Fallos del tipo CWE-918

2172 resultados
CVE-2024-23825LOWTablePress SSRF vulnerability due to insufficient filtering of cloud provider hostsEPSS 0.5%CVE-2025-1521HIGHPostHog slack_incoming_webhook Server-Side Request Forgery Information Disclosure VulnerabilityEPSS 0.5%CVE-2022-4201LOWA blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 allows an attacker to cEPSS 0.5%CVE-2026-26339CRITICALHyland Alfresco Transformation Service Argument Injection RCEEPSS 0.5%CVE-2026-49345MEDIUMMercator CVE Configuration Vulnerable to Server-Side Request Forgery (SSRF)EPSS 0.5%CVE-2024-51665MEDIUMWordPress Magical Addons For Elementor plugin <= 1.2.1 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.5%CVE-2023-3958HIGHWP Remote Users Sync <= 1.2.12 - Authenticated (Subscriber+) Server Side Request ForgeryEPSS 0.5%CVE-2026-26137CRITICALMicrosoft Exchange Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-27018HIGHGotenberg: Chromium deny-list bypass via case-insensitive URL schemeEPSS 0.5%CVE-2024-1812HIGHEverest Forms <= 2.0.7 - Unauthenticated Server-Side Request Forgery via font_urlEPSS 0.5%CVE-2025-25297HIGHLabel Studio allows Server-Side Request Forgery in the S3 Storage EndpointEPSS 0.5%CVE-2024-1758MEDIUMSuperFaktura WooCommerce <= 1.40.3 - Authenticated (Subscriber+) Blind Server-Side Request ForgeryEPSS 0.5%CVE-2023-36925HIGHUnauthenticated blind SSRF in SAP Solution Manager (Diagnostics agent)EPSS 0.5%CVE-2024-13139MEDIUMwangl1989 mysiteforme FileController doContent server-side request forgeryEPSS 0.5%CVE-2026-44492HIGHAxios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)EPSS 0.5%CVE-2022-41609MEDIUMWordPress Better Messages plugin <= 1.9.10.68 - Server-Side Request Forgery (SSRF) vulnerabilityEPSS 0.5%CVE-2025-22603HIGHAutoGPT SSRF vulnerabilityEPSS 0.5%CVE-2025-0454HIGHSSRF Check Bypass in Requests Utility in significant-gravitas/autogptEPSS 0.5%CVE-2023-4624LOWServer-Side Request Forgery (SSRF) in bookstackapp/bookstackEPSS 0.5%CVE-2026-30828HIGHWallos: SSRF via url parameter leading to File TraversalEPSS 0.5%