Safeguard
Tag

cwe-918

Safeguard articles tagged "cwe-918" — guides, analysis, and best practices for software supply chain and application security.

27 articles

Vulnerability Analysis

CVE-2021-26855: Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2021-26855 affects Microsoft Exchange Server and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2021-34473: Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2021-34473 affects Microsoft Exchange Server and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2021-27103: Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability

CVE-2021-27103 affects Accellion FTA and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2021-40438: Apache HTTP Server-Side Request Forgery (SSRF)

CVE-2021-40438 affects Apache Apache and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-12-01.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2021-21975: VMware Server Side Request Forgery in vRealize Operations Manager API

CVE-2021-21975 affects VMware vRealize Operations Manager API and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-01-18.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2021-21985: VMware vCenter Server Improper Input Validation Vulnerability

CVE-2021-21985 affects VMware vCenter Server and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2021-21973: VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability

CVE-2021-21973 affects VMware vCenter Server and Cloud Foundation and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-03-07.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2022-41040: Microsoft Exchange Server Server-Side Request Forgery Vulnerability

CVE-2022-41040 affects Microsoft Exchange Server and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-09-30.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2023-41763: Microsoft Skype for Business Privilege Escalation Vulnerability

CVE-2023-41763 affects Microsoft Skype for Business and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2023-10-10.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2024-21893: Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability

CVE-2024-21893 affects Ivanti Connect Secure, Policy Secure, and Neurons and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-01-31.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2019-9621: Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability

CVE-2019-9621 affects Synacor Zimbra Collaboration Suite (ZCS) and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-07-07.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2021-21311: Adminer Server-Side Request Forgery Vulnerability

CVE-2021-21311 affects Adminer Adminer and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-09-29.

Sep 17, 20263 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.