE-2021-40438CriKEVSep 16, 2021
    risk 0.85cvss 9.0epss 1.00

    A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

  • CVE-2021-27103CriKEVFeb 16, 2021
    risk 0.83cvss 9.8epss 0.11

    Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later.

  • CVE-2024-21893HigKEVJan 31, 2024
    risk 0.82cvss 8.2epss 1.00

    A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

  • CVE-2021-21975HigKEVMar 31, 2021
    risk 0.76cvss 7.5epss 0.78

    Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.

  • CVE-2020-7796CriKEVFeb 18, 2020
    risk 0.76cvss 9.8epss 0.84

    Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.

  • CVE-2026-20230HigKEVJun 3, 2026
    risk 0.75cvss 8.6epss 0.83

    A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected…

  • CVE-2025-61884HigKEVOct 12, 2025
    risk 0.75cvss 7.5epss 0.98

    Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…

  • CVE-2023-51467CriDec 26, 2023
    risk 0.74cvss 9.8epss 0.96

    The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code

  • CVE-2020-26948CriOct 10, 2020
    risk 0.74cvss 9.8epss 0.87

    Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.

  • CVE-2020-24881CriNov 2, 2020
    risk 0.73cvss 9.8epss 0.73

    SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.

  • CVE-2018-14728CriAug 3, 2018
    risk 0.73cvss 9.8epss 0.77

    upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.

  • CVE-2021-27905CriApr 13, 2021
    risk 0.71cvss 9.8epss 0.93

    The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate another ReplicationHandler on another Solr core to replicate index data into the local core. To prevent…

  • CVE-2021-33690CriSep 15, 2021
    risk 0.70cvss 9.9epss 0.68

    Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50The SAP NetWeaver Development Infrastructure Component Build Service allows a threat actor who…

  • CVE-2020-35313CriApr 20, 2021
    risk 0.70cvss 9.8epss 0.45

    A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attackers to execute arbitrary code via a crafted URL to the theme/plugin installer.

  • CVE-2022-1386CriMay 16, 2022
    risk 0.69cvss 9.8epss 0.72

    The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. The data returned is then reflected back in the application's response. This could be used to interact…