Vulnerabilities (CVE)

Filtered by CWE-918
Total 3025 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2012-10018 1 Mapplic 1 Mapplic 2026-06-16 N/A 8.3 HIGH
The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and including 6.1, 1.0 respectively. This makes it possible for attackers to forgery requests coming from a vulnerable site's server and ultimately perform an XSS attack if requesting an SVG file.
CVE-2010-1637 4 Apple, Fedoraproject, Redhat and 1 more 7 Mac Os X, Mac Os X Server, Fedora and 4 more 2026-06-16 4.0 MEDIUM 6.5 MEDIUM
The Mail Fetch plugin in SquirrelMail 1.4.20 and earlier allows remote authenticated users to bypass firewall restrictions and use SquirrelMail as a proxy to scan internal networks via a modified POP3 port number.
CVE-2007-6758 1 Sencha 1 Ext Js 2026-06-16 5.0 MEDIUM 7.5 HIGH
Server-side request forgery (SSRF) vulnerability in feed-proxy.php in extjs 5.0.0.
CVE-2004-2061 1 Risearch 2 Risearch, Risearch Pro 2026-06-16 7.5 HIGH 9.8 CRITICAL
RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.
CVE-2002-1484 1 Siemens 1 Db4web 2026-06-16 7.5 HIGH 9.8 CRITICAL
DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a connection status in the resulting error message.