VulnSea

CWE-918

CVEs classified under CWE-918, newest first.

840 CVEsRSS

CVE-2025-61884High· 7.5CISA KEVPoC
11mo ago

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI)

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network …

▾ Abyssaloracle · configuratorEPSS 96%via NVD
CVE-2025-9868None
11mo ago

Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated remote attackers to exfiltrate proxy repository credentials via crafted HTTP requests.

Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated remote attackers to exfiltrate proxy repository credentials via crafted HTTP requests.

▾ SunlitEPSS 0.50%via NVD
CVE-2025-10211Medium· 6.3PoC
1y ago

A security vulnerability has been detected in yanyutao0402 ChanCMS 3.3.0

A security vulnerability has been detected in yanyutao0402 ChanCMS 3.3.0. The affected element is the function CollectController of the file /cms/collect/getArticle. The manipulation of the argument taskUrl leads to server-side request f…

▾ Twilightchancms · chancmsEPSS 0.70%via NVD
CVE-2025-51591Low· 3.7PoC
1y ago

A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe

A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe. Note: Some users have stated that Pandoc by default can retrieve and par…

▾ TwilightEPSS 0.66%via NVD
CVE-2025-23172High· 7.2
1y ago

The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints

The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints. However, the "Add Webhook" and "Test Webhook" functionalities can be abused by an authenticated user to sen…

▾ TwilightEPSS 1.1%via NVD
CVE-2025-5276High· 7.4
1y ago

Versions of the package mcp-markdownify-server before 1.0.0 are vulnerable to Server-Side Request Forgery (SSRF) via the Markdownify.get() function

Versions of the package mcp-markdownify-server before 1.0.0 are vulnerable to Server-Side Request Forgery (SSRF) via the Markdownify.get() function. An attacker can craft a prompt that, once accessed by the MCP host, can invoke the webpa…

▾ TwilightEPSS 0.40%via NVD
CVE-2025-0474High· 7.7
1y ago

Invoice Ninja is vulnerable to authenticated Server-Side Request Forgery (SSRF) allowing for arbitrary file read and network resource requests as the application user. This issue affects Invoice Ninja: from 5.8.56 through 5.11.23.

Invoice Ninja is vulnerable to authenticated Server-Side Request Forgery (SSRF) allowing for arbitrary file read and network resource requests as the application user. This issue affects Invoice Ninja: from 5.8.56 through 5.11.23.

▾ TwilightEPSS 0.40%via NVD
CVE-2024-42467Critical· 10.0
2y ago

openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu

openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. In versions 3.4.0.M4 through 4.2.0,, the proxy endpoint of openHAB's CometVisu add-on can be accessed without authenti…

▾ Midnightopenhab · openhab_web_interfaceEPSS 1.0%via NVD
CVE-2024-21527High· 8.2
2y ago

Versions of the package github.com/gotenberg/gotenberg/v8/pkg/gotenberg before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/pkg/modules/chromium before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/…

Versions of the package github.com/gotenberg/gotenberg/v8/pkg/gotenberg before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/pkg/modules/chromium before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/…

▾ TwilightEPSS 0.57%via NVD
CVE-2024-21893High· 8.2CISA KEV0dayPoC
2y ago

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without auth…

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without auth…

▾ Abyssalivanti · connect_secureEPSS 100%via NVD
CVE-2023-35175Critical· 9.8
3y ago

Certain HP LaserJet Pro print products are potentially vulnerable to Potential Remote Code Execution and/or Elevation of Privilege via Server-Side Request Forgery (SSRF) using the Web Service Eventing model.

Certain HP LaserJet Pro print products are potentially vulnerable to Potential Remote Code Execution and/or Elevation of Privilege via Server-Side Request Forgery (SSRF) using the Web Service Eventing model.

▾ Midnighthp · w1a75a_firmwareEPSS 1.4%via NVD
CVE-2023-26735High· 7.5
3y ago

blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface

blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface. This vulnerability allows attackers to detect intranet ports and services, as well as download resources. NOTE: this is disputed by third…

▾ Twilightprometheus · blackbox_exporterEPSS 0.89%via NVD
CVE-2022-42343Medium· 6.5
3y ago

Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read

Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A low-privilege authenticated attacker can force the app…

▾ Sunlitadobe · campaignEPSS 1.4%via NVD
CVE-2020-22983High· 8.1
4y ago

A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers to conduct a server-side request forgery (SSRF) attack via the srcURL parameter to the shortURL …

A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers to conduct a server-side request forgery (SSRF) attack via the srcURL parameter to the shortURL …

▾ Twilightmicrostrategy · microstrategy_webEPSS 2.4%via NVD
CVE-2020-27375Medium· 6.5
4y ago

Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Transmitting Write Requests and Chars.

Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Transmitting Write Requests and Chars.

▾ Sunlitdrtrustusa · icheck_connect_bp_monitor_bp_testing_118_firmwareEPSS 0.60%via NVD
CVE-2022-27245High· 8.8
4y ago

An issue was discovered in MISP before 2.4.156

An issue was discovered in MISP before 2.4.156. app/Model/Server.php does not restrict generateServerSettings to the CLI. This could lead to SSRF.

▾ Twilightmisp-project · mispEPSS 0.90%via NVD
CVE-2021-42637Critical· 9.8
4y ago

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server Side Request Forgery (SSRF) vulnerability.

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server Side Request Forgery (SSRF) vulnerability.

▾ Midnightprinterlogic · web_stackEPSS 2.3%via NVD
CVE-2021-37223Medium· 6.5
4y ago

Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php

Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php. Any authenticated user can create scheduled reports containing PDF screenshots of any view in the NagiosXI applicatio…

▾ Sunlitnagios · nagios_xiEPSS 5.0%via NVD
CVE-2021-40438Critical· 9.0CISA KEVPoC
5y ago

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

▾ Hadalredhat · jboss_core_servicesEPSS 100%via NVD
CVE-2021-34473Critical· 9.1CISA KEV0dayPoC
5y ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

▾ Hadalmicrosoft · exchange_serverEPSS 100%via NVD
CVE-2021-21985Critical· 9.8CISA KEVPoC
5y ago

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to por…

▾ Hadalvmware · vcenter_serverEPSS 100%via NVD
CVE-2017-17674Critical· 9.8
5y ago

BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion

BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinting, internal port scanning, Server Sid…

▾ Midnightbmc · remedy_mid-tierEPSS 2.1%via NVD
CVE-2021-21975High· 7.5CISA KEVPoC
5y ago

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal…

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal…

▾ Abyssalvmware · cloud_foundationEPSS 78%via NVD
CVE-2021-26855Critical· 9.1CISA KEV0dayPoC
5y ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

▾ Hadalmicrosoft · exchange_serverEPSS 100%via NVD
CVE-2021-21009High· 8.6
5y ago

Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier), 19.2.3 (and earlier) and 19.1.7 (and earlier) are affected by a server-side request forgery (SSRF) vulnerability

Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier), 19.2.3 (and earlier) and 19.1.7 (and earlier) are affected by a server-side request forgery (SSRF) vulnerability. Su…

▾ Twilightadobe · campaignEPSS 3.0%via NVD
CVE-2020-24815Medium· 6.5PoC
5y ago

A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2 allows authenticated users to access the content of internal network resources or leak files from the…

A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2 allows authenticated users to access the content of internal network resources or leak files from the…

▾ Twilightmicrostrategy · microstrategyEPSS 1.8%via NVD
CVE-2020-24881Critical· 9.8PoC
5y ago

SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.

SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.

▾ Abyssalenhancesoft · osticketEPSS 73%via NVD
CVE-2020-28043High· 7.5
5y ago

MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL.

MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL.

▾ Twilightmisp-project · mispEPSS 1.3%via NVD
CVE-2020-25466Critical· 9.8
5y ago

A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.

A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.

▾ Midnightcrmeb · crmebEPSS 2.6%via NVD
CVE-2017-7200Medium· 5.8
9y ago

An SSRF issue was discovered in OpenStack Glance before Newton

An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible to create images with a URL such as 'ht…

▾ Sunlitopenstack · glanceEPSS 2.1%via NVD
CWE-918 vulnerabilities (CVEs) — page 28 · VulnSea