Skip to main content

CWE archive

CWE-918 CVEs

Programmatic archive

2,938 CVEs tagged with CWE-918396 Critical, 930 High, 1,355 Medium, 255 Low, 2 Unrated.

CVE-2018-1000184

Published Jun 5, 2018

A server-side request forgery vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubPluginConfig.java that allows attackers with Overall/Read access to cause Jen…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000182

Published Jun 5, 2018

A server-side request forgery vulnerability exists in Jenkins Git Plugin 3.9.0 and older in AssemblaWeb.java, GitBlitRepositoryBrowser.java, Gitiles.java, TFS2013GitRepositoryBrow…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-9920

Published May 24, 2018

Server side request forgery exists in the runtime application in K2 smartforms 4.6.11 via a modified hostname in an https://*/Identity/STS/Forms/Scripts URL.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-11031

Published May 14, 2018

application/home/controller/debug.php in PHPRAP 1.0.4 through 1.0.8 has SSRF via the /debug URI, as demonstrated by an api[url]=file:////etc/passwd&api[method]=get POST request.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-9919

Published May 2, 2018

A web-accessible backdoor, with resultant SSRF, exists in Tp-shop 2.0.5 through 2.0.8, which allows remote attackers to obtain sensitive information, attack intranet hosts, or pos…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-9302

Published May 2, 2018

SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts v…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-8939

Published May 1, 2018

An SSRF issue was discovered in NmAPI.exe in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can submit specially crafted requests via the NmAPI executable to (1) gain…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-8801

Published Apr 25, 2018

GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-10174

Published Apr 20, 2018

Digital Guardian Management Console 7.1.2.0015 has an SSRF issue that allows remote attackers to read arbitrary files via file:// URLs, send TCP traffic to intranet hosts, or obta…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-10220

Published Apr 19, 2018

Glastopf 3.1.3-dev has SSRF, as demonstrated by the abc.php a parameter. NOTE: the vendor indicates that this is intentional behavior because the product is a web application hone…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14611

Published Apr 10, 2018

SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter, related to use of…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-14323

Published Apr 10, 2018

SSRF (Server Side Request Forgery) in getRemoteImage.php in Ueditor in Onethink V1.0 and V1.1 allows remote attackers to obtain sensitive information, attack intranet hosts, or po…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-18096

Published Apr 4, 2018

The OAuth status rest resource in Atlassian Application Links before version 5.2.7, from 5.3.0 before 5.3.4 and from 5.4.0 before 5.4.3 allows remote attackers with administrative…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16614

Published Mar 30, 2018

SSRF (Server Side Request Forgery) in tpshop 2.0.5 and 2.0.6 allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command exe…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1000138

Published Mar 23, 2018

I, Librarian version 4.8 and earlier contains a SSRF vulnerability in "url" parameter of getFromWeb in functions.php that can result in the attacker abusing functionality on the s…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-3990

Published Mar 20, 2018

The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to conduct server-side request forgery (SSRF) attacks or possibly c…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1000124

Published Mar 13, 2018

I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_string) that can result in an a…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-2370

Published Feb 14, 2018

Server Side Request Forgery (SSRF) vulnerability in SAP Central Management Console, BI Launchpad and Fiori BI Launchpad, 4.10, from 4.20, from 4.30, could allow a malicious user t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000056

Published Feb 9, 2018

Jenkins JUnit Plugin 1.23 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extra…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000055

Published Feb 9, 2018

Jenkins Android Lint Plugin 2.5 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000054

Published Feb 9, 2018

Jenkins CCM Plugin 3.1 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort
Showing 2,851-2,875 of 2,938 CVEsPage 115 of 118