Fallos del tipo CWE-918

2173 resultados
CVE-2024-1978MEDIUMFriends <= 2.8.5 - Authenticated (Admin+) Blind Server-Side Request ForgeryEPSS 0.5%CVE-2025-13096HIGHXML eXternal Entity injection (XXE) vulnerability affect IBM Business Automation Workflow -EPSS 0.5%CVE-2024-40544HIGHPublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/#maintenance_sysTask/edit.EPSS 0.5%CVE-2026-46391HIGHHAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apisEPSS 0.5%CVE-2024-23336MEDIUMIncomplete disallowed remote addresses list in MyBBEPSS 0.5%CVE-2024-40718HIGHA server side request forgery vulnerability allows a low-privileged user to perform local privilege escalation through exploiting an SSRF vuEPSS 0.5%CVE-2025-8267HIGHVersions of the package ssrfcheck before 1.2.0 are vulnerable to Server-Side Request Forgery (SSRF) due to an incomplete denylist of IP addrEPSS 0.5%CVE-2024-4894MEDIUMITPison OMICARD EDM - Server-Side Request ForgeryEPSS 0.5%CVE-2026-42213MEDIUMSolidCAM-GPPL-IDE: Path traversal in `inc` directive enables file probing and NTLM-hash leakEPSS 0.5%CVE-2024-33864MEDIUMAn issue was discovered in linqi before 1.4.0.1 on Windows. There is SSRF via Document template generation; i.e., via remote images in proceEPSS 0.5%CVE-2026-42352HIGHpygeoapi 0.23.x: Unauthenticated SSRF via OGC API - Processes SubscriberEPSS 0.5%CVE-2025-0188MEDIUMSSRF in gaizhenbiao/chuanhuchatgptEPSS 0.5%CVE-2026-33039HIGHAVideo vulnerable to unauthenticated SSRF via HTTP redirect bypass in LiveLinks proxyEPSS 0.5%CVE-2025-67494CRITICALZITADEL Vulnerable to Unauthenticated Full-Read SSRF via V2 LoginEPSS 0.5%CVE-2025-25303MEDIUMServer-Side Request Forgery (SSRF) in MouseTooltipTranslatorEPSS 0.5%CVE-2023-46725HIGHFoodCoopShop Server-Side Request Forgery vulnerabilityEPSS 0.5%CVE-2025-2997MEDIUMzhangyanbo2007 youkefu url server-side request forgeryEPSS 0.5%CVE-2026-47938CRITICALAdobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)EPSS 0.4%CVE-2025-68616HIGHWeasyPrint Vulnerable to Server-Side Request Forgery (SSRF) Protection Bypass via HTTP RedirectEPSS 0.4%CVE-2022-25777MEDIUMServer-Side Request Forgery in Asset sectionEPSS 0.4%