Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-918 · Server-side request forgeryDefinition on MITRE ↗Clear

20 results

CVE-2026-64849
2026-08-19
MLflow Server-Side Request Forgery Vulnerability
MLflow

MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.

CWE-918 · Server-side request forgery
Refsgithub.comgithub.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-09-02
CVE-2026-15409
2026-07-14
SonicWall SMA1000 Appliances Server-Side Request Forgery VulnerabilityRansomware
SonicWall

SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.

CWE-918 · Server-side request forgery
Refspsirt.global.sonicwall.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-07-17
CVE-2026-20230
2026-06-25
Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability
Cisco

Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.

CWE-918 · Server-side request forgery
Refscisco.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-06-28
CVE-2021-22054
2026-03-09
Omnissa Workspace ONE Server-Side Request Forgery
Omnissa / Workspace One UEM

Omnissa Workspace One UEM formerly known as VMware Workspace One UEM contains a server-side request forgery (SSRF) vulnerability that could allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.

CWE-918 · Server-side request forgery
Refsweb.archive.orgnvd.nist.gov
Federal remediation due 2026-03-23
CVE-2021-22175
2026-02-18
GitLab Server-Side Request Forgery (SSRF) Vulnerability
GitLab

GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled.

CWE-918 · Server-side request forgery
Refsgitlab.comnvd.nist.gov
Federal remediation due 2026-03-11
CVE-2020-7796
2026-02-17
Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
Synacor

Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery vulnerability if WebEx zimlet installed and zimlet JSP is enabled.

CWE-918 · Server-side request forgery
Refswiki.zimbra.comnvd.nist.gov
Federal remediation due 2026-03-10
CVE-2021-39935
2026-02-03
GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability
GitLab

GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Side Requests via the CI Lint API.

CWE-918 · Server-side request forgery
Refsabout.gitlab.comnvd.nist.gov
Federal remediation due 2026-02-24
CVE-2025-61884
2025-10-20
Oracle E-Business Suite Server-Side Request Forgery (SSRF) VulnerabilityRansomware
Oracle

Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.

CWE-918 · Server-side request forgery
Refsoracle.comnvd.nist.gov
Federal remediation due 2025-11-10
CVE-2021-21311
2025-09-29
Adminer Server-Side Request Forgery Vulnerability
Adminer

Adminer contains a server-side request forgery vulnerability that, when exploited, allows a remote attacker to obtain potentially sensitive information.

CWE-918 · Server-side request forgery
Refsgithub.comnvd.nist.gov
Federal remediation due 2025-10-20
CVE-2019-9621
2025-07-07
Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability
Synacor

Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) vulnerability via the ProxyServlet component.

CWE-918 · Server-side request forgeryCWE-807
Refswiki.zimbra.comwiki.zimbra.comnvd.nist.gov
Federal remediation due 2025-07-28
CVE-2024-21893
2024-01-31
Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) VulnerabilityRansomware
Ivanti

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (SSRF) vulnerability in the SAML component that allows an attacker to access certain restricted resources without authentication.

CWE-918 · Server-side request forgery
Refsforums.ivanti.comnvd.nist.gov
Federal remediation due 2024-02-02
CVE-2023-41763
2023-10-10
Microsoft Skype for Business Privilege Escalation Vulnerability
Microsoft

Microsoft Skype for Business contains an unspecified vulnerability that allows for privilege escalation.

CWE-918 · Server-side request forgery
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2023-10-31
CVE-2022-41040
2022-09-30
Microsoft Exchange Server Server-Side Request Forgery VulnerabilityRansomware
Microsoft

Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution.

CWE-918 · Server-side request forgery
Refsmsrc-blog.microsoft.comnvd.nist.gov
Federal remediation due 2022-10-21
CVE-2021-21973
2022-03-07
VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability
VMware

VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure.

CWE-20 · Improper input validationCWE-918 · Server-side request forgery
Refsnvd.nist.gov
Federal remediation due 2022-03-21
CVE-2021-21975
2022-01-18
VMware Server Side Request Forgery in vRealize Operations Manager APIRansomware
VMware

Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.

CWE-918 · Server-side request forgery
Refsnvd.nist.gov
Federal remediation due 2022-02-01
CVE-2021-40438
2021-12-01
Apache HTTP Server-Side Request Forgery (SSRF)Ransomware
Apache

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

CWE-918 · Server-side request forgery
Refsnvd.nist.gov
Federal remediation due 2021-12-15
CVE-2021-34473
2021-11-03
Microsoft Exchange Server Remote Code Execution VulnerabilityRansomware
Microsoft

Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.

CWE-918 · Server-side request forgery
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-27103
2021-11-03
Accellion FTA Server-Side Request Forgery (SSRF) VulnerabilityRansomware
Accellion

Accellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html.

CWE-918 · Server-side request forgery
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-26855
2021-11-03
Microsoft Exchange Server Remote Code Execution VulnerabilityRansomware
Microsoft

Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

CWE-918 · Server-side request forgery
RefsReference CISA's ED 21-02 (
Federal remediation due 2022-05-03
CVE-2021-21985
2021-11-03
VMware vCenter Server Improper Input Validation VulnerabilityRansomware
VMware

VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution.

CWE-20 · Improper input validationCWE-470CWE-918 · Server-side request forgery
Refsnvd.nist.gov
Federal remediation due 2021-11-17