CWE-348 · 69 kayıt
Use of Less Trusted Source
Bu sınıftaki CVE’ler
69 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2022-31813Kavram kanıtı | mod_proxy X-Forwarded-For dropped by hop-by-hop mechanismapache · http server · CWE-348 | Kritik9,8 | — | %3,5 | 9 Haz 2022 |
40Planlayın | CVE-2026-48772İstismar yok | ProxySQL: PROXY-Protocol-v1 UNKNOWN parses spoofed source IP, bypassing mysql_query_rules.client_addr ACLproxysql · proxysql · CWE-348 | Kritik10,0 | — | %0,2 | 19 Haz 2026 |
37İzleyin | CVE-2026-58122İstismar yok | Hermes WebUI < 0.51.307 Authentication Bypass via X-Forwarded-For Header Spoofingnesquena · hermes-webui · CWE-348 | Kritik9,3 | — | %0,4 | 9 Tem 2026 |
36İzleyin | CVE-2026-97404İstismar yok | In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header.openstack · zaqar · CWE-348 | Kritik9,2 | — | %0,3 | 5 gün önce |
36İzleyin | CVE-2026-16272İstismar yok | Client IP Spoofing via Untrusted HTTP Headers in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Modulepaytr payment and electronic money institution inc. · paytr virtual pos iframe api (v9x) whmcs module · CWE-348 | Kritik9,1 | — | %0,1 | 9 Eyl 2026 |
36İzleyin | CVE-2026-12249İstismar yok | Canonical ADSys Trust Store Poisoning via Plaintext HTTP Certificate Auto-Enrollmentcanonical · ubuntu 20.04 lts · CWE-348 | Kritik9,0 | — | %0,1 | 22 Haz 2026 |
35İzleyin | CVE-2024-27773İstismar yok | Unitronics Unistream Unilogic – Versions prior to 1.35.227 CWE-348: Use of Less Trusted Sourceunitronics · unilogic · CWE-348 | Yüksek8,8 | — | %0,4 | 18 Mar 2024 |
34İzleyin | CVE-2026-43634İstismar yok | HestiaCP 1.2.0-1.9.4 IP Spoofing via CF-Connecting-IP Headerhestiacp · hestiacp · CWE-348 | Yüksek8,7 | — | %0,4 | 19 May 2026 |
34İzleyin | CVE-2026-64619İstismar yok | FileCodeBox < 2.4 Anti-bruteforce Rate Limit Bypass via Spoofed Headersvastsa · filecodebox · CWE-348 | Yüksek8,7 | — | %0,3 | 20 Tem 2026 |
34İzleyin | CVE-2026-35391İstismar yok | Bulwark Webmail getClientIP() trusted client-controlled X-Forwarded-For value, enabling rate limit bypass and audit log forgerybulwarkmail · webmail · CWE-348 | Yüksek8,7 | — | %0,2 | 6 Nis 2026 |
33İzleyin | CVE-2026-100653İstismar yok | vLLM 0.22.1 before 0.28.0 Incomplete Artifact Pin Propagationvllm-project · vllm · CWE-348 | Yüksek8,3 | — | %0,3 | 3 gün önce |
32İzleyin | CVE-2021-21374İstismar yok | Nimble fails to validate certificates due to insecure httpClient defaultsnim-lang · nim · CWE-348 | Yüksek8,1 | — | %1,0 | 26 Mar 2021 |
32İzleyin | CVE-2026-63770İstismar yok | Glance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypassglanceapp · glance · CWE-348 | Yüksek8,2 | — | %0,3 | 20 Tem 2026 |
32İzleyin | CVE-2025-55292İstismar yok | In Meshtastic, an attacker can spoof licensed amateur flag for a nodemeshtastic · meshtastic firmware · CWE-348 | Yüksek8,2 | — | %0,1 | 27 Oca 2026 |
30İzleyin | CVE-2022-2255İstismar yok | A vulnerability was found in mod_wsgi.modwsgi · mod wsgi · CWE-348 | Yüksek7,5 | — | %0,9 | 25 Ağu 2022 |
30İzleyin | CVE-2024-23105İstismar yok | A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allfortinet · fortiportal · CWE-348 | Yüksek7,5 | — | %0,4 | 14 May 2024 |
30İzleyin | CVE-2026-59999İstismar yok | In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.openbsd · openssh · CWE-348 | Yüksek7,5 | — | %0,2 | 7 Tem 2026 |
30İzleyin | CVE-2025-69240İstismar yok | Header Poisoning in Raytha CMSraytha · raytha · CWE-348 | Yüksek7,5 | — | %0,2 | 16 Mar 2026 |
28İzleyin | CVE-2025-47424İstismar yok | Retool (self-hosted) before 3.196.0 allows Host header injection.retool · retool · CWE-348 | Yüksek7,1 | — | %0,2 | 9 May 2025 |
27İzleyin | CVE-2026-57942İstismar yok | LibreTranslate - IP Spoofing via X-Forwarded-For Headerlibretranslate · libretranslate · CWE-348 | Orta6,9 | — | %0,3 | 29 Haz 2026 |
27İzleyin | CVE-2025-53522İstismar yok | Movable Type contains an issue with use of less trusted source.six apart ltd. · movable type (software edition) · CWE-348 | Orta6,9 | — | %0,2 | 20 Ağu 2025 |
27İzleyin | CVE-2025-47149İstismar yok | The optional feature 'Anti-Virus & Sandbox' of i-FILTER contains an issue with improper pattern file validation.digital arts inc. · i-filter · CWE-348 | Orta6,9 | — | %0,2 | 23 May 2025 |
27İzleyin | CVE-2026-22201İstismar yok | wpDiscuz before 7.6.47 - IP Address Spoofing in getIP()gvectors · wpdiscuz · CWE-348 | Orta6,9 | — | %0,2 | 13 Mar 2026 |
26İzleyin | CVE-2022-4537İstismar yok | Hide My WP Ghost – Security Plugin <= 5.0.18 - IP Address Spoofing to Protection Mechanism Bypasswpplugins · hide my wp ghost · CWE-348 | Orta6,5 | — | %0,3 | 8 May 2023 |
26İzleyin | CVE-2022-4532İstismar yok | LOGIN AND REGISTRATION ATTEMPTS LIMIT<= 2.1 - IP Address Spoofing to Protection Mechanism Bypasskrut1 · login and registration attempts limit · CWE-348 | Orta6,5 | — | %0,2 | 17 Ağu 2024 |
- CVE-2022-3181340Planlayın
mod_proxy X-Forwarded-For dropped by hop-by-hop mechanism
KritikCVSS 9,8Kavram kanıtıEPSS %4apache · http server9 Haz 2022
- CVE-2026-4877240Planlayın
ProxySQL: PROXY-Protocol-v1 UNKNOWN parses spoofed source IP, bypassing mysql_query_rules.client_addr ACL
KritikCVSS 10,0İstismar yokEPSS %0proxysql · proxysql19 Haz 2026
- CVE-2026-5812237İzleyin
Hermes WebUI < 0.51.307 Authentication Bypass via X-Forwarded-For Header Spoofing
KritikCVSS 9,3İstismar yokEPSS %0nesquena · hermes-webui9 Tem 2026
- CVE-2026-9740436İzleyin
In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header.
KritikCVSS 9,2İstismar yokEPSS %0openstack · zaqar5 gün önce
- CVE-2026-1627236İzleyin
Client IP Spoofing via Untrusted HTTP Headers in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Module
KritikCVSS 9,1İstismar yokEPSS %0paytr payment and electronic money institution inc. · paytr virtual pos iframe api (v9x) whmcs module9 Eyl 2026
- CVE-2026-1224936İzleyin
Canonical ADSys Trust Store Poisoning via Plaintext HTTP Certificate Auto-Enrollment
KritikCVSS 9,0İstismar yokEPSS %0canonical · ubuntu 20.04 lts22 Haz 2026
- CVE-2024-2777335İzleyin
Unitronics Unistream Unilogic – Versions prior to 1.35.227 CWE-348: Use of Less Trusted Source
YüksekCVSS 8,8İstismar yokEPSS %0unitronics · unilogic18 Mar 2024
- CVE-2026-4363434İzleyin
HestiaCP 1.2.0-1.9.4 IP Spoofing via CF-Connecting-IP Header
YüksekCVSS 8,7İstismar yokEPSS %0hestiacp · hestiacp19 May 2026
- CVE-2026-6461934İzleyin
FileCodeBox < 2.4 Anti-bruteforce Rate Limit Bypass via Spoofed Headers
YüksekCVSS 8,7İstismar yokEPSS %0vastsa · filecodebox20 Tem 2026
- CVE-2026-3539134İzleyin
Bulwark Webmail getClientIP() trusted client-controlled X-Forwarded-For value, enabling rate limit bypass and audit log forgery
YüksekCVSS 8,7İstismar yokEPSS %0bulwarkmail · webmail6 Nis 2026
- CVE-2026-10065333İzleyin
vLLM 0.22.1 before 0.28.0 Incomplete Artifact Pin Propagation
YüksekCVSS 8,3İstismar yokEPSS %0vllm-project · vllm3 gün önce
- CVE-2021-2137432İzleyin
Nimble fails to validate certificates due to insecure httpClient defaults
YüksekCVSS 8,1İstismar yokEPSS %1nim-lang · nim26 Mar 2021
- CVE-2026-6377032İzleyin
Glance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass
YüksekCVSS 8,2İstismar yokEPSS %0glanceapp · glance20 Tem 2026
- CVE-2025-5529232İzleyin
In Meshtastic, an attacker can spoof licensed amateur flag for a node
YüksekCVSS 8,2İstismar yokEPSS %0meshtastic · meshtastic firmware27 Oca 2026
- CVE-2022-225530İzleyin
A vulnerability was found in mod_wsgi.
YüksekCVSS 7,5İstismar yokEPSS %1modwsgi · mod wsgi25 Ağu 2022
- CVE-2024-2310530İzleyin
A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 all
YüksekCVSS 7,5İstismar yokEPSS %0fortinet · fortiportal14 May 2024
- CVE-2026-5999930İzleyin
In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
YüksekCVSS 7,5İstismar yokEPSS %0openbsd · openssh7 Tem 2026
- CVE-2025-6924030İzleyin
Header Poisoning in Raytha CMS
YüksekCVSS 7,5İstismar yokEPSS %0raytha · raytha16 Mar 2026
- CVE-2025-4742428İzleyin
Retool (self-hosted) before 3.196.0 allows Host header injection.
YüksekCVSS 7,1İstismar yokEPSS %0retool · retool9 May 2025
- CVE-2026-5794227İzleyin
LibreTranslate - IP Spoofing via X-Forwarded-For Header
OrtaCVSS 6,9İstismar yokEPSS %0libretranslate · libretranslate29 Haz 2026
- CVE-2025-5352227İzleyin
Movable Type contains an issue with use of less trusted source.
OrtaCVSS 6,9İstismar yokEPSS %0six apart ltd. · movable type (software edition)20 Ağu 2025
- CVE-2025-4714927İzleyin
The optional feature 'Anti-Virus & Sandbox' of i-FILTER contains an issue with improper pattern file validation.
OrtaCVSS 6,9İstismar yokEPSS %0digital arts inc. · i-filter23 May 2025
- CVE-2026-2220127İzleyin
wpDiscuz before 7.6.47 - IP Address Spoofing in getIP()
OrtaCVSS 6,9İstismar yokEPSS %0gvectors · wpdiscuz13 Mar 2026
- CVE-2022-453726İzleyin
Hide My WP Ghost – Security Plugin <= 5.0.18 - IP Address Spoofing to Protection Mechanism Bypass
OrtaCVSS 6,5İstismar yokEPSS %0wpplugins · hide my wp ghost8 May 2023
- CVE-2022-453226İzleyin
LOGIN AND REGISTRATION ATTEMPTS LIMIT<= 2.1 - IP Address Spoofing to Protection Mechanism Bypass
OrtaCVSS 6,5İstismar yokEPSS %0krut1 · login and registration attempts limit17 Ağu 2024