Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-918 (服务端请求伪造(SSRF)) — Vulnerability Class 1496

1496 vulnerabilities classified as CWE-918 (服务端请求伪造(SSRF)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-43379 TruffleHog has a Blind SSRF in some Detectors — trufflehog 3.4 Low2024-08-19
CVE-2022-1751 Skitter Slideshow <= 2.5.2 - Unauthenticated Server-Side Request Forgery — Skitter Slideshow 7.2 High2024-08-17
CVE-2024-7743 wanglongcn ltcms API Endpoint downloadUrl server-side request forgery — ltcms 7.3 High2024-08-13
CVE-2024-7742 wanglongcn ltcms API Endpoint multiDownload server-side request forgery — ltcms 7.3 High2024-08-13
CVE-2024-7740 wanglongcn ltcms API Endpoint download server-side request forgery — ltcms 7.3 High2024-08-13
CVE-2024-38109 Azure Health Bot Elevation of Privilege Vulnerability — Azure Health Bot 9.1 Critical2024-08-13
CVE-2024-41737 Server-Side Request Forgery (SSRF) in SAP CRM ABAP (Insights Management) — SAP CRM ABAP (Insights Management) 5.0 Medium2024-08-13
CVE-2024-42467 CometVisu Backend for openHAB affected by SSRF/XSS — openhab-webui 10.0 Critical2024-08-09
CVE-2024-6522 Modern Events Calendar <= 7.12.1 - Authenticated (Subscriber+) Server Side Request Forgery — Modern Events Calendar 8.5 High2024-08-07
CVE-2024-38206 Microsoft Copilot Studio Information Disclosure Vulnerability — Microsoft Copilot Studio 8.5 High2024-08-06
CVE-2024-42352 Server-Side Request Forgery (SSRF) in nuxt-icon — icon 8.6 High2024-08-05
CVE-2024-36448 Apache IoTDB Workbench: SSRF Vulnerability (EOL) — Apache IoTDB Workbench 9.8AICriticalAI2024-08-05
CVE-2024-39637 WordPress Edubin theme <= 9.2.0 - Server Side Request Forgery (SSRF) vulnerability — Edubin 5.4 Medium2024-08-01
CVE-2024-38791 WordPress AI ENGINE plugin <= 2.4.7 - Server Side Request Forgery (SSRF) vulnerability — AI Engine: ChatGPT Chatbot 4.9 Medium2024-08-01
CVE-2024-2090 Remote Content Shortcode <= 1.5 - Authenticated (Contributor+) Server-Side Request Forgery — Remote Content Shortcode 6.4 Medium2024-08-01
CVE-2024-7330 YouDianCMS ydLib.php curl_exec server-side request forgery — YouDianCMS 6.3 Medium2024-07-31
CVE-2024-41118 streamlit-geospatial blind SSRF in pages/7_📦_Web_Map_Service.py — streamlit-geospatial 7.5 High2024-07-26
CVE-2024-41813 txtdot SSRF vulnerability in /proxy — txtdot 7.5 High2024-07-26
CVE-2024-41812 txtdot SSRF vulnerability in /get — txtdot 7.5 High2024-07-26
CVE-2024-6922 Server-Side Request Forgery in Automation 360 — Automation 360 8.2 -2024-07-26
CVE-2024-41668 cBioPortal Proxy Endpoint Vulnerabliity — cbioportal 8.3 High2024-07-23
CVE-2024-41664 Blind SSRF via Canarytoken Webhook — canarytokens 5.4 Medium2024-07-23
CVE-2024-37942 WordPress BerqWP plugin <= 1.7.5 - Unauthenticated Non-Blind Server Side Request Forgery (SSRF) vulnerability — BerqWP 7.2 High2024-07-22
CVE-2024-38723 WordPress Get Use APIs – JSON Content Importer plugin <= 1.5.6 - Server Side Request Forgery (SSRF) vulnerability — JSON Content Importer 6.4 Medium2024-07-22
CVE-2024-38728 WordPress Seraphinite Post .DOCX Source plugin <= 2.16.9 - Server Side Request Forgery (SSRF) vulnerability — Seraphinite Post .DOCX Source 7.1 High2024-07-22
CVE-2024-38730 WordPress Magical Addons For Elementor plugin <= 1.1.41 - Server Side Request Forgery (SSRF) vulnerability — Magical Addons For Elementor 4.9 Medium2024-07-22
CVE-2024-38758 WordPress WappPress plugin <= 6.0.4 - Blind Server Side Request Forgery (SSRF) vulnerability — WappPress 4.9 Medium2024-07-20
CVE-2024-29736 Apache CXF: SSRF vulnerability via WADL stylesheet parameter — Apache CXF 9.1 -2024-07-19
CVE-2024-21527 Gotenberg 安全漏洞 — github.com/gotenberg/gotenberg/v8/pkg/gotenberg 8.2 High2024-07-19
CVE-2024-40898 Apache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows — Apache HTTP Server 7.5AIHighAI2024-07-18

Vulnerabilities classified as CWE-918 (服务端请求伪造(SSRF)) represent 1496 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.