CVE Intelligence
Skip to main content

Weakness and search-intent cluster

Curated intelligence cluster

SSRF vulnerabilities

22 of 54 pages in this cluster are on CISA's KEV catalog, and 22 are past its remediation deadline.

Pages

54

Ransomware-linked

10

confirmed

Public PoC

46

repositories found

54 pages · showing 1–54 · sorted by kev listed ↓

Published CVE pages, sorted by KEV listed descending
TitleVendorSignals
CVE-2026-83548SonicWall SMA1000 Appliances Server-Side Request Forgery VulnerabilitySonicWall2026-09-022026-09-019%1010
CVE-2026-64849MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)mlflow+12026-08-192026-08-1710%9.312
CVE-2026-15409SonicWall SMA1000 Appliances Server-Side Request Forgery VulnerabilitySonicWall2026-07-142026-07-147%1020
CVE-2026-20230Cisco Unified Communications Manager Server-Side Request Forgery VulnerabilityCisco2026-06-252026-06-0388%8.616
CVE-2021-22054Omnissa Workspace ONE Server-Side Request ForgeryOmnissa2026-03-092021-12-17100%7.521
CVE-2021-22175GitLab Server-Side Request Forgery (SSRF) VulnerabilityGitLab2026-02-182021-06-1153%9.84
CVE-2020-7796Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery VulnerabilitySynacor2026-02-172020-02-1884%9.89
CVE-2021-39935GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) VulnerabilityGitLab2026-02-032021-12-1336%7.56
CVE-2025-61884Oracle E-Business Suite Server-Side Request Forgery (SSRF) VulnerabilityOracle2025-10-202025-10-1296%7.511222SOCRadar
CVE-2021-21311SSRF in adminervrana2025-09-292021-02-1198%7.2538SOCRadar
CVE-2019-9621Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) VulnerabilitySynacor2025-07-072019-04-3081%7.51
CVE-2024-21893Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) VulnerabilityIvanti2024-01-312024-01-31100%8.2292328SOCRadar
CVE-2023-41763Microsoft Skype for Business Privilege Escalation Vulnerabilitymicrosoft2023-10-102023-10-1090%5.3none yet
CVE-2022-41040Microsoft Exchange Server Elevation of Privilege VulnerabilityMicrosoft2022-09-302022-10-03100%8.8142978SOCRadar
CVE-2021-21973VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) VulnerabilityVMware2022-03-072021-02-2488%5.31
CVE-2021-21975VMware Server Side Request Forgery in vRealize Operations Manager APIVMware2022-01-182021-03-3178%7.51
CVE-2021-40438mod_proxy SSRFApache2021-12-012021-09-16100%94194SOCRadar
CVE-2021-34473Microsoft Exchange Server Remote Code Execution VulnerabilityMicrosoft2021-11-032021-07-14100%10449148SOCRadar
CVE-2021-27103Accellion FTA Server-Side Request Forgery (SSRF) VulnerabilityAccellion2021-11-032021-02-1611%9.8
CVE-2021-26855Microsoft Exchange Server Remote Code Execution VulnerabilityMicrosoft2021-11-032021-03-03100%7.561197315SOCRadar
CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution VulnerabilityF52021-11-032021-03-31100%9.8511134SOCRadar
CVE-2016-3718ImageMagick Server-Side Request Forgery (SSRF) VulnerabilityImageMagick2021-11-032016-05-0577%5.51
CVE-2026-102105Kiteworks Email Protection Gateway server-side request forgeryKiteworksn/a2026-09-30n/a9.1none yet
CVE-2026-102104Kiteworks Email Protection Gateway server-side request forgeryKiteworksn/a2026-09-30n/a9.1none yet
CVE-2026-102103Kiteworks Email Protection Gateway server-side request forgeryKiteworksn/a2026-09-30n/a9.1none yet
CVE-2026-102102Kiteworks Email Protection Gateway server-side request forgeryKiteworksn/a2026-09-30n/a9.1none yet
CVE-2026-102095Kiteworks Email Protection Gateway server-side request forgeryKiteworksn/a2026-09-30n/a9.1none yet
CVE-2026-101064Obot before v0.23.0 Server-Side Request Forgery via MCPobot-platformn/a2026-09-27n/a7.61
CVE-2026-100901athlon1600 youtube-downloader stream.php stream server-side request forgeryathlon1600n/a2026-09-28n/a7.32
CVE-2026-100850AzuraCast before 0.23.8 SSRF and Local File Read via Remote PlaylistAzuraCastn/a2026-09-27n/a7.72
CVE-2026-100567OpenClaw before 2026.8.1 DNS Rebinding via CDP HostnameOpenClawn/a2026-09-26n/a8.21
CVE-2026-100555OpenClaw before 2026.8.1 DNS Rebinding via attachment deliveryOpenClawn/a2026-09-26n/a7.11
CVE-2026-100391MediaFlow Proxy through 2.4.9 Server-Side Request Forgery via Incomplete Validationmhdzumairn/a2026-09-25n/a8.21
CVE-2026-81549DataStage on Cloud Pak for Data has several vulnerabilitiesIBMn/a2026-09-24n/a9.62
CVE-2026-80123Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Server-Side…Delln/a2026-09-090%7.31
CVE-2026-73058stoatchat before 0.15.0 SSRF via IPv6 unspecified address bypassstoatchatn/a2026-08-160%5.81
CVE-2026-57894Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository ExfiltrationGitea+1n/a2026-08-130%n/a1
CVE-2026-55526PraisonAI: SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)MervinPraison+1n/a2026-08-250%8.53
CVE-2026-54794Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerabilityDelln/a2026-08-190%7.210
CVE-2026-50143Actor MCP path authority injection leaks Apify tokenapify+1n/a2026-08-180%8.12
CVE-2026-49865Kimai has Server-Side Request Forgery in Invoice PDF Rendering via Markdown Image URLskimai+1n/a2026-09-110%5.32
CVE-2026-45123MyBB: IPv6 SSRFmybbn/a2026-08-180%4.329
CVE-2026-33990Docker Model Runner OCI Registry Client Vulnerable to Server-Side Request Forgery (SSRF)dockern/a2026-04-010%9.1none yet
CVE-2026-19751EnzoVezzaro mcp-dominican-layer parse-csv tool index.ts axios.get server-side request forgeryEnzoVezzaron/a2026-08-130%6.34
CVE-2026-19516CVE-2026-19516 CVE RecordGrafanan/a2026-08-110%9.17
CVE-2026-18952Missing Input Validation in Threat Intel Feed Parser in OpenSearch Security Analytics PluginAWS+1n/a2026-08-120%8.14
CVE-2026-18066IBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesIBMn/a2026-09-22n/a7.94
CVE-2026-17608WP Compress <= 7.10.09 - Cross-Site Request Forgery to Arbitrary Options Deletionaresitn/a2026-08-160%6.51
CVE-2026-15583SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL headerGrafanan/a2026-07-151%8.610
CVE-2026-12037Asset CleanUp: Page Speed Booster <= 1.4.0.5 - Authenticated (Administrator+) Server-Side Request Forgery via 'page_url' Parametergabelivann/a2026-09-25n/a5.54
CVE-2026-1641Wow Elements Addons for Elementor <= 1.11.2 - Authenticated (Contributor+) Server-Side Request Forgery via Changelog File Settingwowelementsn/a2026-09-190%6.568
CVE-2026-0532External Control of File Name or Path and Server-Side Request Forgery (SSRF) in Kibana Google Gemini ConnectorElasticn/a2026-01-140%8.67
CVE-2024-20404A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF…Ciscon/a2024-06-0523%5.38
CVE-2019-18394A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to…Unknown+1n/a2019-10-2432%9.87

Field coverage across these 54 pages: KEV listing date 22 · CVSS base score 53 · publication date 54 · EPSS 40 · threat-intel signals 8. Rows with no value on the column being sorted are listed last in both directions rather than counted as zero.

Reading a row

ransomware
CISA records known use in ransomware campaigns. Varies across this index, which is why it is on the row.
PoC
Public proof-of-concept repositories this deployment found on GitHub, and how many.
EPSS
FIRST's estimate of the probability the CVE is exploited in the next 30 days. Present on every record here.
CVSS
Base score, from scored sources only. "n/a" means no source scored it — not that the score is low.