İçeriğe atla
Noroxi

CWE-348 · 69 kayıt

Use of Less Trusted Source

Bu sınıftaki CVE’ler

69 kayıt

  • CVE-2022-31813
    40Planlayın

    mod_proxy X-Forwarded-For dropped by hop-by-hop mechanism

    KritikCVSS 9,8Kavram kanıtıEPSS %4

    apache · http server9 Haz 2022

  • CVE-2026-48772
    40Planlayın

    ProxySQL: PROXY-Protocol-v1 UNKNOWN parses spoofed source IP, bypassing mysql_query_rules.client_addr ACL

    KritikCVSS 10,0İstismar yokEPSS %0

    proxysql · proxysql19 Haz 2026

  • CVE-2026-58122
    37İzleyin

    Hermes WebUI < 0.51.307 Authentication Bypass via X-Forwarded-For Header Spoofing

    KritikCVSS 9,3İstismar yokEPSS %0

    nesquena · hermes-webui9 Tem 2026

  • CVE-2026-97404
    36İzleyin

    In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header.

    KritikCVSS 9,2İstismar yokEPSS %0

    openstack · zaqar5 gün önce

  • CVE-2026-16272
    36İzleyin

    Client IP Spoofing via Untrusted HTTP Headers in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Module

    KritikCVSS 9,1İstismar yokEPSS %0

    paytr payment and electronic money institution inc. · paytr virtual pos iframe api (v9x) whmcs module9 Eyl 2026

  • CVE-2026-12249
    36İzleyin

    Canonical ADSys Trust Store Poisoning via Plaintext HTTP Certificate Auto-Enrollment

    KritikCVSS 9,0İstismar yokEPSS %0

    canonical · ubuntu 20.04 lts22 Haz 2026

  • CVE-2024-27773
    35İzleyin

    Unitronics Unistream Unilogic – Versions prior to 1.35.227 CWE-348: Use of Less Trusted Source

    YüksekCVSS 8,8İstismar yokEPSS %0

    unitronics · unilogic18 Mar 2024

  • CVE-2026-43634
    34İzleyin

    HestiaCP 1.2.0-1.9.4 IP Spoofing via CF-Connecting-IP Header

    YüksekCVSS 8,7İstismar yokEPSS %0

    hestiacp · hestiacp19 May 2026

  • CVE-2026-64619
    34İzleyin

    FileCodeBox < 2.4 Anti-bruteforce Rate Limit Bypass via Spoofed Headers

    YüksekCVSS 8,7İstismar yokEPSS %0

    vastsa · filecodebox20 Tem 2026

  • CVE-2026-35391
    34İzleyin

    Bulwark Webmail getClientIP() trusted client-controlled X-Forwarded-For value, enabling rate limit bypass and audit log forgery

    YüksekCVSS 8,7İstismar yokEPSS %0

    bulwarkmail · webmail6 Nis 2026

  • CVE-2026-100653
    33İzleyin

    vLLM 0.22.1 before 0.28.0 Incomplete Artifact Pin Propagation

    YüksekCVSS 8,3İstismar yokEPSS %0

    vllm-project · vllm3 gün önce

  • CVE-2021-21374
    32İzleyin

    Nimble fails to validate certificates due to insecure httpClient defaults

    YüksekCVSS 8,1İstismar yokEPSS %1

    nim-lang · nim26 Mar 2021

  • CVE-2026-63770
    32İzleyin

    Glance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass

    YüksekCVSS 8,2İstismar yokEPSS %0

    glanceapp · glance20 Tem 2026

  • CVE-2025-55292
    32İzleyin

    In Meshtastic, an attacker can spoof licensed amateur flag for a node

    YüksekCVSS 8,2İstismar yokEPSS %0

    meshtastic · meshtastic firmware27 Oca 2026

  • CVE-2022-2255
    30İzleyin

    A vulnerability was found in mod_wsgi.

    YüksekCVSS 7,5İstismar yokEPSS %1

    modwsgi · mod wsgi25 Ağu 2022

  • CVE-2024-23105
    30İzleyin

    A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 all

    YüksekCVSS 7,5İstismar yokEPSS %0

    fortinet · fortiportal14 May 2024

  • CVE-2026-59999
    30İzleyin

    In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.

    YüksekCVSS 7,5İstismar yokEPSS %0

    openbsd · openssh7 Tem 2026

  • CVE-2025-69240
    30İzleyin

    Header Poisoning in Raytha CMS

    YüksekCVSS 7,5İstismar yokEPSS %0

    raytha · raytha16 Mar 2026

  • CVE-2025-47424
    28İzleyin

    Retool (self-hosted) before 3.196.0 allows Host header injection.

    YüksekCVSS 7,1İstismar yokEPSS %0

    retool · retool9 May 2025

  • CVE-2026-57942
    27İzleyin

    LibreTranslate - IP Spoofing via X-Forwarded-For Header

    OrtaCVSS 6,9İstismar yokEPSS %0

    libretranslate · libretranslate29 Haz 2026

  • CVE-2025-53522
    27İzleyin

    Movable Type contains an issue with use of less trusted source.

    OrtaCVSS 6,9İstismar yokEPSS %0

    six apart ltd. · movable type (software edition)20 Ağu 2025

  • CVE-2025-47149
    27İzleyin

    The optional feature 'Anti-Virus & Sandbox' of i-FILTER contains an issue with improper pattern file validation.

    OrtaCVSS 6,9İstismar yokEPSS %0

    digital arts inc. · i-filter23 May 2025

  • CVE-2026-22201
    27İzleyin

    wpDiscuz before 7.6.47 - IP Address Spoofing in getIP()

    OrtaCVSS 6,9İstismar yokEPSS %0

    gvectors · wpdiscuz13 Mar 2026

  • CVE-2022-4537
    26İzleyin

    Hide My WP Ghost – Security Plugin <= 5.0.18 - IP Address Spoofing to Protection Mechanism Bypass

    OrtaCVSS 6,5İstismar yokEPSS %0

    wpplugins · hide my wp ghost8 May 2023

  • CVE-2022-4532
    26İzleyin

    LOGIN AND REGISTRATION ATTEMPTS LIMIT<= 2.1 - IP Address Spoofing to Protection Mechanism Bypass

    OrtaCVSS 6,5İstismar yokEPSS %0

    krut1 · login and registration attempts limit17 Ağu 2024

Tüm zafiyet sınıfları