CWE-300 · 57 kayıt
Channel Accessible by Non-Endpoint
Bu sınıftaki CVE’ler
57 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2017-7480İstismar yok | rkhunter versions before 1.4.4 are vulnerable to file download over insecure channel when doing mirror update resulting into potential remotrootkit hunter project · rootkit hunter · CWE-300 | Kritik9,8 | — | %2,3 | 21 Tem 2017 |
39İzleyin | CVE-2019-3793İstismar yok | Invitations Service supports HTTP connectionspivotal software · application service · CWE-300 | Kritik9,8 | — | %1,1 | 24 Nis 2019 |
37İzleyin | CVE-2026-74232İstismar yok | Zbtlink MQWrt yunmgrd Cloud C2 Implantzbtlink · l3_v2_8 · CWE-300 | Kritik9,3 | — | %0,8 | 27 Ağu 2026 |
37İzleyin | CVE-2025-54792İstismar yok | LocalSend is Vulnerable to Man-in-the-Middle Attacks, Leading to File Interceptionlocalsend · localsend · CWE-300 | Kritik9,3 | — | %0,3 | 1 Ağu 2025 |
36İzleyin | CVE-2023-31004İstismar yok | IBM Security Access Manager Container gain accessibm · security verify access · CWE-300 | Kritik9,0 | — | %1,0 | 2 Şub 2024 |
34İzleyin | CVE-2026-12991İstismar yok | Multiple vulnerabilities in Ghost Robotics' Vision 60ghost robotics · vision 60 · CWE-300 | Yüksek8,7 | — | %0,2 | 27 Tem 2026 |
33İzleyin | CVE-2017-12150İstismar yok | It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration samba · samba · CWE-300 | Yüksek7,4 | — | %13,3 | 26 Tem 2018 |
32İzleyin | CVE-2018-0025İstismar yok | Junos OS: SRX Series: Credentials exposed when using HTTP and HTTPS Firewall Pass-through User Authenticationjuniper · junos · CWE-300 | Yüksek8,1 | — | %1,4 | 11 Tem 2018 |
32İzleyin | CVE-2019-5456İstismar yok | SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 and their actual SMTP ui · unifi controller · CWE-300 | Yüksek8,1 | — | %1,3 | 30 Tem 2019 |
32İzleyin | CVE-2021-41033İstismar yok | In all released versions of Eclipse Equinox, at least until version 4.21 (September 2021), installation can be vulnerable to man-in-the-middeclipse · equinox · CWE-300 | Yüksek8,1 | — | %1,1 | 13 Eyl 2021 |
32İzleyin | CVE-2021-21953İstismar yok | An authentication bypass vulnerability exists in the process_msg() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h.anker · eufy homebase 2 firmware · CWE-300 | Yüksek8,1 | — | %1,0 | 22 Ara 2021 |
32İzleyin | CVE-2018-13298İstismar yok | Channel accessible by non-endpoint vulnerability in privacy page in Synology Android Moments before 1.2.3-199 allows man-in-the-middle attacsynology · moments · CWE-300 | Yüksek8,1 | — | %0,9 | 1 Nis 2019 |
32İzleyin | CVE-2020-11024İstismar yok | Man-in-the-middle attack in Moonlight iOS/tvOSmoonlight-stream · moonlight · CWE-300 | Yüksek8,2 | — | %0,8 | 29 Nis 2020 |
32İzleyin | CVE-2025-31214İstismar yok | This issue was addressed through improved state management.apple · ipados · CWE-300 | Yüksek8,1 | — | %0,5 | 12 May 2025 |
32İzleyin | CVE-2024-31206İstismar yok | Use of Unencrypted HTTP Request in dectalk-ttsjstnmcbrd · dectalk-tts · CWE-300 | Yüksek8,2 | — | %0,3 | 4 Nis 2024 |
32İzleyin | CVE-2024-36553İstismar yok | Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h is vulnerable to MITM attack.CWE-300 | Yüksek8,1 | — | %0,3 | 6 Şub 2025 |
32İzleyin | GHSA-j3rq-4xjw-xg63İstismar yok | Go package github.com/edgelesssys/marblerun CLI commands susceptible to MITM attacksGo · github.com/edgelesssys/marblerun · CWE-300 | Yüksek8,0 | — | — | 4 Ara 2023 |
31İzleyin | CVE-2021-32926İstismar yok | When an authenticated password change request takes place, this vulnerability could allow the attacker to intercept the message that includerockwellautomation · micro800 firmware · CWE-300 | Yüksek7,5 | — | %3,0 | 3 Haz 2021 |
31İzleyin | CVE-2025-20122İstismar yok | Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerabilitycisco · catalyst sd-wan manager · CWE-300 | Yüksek7,8 | — | %0,1 | 7 May 2025 |
30İzleyin | CVE-2017-12151İstismar yok | A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3samba · samba · CWE-300 | Yüksek7,4 | — | %4,6 | 27 Tem 2018 |
30İzleyin | CVE-2017-15086İstismar yok | It was discovered that the fix for CVE-2017-12151 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEredhat · gluster storage · CWE-300 | Yüksek7,4 | — | %1,7 | 8 Kas 2017 |
30İzleyin | CVE-2021-22909İstismar yok | A vulnerability found in EdgeMAX EdgeRouter V2.0.9 and earlier could allow a malicious actor to execute a man-in-the-middle (MitM) attack duui · edgemax edgerouter firmware · CWE-300 | Yüksek7,5 | — | %1,3 | 27 May 2021 |
30İzleyin | CVE-2024-50565İstismar yok | A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.fortinet · fortiweb · CWE-300 | Yüksek7,5 | — | %0,4 | 8 Nis 2025 |
30İzleyin | CVE-2023-38272İstismar yok | IBM Cloud Pak System information disclosureibm · cloud pak system · CWE-300 | Yüksek7,5 | — | %0,3 | 27 Mar 2025 |
30İzleyin | CVE-2024-12602İstismar yok | Identity verification vulnerability in the ParamWatcher module Impact: Successful exploitation of this vulnerability may affect service confhuawei · harmonyos · CWE-300 | Yüksek7,5 | — | %0,2 | 6 Şub 2025 |
- CVE-2017-748040Planlayın
rkhunter versions before 1.4.4 are vulnerable to file download over insecure channel when doing mirror update resulting into potential remot
KritikCVSS 9,8İstismar yokEPSS %2rootkit hunter project · rootkit hunter21 Tem 2017
- CVE-2019-379339İzleyin
Invitations Service supports HTTP connections
KritikCVSS 9,8İstismar yokEPSS %1pivotal software · application service24 Nis 2019
- CVE-2026-7423237İzleyin
Zbtlink MQWrt yunmgrd Cloud C2 Implant
KritikCVSS 9,3İstismar yokEPSS %1zbtlink · l3_v2_827 Ağu 2026
- CVE-2025-5479237İzleyin
LocalSend is Vulnerable to Man-in-the-Middle Attacks, Leading to File Interception
KritikCVSS 9,3İstismar yokEPSS %0localsend · localsend1 Ağu 2025
- CVE-2023-3100436İzleyin
IBM Security Access Manager Container gain access
KritikCVSS 9,0İstismar yokEPSS %1ibm · security verify access2 Şub 2024
- CVE-2026-1299134İzleyin
Multiple vulnerabilities in Ghost Robotics' Vision 60
YüksekCVSS 8,7İstismar yokEPSS %0ghost robotics · vision 6027 Tem 2026
- CVE-2017-1215033İzleyin
It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration
YüksekCVSS 7,4İstismar yokEPSS %13samba · samba26 Tem 2018
- CVE-2018-002532İzleyin
Junos OS: SRX Series: Credentials exposed when using HTTP and HTTPS Firewall Pass-through User Authentication
YüksekCVSS 8,1İstismar yokEPSS %1juniper · junos11 Tem 2018
- CVE-2019-545632İzleyin
SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 and their actual SMTP
YüksekCVSS 8,1İstismar yokEPSS %1ui · unifi controller30 Tem 2019
- CVE-2021-4103332İzleyin
In all released versions of Eclipse Equinox, at least until version 4.21 (September 2021), installation can be vulnerable to man-in-the-midd
YüksekCVSS 8,1İstismar yokEPSS %1eclipse · equinox13 Eyl 2021
- CVE-2021-2195332İzleyin
An authentication bypass vulnerability exists in the process_msg() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h.
YüksekCVSS 8,1İstismar yokEPSS %1anker · eufy homebase 2 firmware22 Ara 2021
- CVE-2018-1329832İzleyin
Channel accessible by non-endpoint vulnerability in privacy page in Synology Android Moments before 1.2.3-199 allows man-in-the-middle attac
YüksekCVSS 8,1İstismar yokEPSS %1synology · moments1 Nis 2019
- CVE-2020-1102432İzleyin
Man-in-the-middle attack in Moonlight iOS/tvOS
YüksekCVSS 8,2İstismar yokEPSS %1moonlight-stream · moonlight29 Nis 2020
- CVE-2025-3121432İzleyin
This issue was addressed through improved state management.
YüksekCVSS 8,1İstismar yokEPSS %1apple · ipados12 May 2025
- CVE-2024-3120632İzleyin
Use of Unencrypted HTTP Request in dectalk-tts
YüksekCVSS 8,2İstismar yokEPSS %0jstnmcbrd · dectalk-tts4 Nis 2024
- CVE-2024-3655332İzleyin
Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h is vulnerable to MITM attack.
YüksekCVSS 8,1İstismar yokEPSS %06 Şub 2025
- GHSA-j3rq-4xjw-xg6332İzleyin
Go package github.com/edgelesssys/marblerun CLI commands susceptible to MITM attacks
YüksekCVSS 8,0İstismar yokGo · github.com/edgelesssys/marblerun4 Ara 2023
- CVE-2021-3292631İzleyin
When an authenticated password change request takes place, this vulnerability could allow the attacker to intercept the message that include
YüksekCVSS 7,5İstismar yokEPSS %3rockwellautomation · micro800 firmware3 Haz 2021
- CVE-2025-2012231İzleyin
Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability
YüksekCVSS 7,8İstismar yokEPSS %0cisco · catalyst sd-wan manager7 May 2025
- CVE-2017-1215130İzleyin
A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3
YüksekCVSS 7,4İstismar yokEPSS %5samba · samba27 Tem 2018
- CVE-2017-1508630İzleyin
It was discovered that the fix for CVE-2017-12151 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHE
YüksekCVSS 7,4İstismar yokEPSS %2redhat · gluster storage8 Kas 2017
- CVE-2021-2290930İzleyin
A vulnerability found in EdgeMAX EdgeRouter V2.0.9 and earlier could allow a malicious actor to execute a man-in-the-middle (MitM) attack du
YüksekCVSS 7,5İstismar yokEPSS %1ui · edgemax edgerouter firmware27 May 2021
- CVE-2024-5056530İzleyin
A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.
YüksekCVSS 7,5İstismar yokEPSS %0fortinet · fortiweb8 Nis 2025
- CVE-2023-3827230İzleyin
IBM Cloud Pak System information disclosure
YüksekCVSS 7,5İstismar yokEPSS %0ibm · cloud pak system27 Mar 2025
- CVE-2024-1260230İzleyin
Identity verification vulnerability in the ParamWatcher module Impact: Successful exploitation of this vulnerability may affect service conf
YüksekCVSS 7,5İstismar yokEPSS %0huawei · harmonyos6 Şub 2025