CWE-923 · 63 kayıt
Improper Restriction of Communication Channel to Intended Endpoints
Bu sınıftaki CVE’ler
63 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2019-17440İstismar yok | PAN-OS on PA-7000 Series: Improper restriction of communication to Log Forwarding Card (LFC) allows root accesspaloaltonetworks · pan-os · CWE-923 | Kritik9,8 | — | %1,7 | 20 Ara 2019 |
40Planlayın | CVE-2026-62836İstismar yok | Azure SQL Managed Instance Elevation of Privilege Vulnerabilitymicrosoft · azure sql managed instance · CWE-923 | Kritik10,0 | — | %0,6 | 6 Ağu 2026 |
39İzleyin | CVE-2024-41889İstismar yok | Multiple Pimax products accept WebSocket connections from unintended endpoints.pimax · pitool · CWE-923 | Kritik9,8 | — | %0,7 | 5 Ağu 2024 |
38İzleyin | CVE-2017-3891İstismar yok | In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default configuration of the QNXblackberry · qnx software development platform · CWE-923 | Kritik9,6 | — | %1,3 | 14 Kas 2017 |
38İzleyin | CVE-2026-34205İstismar yok | Home Assistant: Unauthenticated App (Add-on) Endpoints Exposed to Local Network via Host Network Modehome-assistant · home assistant operating system · CWE-923 | Kritik9,6 | — | %0,3 | 27 Mar 2026 |
36İzleyin | CVE-2023-28078İstismar yok | Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured.dell · smartfabric os10 · CWE-923 | Kritik9,1 | — | %0,9 | 15 Şub 2024 |
36İzleyin | CVE-2022-43916İstismar yok | IBM App Connect Enterprise Certified Container improper communications restrictionibm · app connect enterprise certified container · CWE-923 | Kritik9,1 | — | %0,3 | 30 Oca 2025 |
35İzleyin | CVE-2025-20261İstismar yok | Cisco Integrated Management Controller Privilege Escalation Vulnerabilitycisco · cisco unified computing system (managed) · CWE-923 | Yüksek8,8 | — | %0,5 | 4 Haz 2025 |
34İzleyin | CVE-2025-61939İstismar yok | Columbia Weather Systems MicroServer Improper Restriction of Communication Channel to Intended Endpointscolumbiaweather · weather microserver firmware · CWE-923 | Yüksek8,7 | — | %0,3 | 7 Oca 2026 |
33İzleyin | CVE-2024-24974İstismar yok | The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attackeropenvpn · openvpn · CWE-923 | Yüksek7,5 | — | %9,8 | 8 Tem 2024 |
33İzleyin | CVE-2025-29986İstismar yok | Dell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Improper Restriction of Communication Channel to Intended Endpoints vulneradell · common event enabler · CWE-923 | Yüksek8,3 | — | %0,3 | 8 Nis 2025 |
31İzleyin | CVE-2024-26131İstismar yok | Element Android Intent Redirectionelement · element · CWE-923 | Yüksek7,8 | — | %0,5 | 28 Şub 2024 |
30İzleyin | CVE-2026-23664İstismar yok | Azure IoT Explorer Information Disclosure Vulnerabilitymicrosoft · azure iot explorer · CWE-923 | Yüksek7,5 | — | %1,0 | 10 Mar 2026 |
30İzleyin | CVE-2024-34446İstismar yok | Mullvad VPN through 2024.1 on Android does not set a DNS server in the blocking state (after a hard failure to create a tunnel), and thus DNCWE-923 | Yüksek7,5 | — | %0,6 | 3 May 2024 |
30İzleyin | CVE-2024-47490İstismar yok | Junos OS Evolved: ACX 7000 Series: Receipt of specific transit MPLS packets causes resources to be exhaustedjuniper · junos os evolved · CWE-923 | Yüksek7,7 | — | %0,6 | 11 Eki 2024 |
30İzleyin | CVE-2026-87734İstismar yok | An issue was discovered in the utcp package before 0.0.6 for OCaml.ocaml · utcp · CWE-923 | Yüksek7,5 | — | %0,5 | 9 Eyl 2026 |
30İzleyin | CVE-2024-26013İstismar yok | A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.fortinet · fortianalyzer · CWE-923 | Yüksek7,5 | — | %0,5 | 8 Nis 2025 |
30İzleyin | CVE-2025-23178İstismar yok | Ribbon Communications - CWE-923: Improper Restriction of Communication Channel to Intended Endpointsribbon communications · apollo 9608 · CWE-923 | Yüksek7,6 | — | %0,3 | 29 Nis 2025 |
30İzleyin | CVE-2026-59841İstismar yok | A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 mafortinet · fortisiem · CWE-923 | Yüksek7,5 | — | %0,2 | 14 Tem 2026 |
30İzleyin | CVE-2025-36180İstismar yok | Inadequate Pod Communication Restrictions, affects watsonx.dataibm · watsonx.data · CWE-923 | Yüksek7,5 | — | %0,2 | 30 Nis 2026 |
30İzleyin | CVE-2024-47125İstismar yok | Improper Restriction of Communication Channel to Intended Endpoints in goTenna Progotenna · gotenna pro · CWE-923 | Yüksek7,6 | — | %0,1 | 26 Eyl 2024 |
29İzleyin | CVE-2026-23904İstismar yok | Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxyapache · kyuubi · CWE-923 | Yüksek7,3 | — | %0,9 | 29 Tem 2026 |
29İzleyin | CVE-2024-43571İstismar yok | Sudo for Windows Spoofing Vulnerabilitymicrosoft · windows 11 24h2 · CWE-923 | Yüksek7,3 | — | %0,6 | 8 Eki 2024 |
29İzleyin | CVE-2024-6222İstismar yok | In Docker Desktop before v4.29.0 an attacker who has gained access to the Docker Desktop VM through a container breakout can further escape to the host by passidocker · desktop · CWE-923 | Yüksek7,3 | — | %0,6 | 9 Tem 2024 |
29İzleyin | CVE-2026-13608İstismar yok | OpenLDAP SASL authentication bypasshaxx · curl · CWE-923 | Yüksek7,4 | — | %0,5 | 6 Eyl 2026 |
- CVE-2019-1744040Planlayın
PAN-OS on PA-7000 Series: Improper restriction of communication to Log Forwarding Card (LFC) allows root access
KritikCVSS 9,8İstismar yokEPSS %2paloaltonetworks · pan-os20 Ara 2019
- CVE-2026-6283640Planlayın
Azure SQL Managed Instance Elevation of Privilege Vulnerability
KritikCVSS 10,0İstismar yokEPSS %1microsoft · azure sql managed instance6 Ağu 2026
- CVE-2024-4188939İzleyin
Multiple Pimax products accept WebSocket connections from unintended endpoints.
KritikCVSS 9,8İstismar yokEPSS %1pimax · pitool5 Ağu 2024
- CVE-2017-389138İzleyin
In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default configuration of the QNX
KritikCVSS 9,6İstismar yokEPSS %1blackberry · qnx software development platform14 Kas 2017
- CVE-2026-3420538İzleyin
Home Assistant: Unauthenticated App (Add-on) Endpoints Exposed to Local Network via Host Network Mode
KritikCVSS 9,6İstismar yokEPSS %0home-assistant · home assistant operating system27 Mar 2026
- CVE-2023-2807836İzleyin
Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured.
KritikCVSS 9,1İstismar yokEPSS %1dell · smartfabric os1015 Şub 2024
- CVE-2022-4391636İzleyin
IBM App Connect Enterprise Certified Container improper communications restriction
KritikCVSS 9,1İstismar yokEPSS %0ibm · app connect enterprise certified container30 Oca 2025
- CVE-2025-2026135İzleyin
Cisco Integrated Management Controller Privilege Escalation Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0cisco · cisco unified computing system (managed)4 Haz 2025
- CVE-2025-6193934İzleyin
Columbia Weather Systems MicroServer Improper Restriction of Communication Channel to Intended Endpoints
YüksekCVSS 8,7İstismar yokEPSS %0columbiaweather · weather microserver firmware7 Oca 2026
- CVE-2024-2497433İzleyin
The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker
YüksekCVSS 7,5İstismar yokEPSS %10openvpn · openvpn8 Tem 2024
- CVE-2025-2998633İzleyin
Dell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Improper Restriction of Communication Channel to Intended Endpoints vulnera
YüksekCVSS 8,3İstismar yokEPSS %0dell · common event enabler8 Nis 2025
- CVE-2024-2613131İzleyin
Element Android Intent Redirection
YüksekCVSS 7,8İstismar yokEPSS %0element · element28 Şub 2024
- CVE-2026-2366430İzleyin
Azure IoT Explorer Information Disclosure Vulnerability
YüksekCVSS 7,5İstismar yokEPSS %1microsoft · azure iot explorer10 Mar 2026
- CVE-2024-3444630İzleyin
Mullvad VPN through 2024.1 on Android does not set a DNS server in the blocking state (after a hard failure to create a tunnel), and thus DN
YüksekCVSS 7,5İstismar yokEPSS %13 May 2024
- CVE-2024-4749030İzleyin
Junos OS Evolved: ACX 7000 Series: Receipt of specific transit MPLS packets causes resources to be exhausted
YüksekCVSS 7,7İstismar yokEPSS %1juniper · junos os evolved11 Eki 2024
- CVE-2026-8773430İzleyin
An issue was discovered in the utcp package before 0.0.6 for OCaml.
YüksekCVSS 7,5İstismar yokEPSS %1ocaml · utcp9 Eyl 2026
- CVE-2024-2601330İzleyin
A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.
YüksekCVSS 7,5İstismar yokEPSS %0fortinet · fortianalyzer8 Nis 2025
- CVE-2025-2317830İzleyin
Ribbon Communications - CWE-923: Improper Restriction of Communication Channel to Intended Endpoints
YüksekCVSS 7,6İstismar yokEPSS %0ribbon communications · apollo 960829 Nis 2025
- CVE-2026-5984130İzleyin
A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 ma
YüksekCVSS 7,5İstismar yokEPSS %0fortinet · fortisiem14 Tem 2026
- CVE-2025-3618030İzleyin
Inadequate Pod Communication Restrictions, affects watsonx.data
YüksekCVSS 7,5İstismar yokEPSS %0ibm · watsonx.data30 Nis 2026
- CVE-2024-4712530İzleyin
Improper Restriction of Communication Channel to Intended Endpoints in goTenna Pro
YüksekCVSS 7,6İstismar yokEPSS %0gotenna · gotenna pro26 Eyl 2024
- CVE-2026-2390429İzleyin
Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxy
YüksekCVSS 7,3İstismar yokEPSS %1apache · kyuubi29 Tem 2026
- CVE-2024-4357129İzleyin
Sudo for Windows Spoofing Vulnerability
YüksekCVSS 7,3İstismar yokEPSS %1microsoft · windows 11 24h28 Eki 2024
- CVE-2024-622229İzleyin
In Docker Desktop before v4.29.0 an attacker who has gained access to the Docker Desktop VM through a container breakout can further escape to the host by passi
YüksekCVSS 7,3İstismar yokEPSS %1docker · desktop9 Tem 2024
- CVE-2026-1360829İzleyin
OpenLDAP SASL authentication bypass
YüksekCVSS 7,4İstismar yokEPSS %0haxx · curl6 Eyl 2026