Перейти к содержимому
Noroxi

CWE-441 · 143 записей

Unintended Proxy or Intermediary ('Confused Deputy')

CVE этого класса

143 записей

  • CVE-2026-83548
    73На этой неделе

    A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path.

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 9 %

    sonicwall · sma8200v1 сент. 2026 г.

  • CVE-2025-47269
    46В плане

    code-server session cookie can be extracted by having user visit specially crafted proxy URL

    ВысокаяCVSS 8,3Эксплойта нетEPSS 43 %

    coder · code-server9 мая 2025 г.

  • CVE-2021-20042
    40В плане

    An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    sonicwall · sma 200 firmware8 дек. 2021 г.

  • CVE-2026-42933
    40В плане

    Unintended Proxy or Intermediary in Panduit IntraVUE by Pronetiqs

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    pronetiqs · panduit intravue23 июл. 2026 г.

  • CVE-2026-16158
    40В плане

    @fastify/reply-from vulnerable to cross-upstream request routing via URL cache key collision

    КритическаяCVSS 10,0Эксплойта нетEPSS 0 %

    fastify · fastify\/reply-from18 июл. 2026 г.

  • CVE-2026-72526
    39Наблюдать

    Multicloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster

    КритическаяCVSS 9,9Эксплойта нетEPSS 1 %

    red hat · red hat advanced cluster management for kubernetes 2.1111 авг. 2026 г.

  • CVE-2026-67567
    39Наблюдать

    Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart applied with controller sa without gvk or namespace restriction

    КритическаяCVSS 9,9Эксплойта нетEPSS 1 %

    red hat · red hat advanced cluster management for kubernetes 2.1120 авг. 2026 г.

  • CVE-2026-69399
    39Наблюдать

    Azure Arc Elevation of Privilege Vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    microsoft · azure arc17 сент. 2026 г.

  • CVE-2026-70398
    38Наблюдать

    Multicloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonamespace writes spoke bearer tokens to attacker-chosen namespace

    КритическаяCVSS 9,6Эксплойта нетEPSS 1 %

    red hat · red hat advanced cluster management for kubernetes 2.1111 авг. 2026 г.

  • CVE-2026-100706
    37Наблюдать

    kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPath

    КритическаяCVSS 9,4Эксплойта нетEPSS 1 %

    kyverno · kyverno4 дня назад

  • CVE-2026-24471
    37Наблюдать

    Improper Validation in Conduit-derived homeservers resulting in Unintended Proxy or Intermediary ('Confused Deputy')

    КритическаяCVSS 9,3Эксплойта нетEPSS 0 %

    continuwuity · continuwuity2 февр. 2026 г.

  • CVE-2025-64125
    37Наблюдать

    Nuvation Energy nCloud Client-to-Client Communication

    КритическаяCVSS 9,4Эксплойта нетEPSS 0 %

    nuvation energy · ncloud vpn service2 янв. 2026 г.

  • CVE-2015-2947
    36Наблюдать

    KanColleViewer versions 3.8.1 and earlier operates as an open proxy which allows remote attackers to trigger outbound network traffic.

    КритическаяCVSS 9,1Эксплойта нетEPSS 2 %

    grabacr.net · kancolleviewer13 апр. 2017 г.

  • CVE-2026-44945
    36Наблюдать

    Cross-Cluster Impersonation Confused-Deputy Privilege Escalation

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    suse · rancher5 авг. 2026 г.

  • CVE-2026-33768
    36Наблюдать

    Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    astro · \@astrojs\/vercel24 мар. 2026 г.

  • CVE-2019-3924
    35Наблюдать

    MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability.

    ВысокаяCVSS 7,5Proof of conceptEPSS 16 %

    mikrotik · routeros20 февр. 2019 г.

  • CVE-2024-9870
    35Наблюдать

    Unintended Proxy or Intermediary ('Confused Deputy') in GitLab

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    gitlab · gitlab12 февр. 2025 г.

  • CVE-2026-36608
    35Наблюдать

    Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external ports to the router's own adm

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    3 июн. 2026 г.

  • CVE-2021-32783
    34Наблюдать

    Authorization bypass in Contour

    ВысокаяCVSS 8,5Эксплойта нетEPSS 1 %

    projectcontour · contour23 июл. 2021 г.

  • CVE-2026-44494
    34Наблюдать

    Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    axios · axios11 июн. 2026 г.

  • CVE-2026-17107
    34Наблюдать

    Cluster-proxy: impersonation-header injection grants cluster-admin on every managed cluster

    ВысокаяCVSS 8,5Эксплойта нетEPSS 1 %

    red hat · multicluster engine for kubernetes 2.124 июл. 2026 г.

  • CVE-2026-100625
    34Наблюдать

    Capgo Build Upload Proxy Authorization Bypass via TUS Resource

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    cap-go · capgo.app4 дня назад

  • CVE-2025-11393
    34Наблюдать

    Insights-runtimes-tech-preview/runtimes-inventory-rhel8-operator: improper proxy configuration allows unauthorized administrative commands

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    red hat · red hat lightspeed (formerly insights) for runtimes 1.015 дек. 2025 г.

  • CVE-2019-1841
    33Наблюдать

    Cisco DNA Center Unintended Proxy Via SWIM Import Interface Vulnerability

    ВысокаяCVSS 8,1Эксплойта нетEPSS 3 %

    cisco · catalyst center17 апр. 2019 г.

  • CVE-2026-87582
    33Наблюдать

    Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process t

    ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %

    google · chrome8 сент. 2026 г.

Все классы уязвимостей