Перейти к содержимому
Noroxi

CWE-300 · 57 записей

Channel Accessible by Non-Endpoint

CVE этого класса

57 записей

  • CVE-2017-7480
    40В плане

    rkhunter versions before 1.4.4 are vulnerable to file download over insecure channel when doing mirror update resulting into potential remot

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    rootkit hunter project · rootkit hunter21 июл. 2017 г.

  • CVE-2019-3793
    39Наблюдать

    Invitations Service supports HTTP connections

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    pivotal software · application service24 апр. 2019 г.

  • CVE-2026-74232
    37Наблюдать

    Zbtlink MQWrt yunmgrd Cloud C2 Implant

    КритическаяCVSS 9,3Эксплойта нетEPSS 1 %

    zbtlink · l3_v2_827 авг. 2026 г.

  • CVE-2025-54792
    37Наблюдать

    LocalSend is Vulnerable to Man-in-the-Middle Attacks, Leading to File Interception

    КритическаяCVSS 9,3Эксплойта нетEPSS 0 %

    localsend · localsend1 авг. 2025 г.

  • CVE-2023-31004
    36Наблюдать

    IBM Security Access Manager Container gain access

    КритическаяCVSS 9,0Эксплойта нетEPSS 1 %

    ibm · security verify access2 февр. 2024 г.

  • CVE-2026-12991
    34Наблюдать

    Multiple vulnerabilities in Ghost Robotics' Vision 60

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    ghost robotics · vision 6027 июл. 2026 г.

  • CVE-2017-12150
    33Наблюдать

    It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration

    ВысокаяCVSS 7,4Эксплойта нетEPSS 13 %

    samba · samba26 июл. 2018 г.

  • CVE-2018-0025
    32Наблюдать

    Junos OS: SRX Series: Credentials exposed when using HTTP and HTTPS Firewall Pass-through User Authentication

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    juniper · junos11 июл. 2018 г.

  • CVE-2019-5456
    32Наблюдать

    SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 and their actual SMTP

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    ui · unifi controller30 июл. 2019 г.

  • CVE-2021-41033
    32Наблюдать

    In all released versions of Eclipse Equinox, at least until version 4.21 (September 2021), installation can be vulnerable to man-in-the-midd

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    eclipse · equinox13 сент. 2021 г.

  • CVE-2021-21953
    32Наблюдать

    An authentication bypass vulnerability exists in the process_msg() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h.

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    anker · eufy homebase 2 firmware22 дек. 2021 г.

  • CVE-2018-13298
    32Наблюдать

    Channel accessible by non-endpoint vulnerability in privacy page in Synology Android Moments before 1.2.3-199 allows man-in-the-middle attac

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    synology · moments1 апр. 2019 г.

  • CVE-2020-11024
    32Наблюдать

    Man-in-the-middle attack in Moonlight iOS/tvOS

    ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %

    moonlight-stream · moonlight29 апр. 2020 г.

  • CVE-2025-31214
    32Наблюдать

    This issue was addressed through improved state management.

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    apple · ipados12 мая 2025 г.

  • CVE-2024-31206
    32Наблюдать

    Use of Unencrypted HTTP Request in dectalk-tts

    ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %

    jstnmcbrd · dectalk-tts4 апр. 2024 г.

  • CVE-2024-36553
    32Наблюдать

    Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h is vulnerable to MITM attack.

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    6 февр. 2025 г.

  • GHSA-j3rq-4xjw-xg63
    32Наблюдать

    Go package github.com/edgelesssys/marblerun CLI commands susceptible to MITM attacks

    ВысокаяCVSS 8,0Эксплойта нет

    Go · github.com/edgelesssys/marblerun4 дек. 2023 г.

  • CVE-2021-32926
    31Наблюдать

    When an authenticated password change request takes place, this vulnerability could allow the attacker to intercept the message that include

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    rockwellautomation · micro800 firmware3 июн. 2021 г.

  • CVE-2025-20122
    31Наблюдать

    Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    cisco · catalyst sd-wan manager7 мая 2025 г.

  • CVE-2017-12151
    30Наблюдать

    A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3

    ВысокаяCVSS 7,4Эксплойта нетEPSS 5 %

    samba · samba27 июл. 2018 г.

  • CVE-2017-15086
    30Наблюдать

    It was discovered that the fix for CVE-2017-12151 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHE

    ВысокаяCVSS 7,4Эксплойта нетEPSS 2 %

    redhat · gluster storage8 нояб. 2017 г.

  • CVE-2021-22909
    30Наблюдать

    A vulnerability found in EdgeMAX EdgeRouter V2.0.9 and earlier could allow a malicious actor to execute a man-in-the-middle (MitM) attack du

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    ui · edgemax edgerouter firmware27 мая 2021 г.

  • CVE-2024-50565
    30Наблюдать

    A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    fortinet · fortiweb8 апр. 2025 г.

  • CVE-2023-38272
    30Наблюдать

    IBM Cloud Pak System information disclosure

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    ibm · cloud pak system27 мар. 2025 г.

  • CVE-2024-12602
    30Наблюдать

    Identity verification vulnerability in the ParamWatcher module Impact: Successful exploitation of this vulnerability may affect service conf

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    huawei · harmonyos6 февр. 2025 г.

Все классы уязвимостей