İçeriğe atla
Noroxi

CWE-923 · 63 kayıt

Improper Restriction of Communication Channel to Intended Endpoints

Bu sınıftaki CVE’ler

63 kayıt

  • CVE-2019-17440
    40Planlayın

    PAN-OS on PA-7000 Series: Improper restriction of communication to Log Forwarding Card (LFC) allows root access

    KritikCVSS 9,8İstismar yokEPSS %2

    paloaltonetworks · pan-os20 Ara 2019

  • CVE-2026-62836
    40Planlayın

    Azure SQL Managed Instance Elevation of Privilege Vulnerability

    KritikCVSS 10,0İstismar yokEPSS %1

    microsoft · azure sql managed instance6 Ağu 2026

  • CVE-2024-41889
    39İzleyin

    Multiple Pimax products accept WebSocket connections from unintended endpoints.

    KritikCVSS 9,8İstismar yokEPSS %1

    pimax · pitool5 Ağu 2024

  • CVE-2017-3891
    38İzleyin

    In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default configuration of the QNX

    KritikCVSS 9,6İstismar yokEPSS %1

    blackberry · qnx software development platform14 Kas 2017

  • CVE-2026-34205
    38İzleyin

    Home Assistant: Unauthenticated App (Add-on) Endpoints Exposed to Local Network via Host Network Mode

    KritikCVSS 9,6İstismar yokEPSS %0

    home-assistant · home assistant operating system27 Mar 2026

  • CVE-2023-28078
    36İzleyin

    Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured.

    KritikCVSS 9,1İstismar yokEPSS %1

    dell · smartfabric os1015 Şub 2024

  • CVE-2022-43916
    36İzleyin

    IBM App Connect Enterprise Certified Container improper communications restriction

    KritikCVSS 9,1İstismar yokEPSS %0

    ibm · app connect enterprise certified container30 Oca 2025

  • CVE-2025-20261
    35İzleyin

    Cisco Integrated Management Controller Privilege Escalation Vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %0

    cisco · cisco unified computing system (managed)4 Haz 2025

  • CVE-2025-61939
    34İzleyin

    Columbia Weather Systems MicroServer Improper Restriction of Communication Channel to Intended Endpoints

    YüksekCVSS 8,7İstismar yokEPSS %0

    columbiaweather · weather microserver firmware7 Oca 2026

  • CVE-2024-24974
    33İzleyin

    The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker

    YüksekCVSS 7,5İstismar yokEPSS %10

    openvpn · openvpn8 Tem 2024

  • CVE-2025-29986
    33İzleyin

    Dell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Improper Restriction of Communication Channel to Intended Endpoints vulnera

    YüksekCVSS 8,3İstismar yokEPSS %0

    dell · common event enabler8 Nis 2025

  • CVE-2024-26131
    31İzleyin

    Element Android Intent Redirection

    YüksekCVSS 7,8İstismar yokEPSS %0

    element · element28 Şub 2024

  • CVE-2026-23664
    30İzleyin

    Azure IoT Explorer Information Disclosure Vulnerability

    YüksekCVSS 7,5İstismar yokEPSS %1

    microsoft · azure iot explorer10 Mar 2026

  • CVE-2024-34446
    30İzleyin

    Mullvad VPN through 2024.1 on Android does not set a DNS server in the blocking state (after a hard failure to create a tunnel), and thus DN

    YüksekCVSS 7,5İstismar yokEPSS %1

    3 May 2024

  • CVE-2024-47490
    30İzleyin

    Junos OS Evolved: ACX 7000 Series: Receipt of specific transit MPLS packets causes resources to be exhausted

    YüksekCVSS 7,7İstismar yokEPSS %1

    juniper · junos os evolved11 Eki 2024

  • CVE-2026-87734
    30İzleyin

    An issue was discovered in the utcp package before 0.0.6 for OCaml.

    YüksekCVSS 7,5İstismar yokEPSS %1

    ocaml · utcp9 Eyl 2026

  • CVE-2024-26013
    30İzleyin

    A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.

    YüksekCVSS 7,5İstismar yokEPSS %0

    fortinet · fortianalyzer8 Nis 2025

  • CVE-2025-23178
    30İzleyin

    Ribbon Communications - CWE-923: Improper Restriction of Communication Channel to Intended Endpoints

    YüksekCVSS 7,6İstismar yokEPSS %0

    ribbon communications · apollo 960829 Nis 2025

  • CVE-2026-59841
    30İzleyin

    A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 ma

    YüksekCVSS 7,5İstismar yokEPSS %0

    fortinet · fortisiem14 Tem 2026

  • CVE-2025-36180
    30İzleyin

    Inadequate Pod Communication Restrictions, affects watsonx.data

    YüksekCVSS 7,5İstismar yokEPSS %0

    ibm · watsonx.data30 Nis 2026

  • CVE-2024-47125
    30İzleyin

    Improper Restriction of Communication Channel to Intended Endpoints in goTenna Pro

    YüksekCVSS 7,6İstismar yokEPSS %0

    gotenna · gotenna pro26 Eyl 2024

  • CVE-2026-23904
    29İzleyin

    Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxy

    YüksekCVSS 7,3İstismar yokEPSS %1

    apache · kyuubi29 Tem 2026

  • CVE-2024-43571
    29İzleyin

    Sudo for Windows Spoofing Vulnerability

    YüksekCVSS 7,3İstismar yokEPSS %1

    microsoft · windows 11 24h28 Eki 2024

  • CVE-2024-6222
    29İzleyin

    In Docker Desktop before v4.29.0 an attacker who has gained access to the Docker Desktop VM through a container breakout can further escape to the host by passi

    YüksekCVSS 7,3İstismar yokEPSS %1

    docker · desktop9 Tem 2024

  • CVE-2026-13608
    29İzleyin

    OpenLDAP SASL authentication bypass

    YüksekCVSS 7,4İstismar yokEPSS %0

    haxx · curl6 Eyl 2026

Tüm zafiyet sınıfları