The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Volume of CVEs assigned to CWE-918 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
2,950 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-22986CRITICAL On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7. | Mar 31, 2021 | 9.8 | 99 | YES | YES |
CVE-2021-26855CRITICAL Microsoft Exchange Server Remote Code Execution Vulnerability | Mar 3, 2021 | 9.8 | 99 | YES | YES |
CVE-2025-61884HIGH Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vu | Oct 12, 2025 | 7.5 | 98 | YES | YES |
CVE-2024-21893HIGH A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an att | Jan 31, 2024 | 8.2 | 98 | YES | YES |
CVE-2021-34473CRITICAL Microsoft Exchange Server Remote Code Execution Vulnerability | Jul 14, 2021 | 9.8 | 98 | YES | YES |
CVE-2021-21985CRITICAL The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCe | May 26, 2021 | 9.8 | 98 | YES | YES |
CVE-2022-41040HIGH Microsoft Exchange Server Elevation of Privilege Vulnerability | Oct 3, 2022 | 8.8 | 97 | YES | YES |
CVE-2021-22054HIGH VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. Thi | Dec 17, 2021 | 7.5 | 97 | YES | YES |
CVE-2021-40438CRITICAL A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. | Sep 16, 2021 | 9.0 | 97 | YES | YES |
CVE-2019-9621HIGH Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet compon | Apr 30, 2019 | 7.5 | 97 | YES | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.