CWE-454 · 4 records
External Initialization of Trusted Variables or Data Stores
CVEs in this class
4 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2026-54003No exploit | Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` headergetkirby · kirby · CWE-454 | Critical9.1 | — | 0.7% | Jul 9, 2026 |
32Monitor | CVE-2026-26148No exploit | Microsoft Azure AD SSH Login extension for Linux Elevation of Privilege Vulnerabilitymicrosoft · azure ad ssh login extension for linux · CWE-454 | High8.1 | — | 0.3% | Mar 10, 2026 |
25Monitor | CVE-2026-48980No exploit | pam_usb: getenv() used in PAM context allows environment variable injection into local-check logicmcdope · pam_usb · CWE-454 | Medium6.3 | — | 0.2% | Jun 18, 2026 |
22Monitor | CVE-2025-36244No exploit | IBM AIX privilege escalationibm · vios · CWE-454 | Medium5.5 | — | 0.1% | Sep 16, 2025 |
- CVE-2026-5400336Monitor
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
CriticalCVSS 9.1No exploitEPSS 1%getkirby · kirbyJul 9, 2026
- CVE-2026-2614832Monitor
Microsoft Azure AD SSH Login extension for Linux Elevation of Privilege Vulnerability
HighCVSS 8.1No exploitEPSS 0%microsoft · azure ad ssh login extension for linuxMar 10, 2026
- CVE-2026-4898025Monitor
pam_usb: getenv() used in PAM context allows environment variable injection into local-check logic
MediumCVSS 6.3No exploitEPSS 0%mcdope · pam_usbJun 18, 2026
- CVE-2025-3624422Monitor
IBM AIX privilege escalation
MediumCVSS 5.5No exploitEPSS 0%ibm · viosSep 16, 2025