Skip to content
Noroxi

CWE-441 · 143 records

Unintended Proxy or Intermediary ('Confused Deputy')

CVEs in this class

143 records

  • CVE-2026-83548
    73This week

    A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path.

    CriticalCVSS 10.0KEVWeaponizedEPSS 9%

    sonicwall · sma8200vSep 1, 2026

  • code-server session cookie can be extracted by having user visit specially crafted proxy URL

    HighCVSS 8.3No exploitEPSS 43%

    coder · code-serverMay 9, 2025

  • An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules.

    CriticalCVSS 9.8No exploitEPSS 3%

    sonicwall · sma 200 firmwareDec 8, 2021

  • Unintended Proxy or Intermediary in Panduit IntraVUE by Pronetiqs

    CriticalCVSS 10.0No exploitEPSS 1%

    pronetiqs · panduit intravueJul 23, 2026

  • @fastify/reply-from vulnerable to cross-upstream request routing via URL cache key collision

    CriticalCVSS 10.0No exploitEPSS 0%

    fastify · fastify\/reply-fromJul 18, 2026

  • Multicloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster

    CriticalCVSS 9.9No exploitEPSS 1%

    red hat · red hat advanced cluster management for kubernetes 2.11Aug 11, 2026

  • Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart applied with controller sa without gvk or namespace restriction

    CriticalCVSS 9.9No exploitEPSS 1%

    red hat · red hat advanced cluster management for kubernetes 2.11Aug 20, 2026

  • Azure Arc Elevation of Privilege Vulnerability

    CriticalCVSS 9.8No exploitEPSS 0%

    microsoft · azure arcSep 17, 2026

  • Multicloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonamespace writes spoke bearer tokens to attacker-chosen namespace

    CriticalCVSS 9.6No exploitEPSS 1%

    red hat · red hat advanced cluster management for kubernetes 2.11Aug 11, 2026

  • kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPath

    CriticalCVSS 9.4No exploitEPSS 1%

    kyverno · kyverno4 days ago

  • Improper Validation in Conduit-derived homeservers resulting in Unintended Proxy or Intermediary ('Confused Deputy')

    CriticalCVSS 9.3No exploitEPSS 0%

    continuwuity · continuwuityFeb 2, 2026

  • Nuvation Energy nCloud Client-to-Client Communication

    CriticalCVSS 9.4No exploitEPSS 0%

    nuvation energy · ncloud vpn serviceJan 3, 2026

  • CVE-2015-2947
    36Monitor

    KanColleViewer versions 3.8.1 and earlier operates as an open proxy which allows remote attackers to trigger outbound network traffic.

    CriticalCVSS 9.1No exploitEPSS 2%

    grabacr.net · kancolleviewerApr 13, 2017

  • Cross-Cluster Impersonation Confused-Deputy Privilege Escalation

    CriticalCVSS 9.1No exploitEPSS 1%

    suse · rancherAug 5, 2026

  • Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`

    CriticalCVSS 9.1No exploitEPSS 0%

    astro · \@astrojs\/vercelMar 24, 2026

  • CVE-2019-3924
    35Monitor

    MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability.

    HighCVSS 7.5Proof of conceptEPSS 16%

    mikrotik · routerosFeb 20, 2019

  • CVE-2024-9870
    35Monitor

    Unintended Proxy or Intermediary ('Confused Deputy') in GitLab

    HighCVSS 8.8No exploitEPSS 0%

    gitlab · gitlabFeb 12, 2025

  • Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external ports to the router's own adm

    HighCVSS 8.8No exploitEPSS 0%

    Jun 3, 2026

  • Authorization bypass in Contour

    HighCVSS 8.5No exploitEPSS 1%

    projectcontour · contourJul 23, 2021

  • Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

    HighCVSS 8.7No exploitEPSS 1%

    axios · axiosJun 11, 2026

  • Cluster-proxy: impersonation-header injection grants cluster-admin on every managed cluster

    HighCVSS 8.5No exploitEPSS 1%

    red hat · multicluster engine for kubernetes 2.1Jul 24, 2026

  • Capgo Build Upload Proxy Authorization Bypass via TUS Resource

    HighCVSS 8.7No exploitEPSS 0%

    cap-go · capgo.app4 days ago

  • Insights-runtimes-tech-preview/runtimes-inventory-rhel8-operator: improper proxy configuration allows unauthorized administrative commands

    HighCVSS 8.7No exploitEPSS 0%

    red hat · red hat lightspeed (formerly insights) for runtimes 1.0Dec 15, 2025

  • CVE-2019-1841
    33Monitor

    Cisco DNA Center Unintended Proxy Via SWIM Import Interface Vulnerability

    HighCVSS 8.1No exploitEPSS 3%

    cisco · catalyst centerApr 17, 2019

  • Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process t

    HighCVSS 8.3No exploitEPSS 0%

    google · chromeSep 8, 2026

All vulnerability classes