Перейти к содержимому
Noroxi

CWE-940 · 52 записей

Improper Verification of Source of a Communication Channel

CVE этого класса

52 записей

  • CVE-2025-61932
    68На этой неделе

    Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests,

    КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 3 %

    motex · lanscope endpoint manager20 окт. 2025 г.

  • CVE-2024-40515
    39Наблюдать

    An issue in SHENZHEN TENDA TECHNOLOGY CO.,LTD Tenda AX2pro V16.03.29.48_cn allows a remote attacker to execute arbitrary code via the Routin

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    tenda · ax2 pro firmware16 июл. 2024 г.

  • CVE-2024-38886
    39Наблюдать

    An issue in Horizon Business Services Inc.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    horizoncloud · caterease2 авг. 2024 г.

  • CVE-2023-41355
    39Наблюдать

    Chunghwa Telecom NOKIA G-040W-Q - Improper Input Validation

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    nokia · g-040w-q firmware3 нояб. 2023 г.

  • CVE-2023-41094
    39Наблюдать

    Touchlink authentication bypass due to packets processed after timeout or out of range in Ember ZNet

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    silabs · emberznet4 окт. 2023 г.

  • CVE-2026-85085
    38Наблюдать

    The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView.

    КритическаяCVSS 9,6Эксплойта нетEPSS 0 %

    canva · canva4 сент. 2026 г.

  • CVE-2026-33875
    37Наблюдать

    Authenticator Vulnerable to Authentication Flow Hijack

    КритическаяCVSS 9,3Эксплойта нетEPSS 0 %

    gematik · authenticator27 мар. 2026 г.

  • CVE-2026-48745
    37Наблюдать

    Traccar Client: silent configuration hijack via unverified deep link redirects all GPS telemetry

    КритическаяCVSS 9,3Эксплойта нетEPSS 0 %

    traccar · traccar-client17 июн. 2026 г.

  • CVE-2023-48387
    35Наблюдать

    TAIWAN-CA(TWCA) JCICSecurityTool - Improper Input Validation

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    twca · jcicsecuritytool15 дек. 2023 г.

  • CVE-2023-3663
    35Наблюдать

    CODESYS: Missing integrity check in CODESYS Development System

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    codesys · development system3 авг. 2023 г.

  • CVE-2024-40516
    35Наблюдать

    An issue in H3C Technologies Co., Limited H3C Magic RC3000 RC3000V100R009 allows a remote attacker to execute arbitrary code via the Routing

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    16 июл. 2024 г.

  • CVE-2026-78685
    34Наблюдать

    Le-yan|Medical Practice Management System - Remote Code Execution

    ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %

    le-yan · medical practice management system24 авг. 2026 г.

  • CVE-2026-35643
    34Наблюдать

    OpenClaw < 2026.3.22 - Arbitrary Code Execution via Unvalidated WebView JavascriptInterface

    ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %

    openclaw · openclaw10 апр. 2026 г.

  • CVE-2019-25613
    34Наблюдать

    Easy Chat Server 3.1 Denial of Service via message Parameter

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    echatserver · easy chat server22 мар. 2026 г.

  • CVE-2025-40820
    34Наблюдать

    Affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within a broad range.

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    siemens · sidoor atd430w9 дек. 2025 г.

  • CVE-2026-89178
    34Наблюдать

    Howyar|WeenyGenius - Origin Validation Error

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    howyar · weenygenius11 сент. 2026 г.

  • CVE-2024-1621
    33Наблюдать

    uniFLOW Online device registration susceptible to compromise

    ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %

    nt-ware · uniflow online2 сент. 2024 г.

  • CVE-2025-23222
    33Наблюдать

    An issue was discovered in Deepin dde-api-proxy through 1.0.19 in which unprivileged users can access D-Bus services as root.

    ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %

    deepin · dde-api-proxy24 янв. 2025 г.

  • CVE-2026-40434
    32Наблюдать

    Anviz CrossChex Standard Improper Verification of Source of a Communication Channel

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    anviz · crosschex standard17 апр. 2026 г.

  • GHSA-g8fc-vrcg-8vjg
    32Наблюдать

    Constallation has pods exposed to peers in VPC

    ВысокаяCVSS 8,0Эксплойта нет

    Go · github.com/edgelesssys/constellation/v215 апр. 2024 г.

  • CVE-2023-51440
    30Наблюдать

    A vulnerability has been identified in SIMATIC CP 343-1 (6GK7343-1EX30-0XE0) (All versions), SIMATIC CP 343-1 Lean (6GK7343-1CX10-0XE0) (All

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    siemens · simatic cp 343-113 февр. 2024 г.

  • CVE-2026-44894
    30Наблюдать

    Netty's Default QUIC token handler accepts any client-supplied token

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    netty · netty12 июн. 2026 г.

  • CVE-2025-9999
    30Наблюдать

    Improper validation of payload elements

    ВысокаяCVSS 7,6Эксплойта нетEPSS 0 %

    arcinfo · pcvue5 сент. 2025 г.

  • CVE-2025-25305
    28Наблюдать

    SSL validation for outgoing requests in Home Assistant Core and used libs not correct

    ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %

    home-assistant · core18 февр. 2025 г.

  • CVE-2025-23018
    26Наблюдать

    IPv4-in-IPv6 and IPv6-in-IPv6 tunneling (RFC 2473) do not require the validation or verification of the source of a network packet, allowing

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    ietf · ipv614 янв. 2025 г.

Все классы уязвимостей