Vulnerabilities (CVE)

Filtered by CWE-918
Total 2983 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-4203 1 Ibm 1 Api Connect 2026-06-17 9.0 HIGH 9.8 CRITICAL
IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal can be exploited by app developers to download arbitrary files from the host OS and potentially carry out SSRF attacks. IBM X-Force ID: 159124.
CVE-2019-3905 1 Zohocorp 1 Manageengine Adselfservice Plus 2026-06-17 7.5 HIGH 10.0 CRITICAL
Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF.
CVE-2019-3809 1 Moodle 1 Moodle 2026-06-17 7.5 HIGH 6.5 MEDIUM
A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. This resulted in the possibility of blind SSRF via requests made by the page.
CVE-2019-3395 1 Atlassian 2 Confluence, Confluence Server 2026-06-17 7.5 HIGH 9.8 CRITICAL
The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), from version 6.7.0 before 6.8.5 (the fixed version for 6.8.x), and from version 6.9.0 before 6.9.3 (the fixed version for 6.9.x) allows remote attackers to send arbitrary HTTP and WebDAV requests from a Confluence Server or Data Center instance via Server-Side Request Forgery.
CVE-2019-25451 1 Phpmoadmin 1 Phpmoadmin 2026-06-17 N/A 8.8 HIGH
phpMoAdmin 1.1.5 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized database operations by crafting malicious requests. Attackers can trick authenticated users into submitting GET requests to moadmin.php with parameters like action, db, and collection to create, drop, or repair databases and collections without user consent.
CVE-2019-25290 2026-06-17 N/A 5.3 MEDIUM
Smartliving SmartLAN/G/SI <=6.x contains an unauthenticated server-side request forgery vulnerability in the GetImage functionality through the 'host' parameter. Attackers can exploit the onvif.cgi endpoint by specifying external domains to bypass firewalls and perform network enumeration through arbitrary HTTP requests.
CVE-2019-25251 1 Teradek 6 Vidiu, Vidiu Firmware, Vidiu Mini and 3 more 2026-06-17 N/A 6.5 MEDIUM
Teradek VidiU Pro 3.0.3 contains a server-side request forgery vulnerability in the management interface that allows attackers to manipulate GET parameters 'url' and 'xml_url'. Attackers can exploit this flaw to bypass firewalls, initiate network enumeration, and potentially trigger external HTTP requests to arbitrary destinations.
CVE-2019-20872 1 Mattermost 1 Mattermost Server 2026-06-17 2.1 LOW 5.5 MEDIUM
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. SSRF can attack local services.
CVE-2019-20474 1 Zohocorp 1 Manageengine Remote Access Plus 2026-06-17 4.0 MEDIUM 4.3 MEDIUM
An issue was discovered in Zoho ManageEngine Remote Access Plus 10.0.447. The service to test the mail-server configuration suffers from an authorization issue allowing a user with the Guest role (read-only access) to use and abuse it. One of the abuses allows performing network and port scan operations of the localhost or the hosts on the same network segment, aka SSRF.
CVE-2019-20408 1 Atlassian 1 Jira 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.
CVE-2019-20055 1 Liquidpixels 1 Liquifire Os 2026-06-17 6.4 MEDIUM 6.5 MEDIUM
LuquidPixels LiquiFire OS 4.8.0 allows SSRF via the call%3Durl substring followed by a URL in square brackets.
CVE-2019-1872 1 Cisco 1 Telepresence Video Communication Server 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
A vulnerability in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway Series software could allow an unauthenticated, remote attacker to cause an affected system to send arbitrary network requests. The vulnerability is due to improper restrictions on network services in the affected software. An attacker could exploit this vulnerability by sending malicious requests to the affected system. A successful exploit could allow the attacker to send arbitrary network requests sourced from the affected system.
CVE-2019-1679 1 Cisco 2 Telepresence Conductor, Telepresence Video Communication Server 2026-06-17 4.0 MEDIUM 5.0 MEDIUM
A vulnerability in the web interface of Cisco TelePresence Conductor, Cisco Expressway Series, and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to trigger an HTTP request from an affected server to an arbitrary host. This type of attack is commonly referred to as server-side request forgery (SSRF). The vulnerability is due to insufficient access controls for the REST API of Cisco Expressway Series and Cisco TelePresence VCS. An attacker could exploit this vulnerability by submitting a crafted HTTP request to the affected server. Versions prior to XC4.3.4 are affected.
CVE-2019-19999 1 Halo 1 Halo 2026-06-17 6.5 MEDIUM 7.2 HIGH
Halo before 1.2.0-beta.1 allows Server Side Template Injection (SSTI) because TemplateClassResolver.SAFER_RESOLVER is not used in the FreeMarker configuration.
CVE-2019-19835 1 Ruckuswireless 17 C110, E510, H320 and 14 more 2026-06-17 5.0 MEDIUM 7.5 HIGH
SSRF in AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote denial of service via the server attribute to the tools/_rcmdstat.jsp URI.
CVE-2019-19261 1 Gitlab 1 Gitlab 2026-06-17 6.8 MEDIUM 8.8 HIGH
GitLab Enterprise Edition (EE) 6.7 and later through 12.5 allows SSRF.
CVE-2019-18846 1 Open-xchange 1 Open-xchange Appsuite 2026-06-17 4.0 MEDIUM 5.0 MEDIUM
OX App Suite through 7.10.2 allows SSRF.
CVE-2019-18394 1 Igniterealtime 1 Openfire 2026-06-17 7.5 HIGH 9.8 CRITICAL
A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET requests.
CVE-2019-18379 1 Symantec 1 Messaging Gateway 2026-06-17 7.5 HIGH 7.3 HIGH
Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a server-side request forgery (SSRF) exploit, which is a type of issue that can let an attacker send crafted requests from the backend server of a vulnerable web application or access services available through the loopback interface.
CVE-2019-18355 1 Thycotic 1 Secret Server 2026-06-17 7.5 HIGH 9.8 CRITICAL
An SSRF issue was discovered in the legacy Web launcher in Thycotic Secret Server before 10.7.