CWE-441 · 143 записей
Unintended Proxy or Intermediary ('Confused Deputy')
CVE этого класса
143 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
73На этой неделе | CVE-2026-83548Готовый эксплойт | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path.sonicwall · sma8200v · CWE-441 | Критическая10,0 | KEV | 8,8 % | 1 сент. 2026 г. |
46В плане | CVE-2025-47269Эксплойта нет | code-server session cookie can be extracted by having user visit specially crafted proxy URLcoder · code-server · CWE-441 | Высокая8,3 | — | 42,7 % | 9 мая 2025 г. |
40В плане | CVE-2021-20042Эксплойта нет | An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules.sonicwall · sma 200 firmware · CWE-441 | Критическая9,8 | — | 2,6 % | 8 дек. 2021 г. |
40В плане | CVE-2026-42933Эксплойта нет | Unintended Proxy or Intermediary in Panduit IntraVUE by Pronetiqspronetiqs · panduit intravue · CWE-441 | Критическая10,0 | — | 0,5 % | 23 июл. 2026 г. |
40В плане | CVE-2026-16158Эксплойта нет | @fastify/reply-from vulnerable to cross-upstream request routing via URL cache key collisionfastify · fastify\/reply-from · CWE-441 | Критическая10,0 | — | 0,4 % | 18 июл. 2026 г. |
39Наблюдать | CVE-2026-72526Эксплойта нет | Multicloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-clusterred hat · red hat advanced cluster management for kubernetes 2.11 · CWE-441 | Критическая9,9 | — | 0,7 % | 11 авг. 2026 г. |
39Наблюдать | CVE-2026-67567Эксплойта нет | Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart applied with controller sa without gvk or namespace restrictionred hat · red hat advanced cluster management for kubernetes 2.11 · CWE-441 | Критическая9,9 | — | 0,6 % | 20 авг. 2026 г. |
39Наблюдать | CVE-2026-69399Эксплойта нет | Azure Arc Elevation of Privilege Vulnerabilitymicrosoft · azure arc · CWE-441 | Критическая9,8 | — | 0,5 % | 17 сент. 2026 г. |
38Наблюдать | CVE-2026-70398Эксплойта нет | Multicloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonamespace writes spoke bearer tokens to attacker-chosen namespacered hat · red hat advanced cluster management for kubernetes 2.11 · CWE-441 | Критическая9,6 | — | 0,5 % | 11 авг. 2026 г. |
37Наблюдать | CVE-2026-100706Эксплойта нет | kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPathkyverno · kyverno · CWE-441 | Критическая9,4 | — | 0,6 % | 4 дня назад |
37Наблюдать | CVE-2026-24471Эксплойта нет | Improper Validation in Conduit-derived homeservers resulting in Unintended Proxy or Intermediary ('Confused Deputy')continuwuity · continuwuity · CWE-441 | Критическая9,3 | — | 0,3 % | 2 февр. 2026 г. |
37Наблюдать | CVE-2025-64125Эксплойта нет | Nuvation Energy nCloud Client-to-Client Communicationnuvation energy · ncloud vpn service · CWE-441 | Критическая9,4 | — | 0,3 % | 2 янв. 2026 г. |
36Наблюдать | CVE-2015-2947Эксплойта нет | KanColleViewer versions 3.8.1 and earlier operates as an open proxy which allows remote attackers to trigger outbound network traffic.grabacr.net · kancolleviewer · CWE-441 | Критическая9,1 | — | 1,5 % | 13 апр. 2017 г. |
36Наблюдать | CVE-2026-44945Эксплойта нет | Cross-Cluster Impersonation Confused-Deputy Privilege Escalationsuse · rancher · CWE-441 | Критическая9,1 | — | 0,6 % | 5 авг. 2026 г. |
36Наблюдать | CVE-2026-33768Эксплойта нет | Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`astro · \@astrojs\/vercel · CWE-441 | Критическая9,1 | — | 0,5 % | 24 мар. 2026 г. |
35Наблюдать | CVE-2019-3924Proof of concept | MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability.mikrotik · routeros · CWE-441 | Высокая7,5 | — | 15,7 % | 20 февр. 2019 г. |
35Наблюдать | CVE-2024-9870Эксплойта нет | Unintended Proxy or Intermediary ('Confused Deputy') in GitLabgitlab · gitlab · CWE-441 | Высокая8,8 | — | 0,4 % | 12 февр. 2025 г. |
35Наблюдать | CVE-2026-36608Эксплойта нет | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external ports to the router's own admCWE-441 | Высокая8,8 | — | 0,3 % | 3 июн. 2026 г. |
34Наблюдать | CVE-2021-32783Эксплойта нет | Authorization bypass in Contourprojectcontour · contour · CWE-441 | Высокая8,5 | — | 1,2 % | 23 июл. 2021 г. |
34Наблюдать | CVE-2026-44494Эксплойта нет | Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`axios · axios · CWE-441 | Высокая8,7 | — | 0,9 % | 11 июн. 2026 г. |
34Наблюдать | CVE-2026-17107Эксплойта нет | Cluster-proxy: impersonation-header injection grants cluster-admin on every managed clusterred hat · multicluster engine for kubernetes 2.1 · CWE-441 | Высокая8,5 | — | 0,6 % | 24 июл. 2026 г. |
34Наблюдать | CVE-2026-100625Эксплойта нет | Capgo Build Upload Proxy Authorization Bypass via TUS Resourcecap-go · capgo.app · CWE-441 | Высокая8,7 | — | 0,3 % | 4 дня назад |
34Наблюдать | CVE-2025-11393Эксплойта нет | Insights-runtimes-tech-preview/runtimes-inventory-rhel8-operator: improper proxy configuration allows unauthorized administrative commandsred hat · red hat lightspeed (formerly insights) for runtimes 1.0 · CWE-441 | Высокая8,7 | — | 0,2 % | 15 дек. 2025 г. |
33Наблюдать | CVE-2019-1841Эксплойта нет | Cisco DNA Center Unintended Proxy Via SWIM Import Interface Vulnerabilitycisco · catalyst center · CWE-441 | Высокая8,1 | — | 2,6 % | 17 апр. 2019 г. |
33Наблюдать | CVE-2026-87582Эксплойта нет | Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process tgoogle · chrome · CWE-441 | Высокая8,3 | — | 0,4 % | 8 сент. 2026 г. |
- CVE-2026-8354873На этой неделе
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path.
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 9 %sonicwall · sma8200v1 сент. 2026 г.
- CVE-2025-4726946В плане
code-server session cookie can be extracted by having user visit specially crafted proxy URL
ВысокаяCVSS 8,3Эксплойта нетEPSS 43 %coder · code-server9 мая 2025 г.
- CVE-2021-2004240В плане
An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %sonicwall · sma 200 firmware8 дек. 2021 г.
- CVE-2026-4293340В плане
Unintended Proxy or Intermediary in Panduit IntraVUE by Pronetiqs
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %pronetiqs · panduit intravue23 июл. 2026 г.
- CVE-2026-1615840В плане
@fastify/reply-from vulnerable to cross-upstream request routing via URL cache key collision
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %fastify · fastify\/reply-from18 июл. 2026 г.
- CVE-2026-7252639Наблюдать
Multicloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %red hat · red hat advanced cluster management for kubernetes 2.1111 авг. 2026 г.
- CVE-2026-6756739Наблюдать
Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart applied with controller sa without gvk or namespace restriction
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %red hat · red hat advanced cluster management for kubernetes 2.1120 авг. 2026 г.
- CVE-2026-6939939Наблюдать
Azure Arc Elevation of Privilege Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %microsoft · azure arc17 сент. 2026 г.
- CVE-2026-7039838Наблюдать
Multicloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonamespace writes spoke bearer tokens to attacker-chosen namespace
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %red hat · red hat advanced cluster management for kubernetes 2.1111 авг. 2026 г.
- CVE-2026-10070637Наблюдать
kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPath
КритическаяCVSS 9,4Эксплойта нетEPSS 1 %kyverno · kyverno4 дня назад
- CVE-2026-2447137Наблюдать
Improper Validation in Conduit-derived homeservers resulting in Unintended Proxy or Intermediary ('Confused Deputy')
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %continuwuity · continuwuity2 февр. 2026 г.
- CVE-2025-6412537Наблюдать
Nuvation Energy nCloud Client-to-Client Communication
КритическаяCVSS 9,4Эксплойта нетEPSS 0 %nuvation energy · ncloud vpn service2 янв. 2026 г.
- CVE-2015-294736Наблюдать
KanColleViewer versions 3.8.1 and earlier operates as an open proxy which allows remote attackers to trigger outbound network traffic.
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %grabacr.net · kancolleviewer13 апр. 2017 г.
- CVE-2026-4494536Наблюдать
Cross-Cluster Impersonation Confused-Deputy Privilege Escalation
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %suse · rancher5 авг. 2026 г.
- CVE-2026-3376836Наблюдать
Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %astro · \@astrojs\/vercel24 мар. 2026 г.
- CVE-2019-392435Наблюдать
MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability.
ВысокаяCVSS 7,5Proof of conceptEPSS 16 %mikrotik · routeros20 февр. 2019 г.
- CVE-2024-987035Наблюдать
Unintended Proxy or Intermediary ('Confused Deputy') in GitLab
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %gitlab · gitlab12 февр. 2025 г.
- CVE-2026-3660835Наблюдать
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external ports to the router's own adm
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %3 июн. 2026 г.
- CVE-2021-3278334Наблюдать
Authorization bypass in Contour
ВысокаяCVSS 8,5Эксплойта нетEPSS 1 %projectcontour · contour23 июл. 2021 г.
- CVE-2026-4449434Наблюдать
Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %axios · axios11 июн. 2026 г.
- CVE-2026-1710734Наблюдать
Cluster-proxy: impersonation-header injection grants cluster-admin on every managed cluster
ВысокаяCVSS 8,5Эксплойта нетEPSS 1 %red hat · multicluster engine for kubernetes 2.124 июл. 2026 г.
- CVE-2026-10062534Наблюдать
Capgo Build Upload Proxy Authorization Bypass via TUS Resource
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %cap-go · capgo.app4 дня назад
- CVE-2025-1139334Наблюдать
Insights-runtimes-tech-preview/runtimes-inventory-rhel8-operator: improper proxy configuration allows unauthorized administrative commands
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %red hat · red hat lightspeed (formerly insights) for runtimes 1.015 дек. 2025 г.
- CVE-2019-184133Наблюдать
Cisco DNA Center Unintended Proxy Via SWIM Import Interface Vulnerability
ВысокаяCVSS 8,1Эксплойта нетEPSS 3 %cisco · catalyst center17 апр. 2019 г.
- CVE-2026-8758233Наблюдать
Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process t
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %google · chrome8 сент. 2026 г.