Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-918

Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

2,950
Assigned CVEs
28th
Commonality Rank
7.0
Avg CVSS
0.7%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-918 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 22, 2003
23 years ago
Most Recent CVE
Jul 24, 2026
0 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

2,950 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-22986CRITICAL
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.
Mar 31, 20219.899YESYES
CVE-2021-26855CRITICAL
Microsoft Exchange Server Remote Code Execution Vulnerability
Mar 3, 20219.899YESYES
CVE-2025-61884HIGH
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vu
Oct 12, 20257.598YESYES
CVE-2024-21893HIGH
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an att
Jan 31, 20248.298YESYES
CVE-2021-34473CRITICAL
Microsoft Exchange Server Remote Code Execution Vulnerability
Jul 14, 20219.898YESYES
CVE-2021-21985CRITICAL
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCe
May 26, 20219.898YESYES
CVE-2022-41040HIGH
Microsoft Exchange Server Elevation of Privilege Vulnerability
Oct 3, 20228.897YESYES
CVE-2021-22054HIGH
VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. Thi
Dec 17, 20217.597YESYES
CVE-2021-40438CRITICAL
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
Sep 16, 20219.097YESYES
CVE-2019-9621HIGH
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet compon
Apr 30, 20197.597YESYES
View all 2,950 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
10%
4.0-4.9
16%
19%
5.0-5.9
18%
16%
6.0-6.9
23%
26%
7.0-7.9
14%
11%
8.0-8.9
17%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
21 CVEs
0.7% of CVEs· 88th percentile
Metasploit
16 CVEs
0.5% of CVEs· 84th percentile
Nuclei
149 CVEs
5.1% of CVEs· 95th percentile
ExploitDB
43 CVEs
1.5% of CVEs· 85th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products