cwe-918
Safeguard articles tagged "cwe-918" — guides, analysis, and best practices for software supply chain and application security.
27 articles
CVE-2025-61884: Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability
CVE-2025-61884 affects Oracle E-Business Suite and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-10-20.
CVE-2021-39935: GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability
CVE-2021-39935 affects GitLab Community and Enterprise Editions and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-02-03.
CVE-2020-7796: Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
CVE-2020-7796 affects Synacor Zimbra Collaboration Suite and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-02-17.
CVE-2021-22175: GitLab Server-Side Request Forgery (SSRF) Vulnerability
CVE-2021-22175 affects GitLab GitLab and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-02-18.
CVE-2021-22054: Omnissa Workspace ONE Server-Side Request Forgery
CVE-2021-22054 affects Omnissa Workspace One UEM and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-03-09.
CVE-2026-20230: Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability
CVE-2026-20230 affects Cisco Unified Communications Manager and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-06-25.
CVE-2026-15409: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
CVE-2026-15409 affects SonicWall SMA1000 Appliances and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-07-14.
CVE-2026-64849: MLflow Server-Side Request Forgery Vulnerability
CVE-2026-64849 affects MLflow MLflow and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-08-19.
CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
CVE-2026-83548 affects SonicWall SMA1000 Appliances and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-09-02.
CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability
CVE-2026-49869 affects Kestra Kestra OSS and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-09-02.
ProxyLogon (2021): The Exchange Server Vulnerabilities Behind the HAFNIUM Campaign
A factual retrospective on ProxyLogon (CVE-2021-26855 and related CVEs), a chain of Microsoft Exchange Server vulnerabilities exploited at scale in early 2021, compromising tens of thousands of organizations.
Capital One (2019): An SSRF Misconfiguration Breach in the Cloud
A factual retrospective on the 2019 Capital One breach, in which a server-side request forgery flaw against a misconfigured WAF allowed access to AWS metadata credentials and over 100 million customer records.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.