İçeriğe atla
Noroxi

CWE-300 · 57 kayıt

Channel Accessible by Non-Endpoint

Bu sınıftaki CVE’ler

57 kayıt

  • CVE-2017-7480
    40Planlayın

    rkhunter versions before 1.4.4 are vulnerable to file download over insecure channel when doing mirror update resulting into potential remot

    KritikCVSS 9,8İstismar yokEPSS %2

    rootkit hunter project · rootkit hunter21 Tem 2017

  • CVE-2019-3793
    39İzleyin

    Invitations Service supports HTTP connections

    KritikCVSS 9,8İstismar yokEPSS %1

    pivotal software · application service24 Nis 2019

  • CVE-2026-74232
    37İzleyin

    Zbtlink MQWrt yunmgrd Cloud C2 Implant

    KritikCVSS 9,3İstismar yokEPSS %1

    zbtlink · l3_v2_827 Ağu 2026

  • CVE-2025-54792
    37İzleyin

    LocalSend is Vulnerable to Man-in-the-Middle Attacks, Leading to File Interception

    KritikCVSS 9,3İstismar yokEPSS %0

    localsend · localsend1 Ağu 2025

  • CVE-2023-31004
    36İzleyin

    IBM Security Access Manager Container gain access

    KritikCVSS 9,0İstismar yokEPSS %1

    ibm · security verify access2 Şub 2024

  • CVE-2026-12991
    34İzleyin

    Multiple vulnerabilities in Ghost Robotics' Vision 60

    YüksekCVSS 8,7İstismar yokEPSS %0

    ghost robotics · vision 6027 Tem 2026

  • CVE-2017-12150
    33İzleyin

    It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration

    YüksekCVSS 7,4İstismar yokEPSS %13

    samba · samba26 Tem 2018

  • CVE-2018-0025
    32İzleyin

    Junos OS: SRX Series: Credentials exposed when using HTTP and HTTPS Firewall Pass-through User Authentication

    YüksekCVSS 8,1İstismar yokEPSS %1

    juniper · junos11 Tem 2018

  • CVE-2019-5456
    32İzleyin

    SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 and their actual SMTP

    YüksekCVSS 8,1İstismar yokEPSS %1

    ui · unifi controller30 Tem 2019

  • CVE-2021-41033
    32İzleyin

    In all released versions of Eclipse Equinox, at least until version 4.21 (September 2021), installation can be vulnerable to man-in-the-midd

    YüksekCVSS 8,1İstismar yokEPSS %1

    eclipse · equinox13 Eyl 2021

  • CVE-2021-21953
    32İzleyin

    An authentication bypass vulnerability exists in the process_msg() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h.

    YüksekCVSS 8,1İstismar yokEPSS %1

    anker · eufy homebase 2 firmware22 Ara 2021

  • CVE-2018-13298
    32İzleyin

    Channel accessible by non-endpoint vulnerability in privacy page in Synology Android Moments before 1.2.3-199 allows man-in-the-middle attac

    YüksekCVSS 8,1İstismar yokEPSS %1

    synology · moments1 Nis 2019

  • CVE-2020-11024
    32İzleyin

    Man-in-the-middle attack in Moonlight iOS/tvOS

    YüksekCVSS 8,2İstismar yokEPSS %1

    moonlight-stream · moonlight29 Nis 2020

  • CVE-2025-31214
    32İzleyin

    This issue was addressed through improved state management.

    YüksekCVSS 8,1İstismar yokEPSS %1

    apple · ipados12 May 2025

  • CVE-2024-31206
    32İzleyin

    Use of Unencrypted HTTP Request in dectalk-tts

    YüksekCVSS 8,2İstismar yokEPSS %0

    jstnmcbrd · dectalk-tts4 Nis 2024

  • CVE-2024-36553
    32İzleyin

    Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h is vulnerable to MITM attack.

    YüksekCVSS 8,1İstismar yokEPSS %0

    6 Şub 2025

  • Go package github.com/edgelesssys/marblerun CLI commands susceptible to MITM attacks

    YüksekCVSS 8,0İstismar yok

    Go · github.com/edgelesssys/marblerun4 Ara 2023

  • CVE-2021-32926
    31İzleyin

    When an authenticated password change request takes place, this vulnerability could allow the attacker to intercept the message that include

    YüksekCVSS 7,5İstismar yokEPSS %3

    rockwellautomation · micro800 firmware3 Haz 2021

  • CVE-2025-20122
    31İzleyin

    Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability

    YüksekCVSS 7,8İstismar yokEPSS %0

    cisco · catalyst sd-wan manager7 May 2025

  • CVE-2017-12151
    30İzleyin

    A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3

    YüksekCVSS 7,4İstismar yokEPSS %5

    samba · samba27 Tem 2018

  • CVE-2017-15086
    30İzleyin

    It was discovered that the fix for CVE-2017-12151 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHE

    YüksekCVSS 7,4İstismar yokEPSS %2

    redhat · gluster storage8 Kas 2017

  • CVE-2021-22909
    30İzleyin

    A vulnerability found in EdgeMAX EdgeRouter V2.0.9 and earlier could allow a malicious actor to execute a man-in-the-middle (MitM) attack du

    YüksekCVSS 7,5İstismar yokEPSS %1

    ui · edgemax edgerouter firmware27 May 2021

  • CVE-2024-50565
    30İzleyin

    A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.

    YüksekCVSS 7,5İstismar yokEPSS %0

    fortinet · fortiweb8 Nis 2025

  • CVE-2023-38272
    30İzleyin

    IBM Cloud Pak System information disclosure

    YüksekCVSS 7,5İstismar yokEPSS %0

    ibm · cloud pak system27 Mar 2025

  • CVE-2024-12602
    30İzleyin

    Identity verification vulnerability in the ParamWatcher module Impact: Successful exploitation of this vulnerability may affect service conf

    YüksekCVSS 7,5İstismar yokEPSS %0

    huawei · harmonyos6 Şub 2025

Tüm zafiyet sınıfları