cwe-918
Safeguard articles tagged "cwe-918" — guides, analysis, and best practices for software supply chain and application security.
27 articles
CVE-2021-26855: Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-26855 affects Microsoft Exchange Server and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2021-34473: Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-34473 affects Microsoft Exchange Server and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2021-27103: Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability
CVE-2021-27103 affects Accellion FTA and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2021-40438: Apache HTTP Server-Side Request Forgery (SSRF)
CVE-2021-40438 affects Apache Apache and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-12-01.
CVE-2021-21975: VMware Server Side Request Forgery in vRealize Operations Manager API
CVE-2021-21975 affects VMware vRealize Operations Manager API and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-01-18.
CVE-2021-21985: VMware vCenter Server Improper Input Validation Vulnerability
CVE-2021-21985 affects VMware vCenter Server and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2021-21973: VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability
CVE-2021-21973 affects VMware vCenter Server and Cloud Foundation and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-03-07.
CVE-2022-41040: Microsoft Exchange Server Server-Side Request Forgery Vulnerability
CVE-2022-41040 affects Microsoft Exchange Server and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-09-30.
CVE-2023-41763: Microsoft Skype for Business Privilege Escalation Vulnerability
CVE-2023-41763 affects Microsoft Skype for Business and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2023-10-10.
CVE-2024-21893: Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability
CVE-2024-21893 affects Ivanti Connect Secure, Policy Secure, and Neurons and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-01-31.
CVE-2019-9621: Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability
CVE-2019-9621 affects Synacor Zimbra Collaboration Suite (ZCS) and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-07-07.
CVE-2021-21311: Adminer Server-Side Request Forgery Vulnerability
CVE-2021-21311 affects Adminer Adminer and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-09-29.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.