İçeriğe atla
Noroxi

CWE-350 · 28 kayıt

Reliance on Reverse DNS Resolution for a Security-Critical Action

Bu sınıftaki CVE’ler

28 kayıt

  • CVE-2021-22884
    40Planlayın

    Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”.

    YüksekCVSS 7,5İstismar yokEPSS %32

    nodejs · node.js3 Mar 2021

  • CVE-2026-1490
    39İzleyin

    Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.71 - Authorization Bypass via Reverse DNS (PTR record) Spoofing to Unauthenticated Arbitrary Plugin Insta

    KritikCVSS 9,8İstismar yokEPSS %1

    cleantalk · spam protection, honeypot, anti-spam by cleantalk15 Şub 2026

  • CVE-2018-7160
    38İzleyin

    The Node.js inspector, in 6.x and later is vulnerable to a DNS rebinding attack which could be exploited to perform remote code execution.

    YüksekCVSS 8,8İstismar yokEPSS %10

    nodejs · node.js17 May 2018

  • CVE-2026-61568
    38İzleyin

    @zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport

    KritikCVSS 9,6İstismar yokEPSS %1

    zereight · gitlab-mcp15 Eyl 2026

  • CVE-2021-34561
    35İzleyin

    A vulnerability in WirelessHART-Gateway <= 3.0.8 allows to bypass any IP or firewall based access restrictions through DNS rebinding

    YüksekCVSS 8,8İstismar yokEPSS %1

    pepperl-fuchs · wha-gw-f2d2-0-as-z2-eth firmware31 Ağu 2021

  • CVE-2023-52235
    35İzleyin

    SpaceX Starlink Wi-Fi router GEN 2 before 2023.53.0 and Starlink Dish before 07dd2798-ff15-4722-a9ee-de28928aed34 allow CSRF (e.g., for a re

    YüksekCVSS 8,8Kavram kanıtıEPSS %1

    5 Nis 2024

  • CVE-2026-56709
    34İzleyin

    Grav before 3.9.2 Host Header Injection via sendInvitationEmail

    YüksekCVSS 8,7İstismar yokEPSS %0

    getgrav · grav24 Ağu 2026

  • CVE-2026-55526
    34İzleyin

    PraisonAI: SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)

    YüksekCVSS 8,5İstismar yokEPSS %0

    mervinpraison · praisonai25 Ağu 2026

  • CVE-2017-0902
    33İzleyin

    RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client

    YüksekCVSS 8,1İstismar yokEPSS %5

    rubygems · rubygems31 Ağu 2017

  • CVE-2025-8036
    32İzleyin

    DNS rebinding circumvents CORS

    YüksekCVSS 8,1İstismar yokEPSS %0

    mozilla · firefox22 Tem 2025

  • CVE-2026-97875
    32İzleyin

    DNS rebinding vulnerability in rojo serve HTTP API

    YüksekCVSS 8,1İstismar yokEPSS %0

    rojo-rbx · rojo5 gün önce

  • CVE-2026-33002
    30İzleyin

    Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made t

    YüksekCVSS 7,5İstismar yokEPSS %0

    jenkins · jenkins18 Mar 2026

  • CVE-2026-55391
    30İzleyin

    datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding

    YüksekCVSS 7,5İstismar yokEPSS %0

    koxudaxi · datamodel-code-generator28 Tem 2026

  • CVE-2026-28271
    26İzleyin

    Kiteworks Core is vulnerable to Server-Side Request Forgery (SSRF)

    OrtaCVSS 6,5İstismar yokEPSS %1

    accellion · kiteworks27 Şub 2026

  • CVE-2025-59956
    26İzleyin

    AgentAPI exposed user chat history via a DNS rebinding attack

    OrtaCVSS 6,5İstismar yokEPSS %0

    coder · agentapi30 Eyl 2025

  • CVE-2026-36604
    26İzleyin

    Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 does not validate the HTTP Host header, enabling DNS rebinding attacks.

    OrtaCVSS 6,5İstismar yokEPSS %0

    3 Haz 2026

  • CVE-2026-53708
    26İzleyin

    ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)

    OrtaCVSS 6,6İstismar yokEPSS %0

    ibm · mcp-context-forge14 Eyl 2026

  • CVE-2024-42364
    26İzleyin

    homepage DNS rebinding vulnerability (GHSL-2024-096)

    OrtaCVSS 6,5İstismar yokEPSS %0

    gethomepage · homepage23 Ağu 2024

  • CVE-2025-61430
    26İzleyin

    Improper handling of DNS over TCP in Simple DNS Plus v9 allows a remote attacker with querying access to the DNS server to cause the server

    OrtaCVSS 6,5İstismar yokEPSS %0

    24 Eki 2025

  • CVE-2026-61743
    25İzleyin

    Chartbrew: DNS Rebinding SSRF Bypass in Outbound Request Validation

    OrtaCVSS 6,3İstismar yokEPSS %0

    chartbrew · chartbrew21 Eyl 2026

  • CVE-2020-11091
    23İzleyin

    Weave Net clusters susceptible to MitM attacks via IPv6 rogue router advertisements

    OrtaCVSS 5,8İstismar yokEPSS %1

    weave · weave net3 Haz 2020

  • CVE-2026-75514
    23İzleyin

    BunkerWeb: rDNS bypass via missing forward-confirmation (FCrDNS) in blacklist, greylist, and antibot

    OrtaCVSS 5,9İstismar yokEPSS %1

    bunkerity · bunkerweb20 Ağu 2026

  • CVE-2023-32020
    22İzleyin

    Windows DNS Spoofing Vulnerability

    OrtaCVSS 5,6İstismar yokEPSS %1

    microsoft · windows server 200813 Haz 2023

  • CVE-2022-22364
    21İzleyin

    IBM Cognos Controller security bypass

    OrtaCVSS 5,3İstismar yokEPSS %1

    ibm · cognos controller3 May 2024

  • CVE-2024-53275
    21İzleyin

    GHSL-2024-091: DNS rebinding attack in home-gallery

    OrtaCVSS 5,3İstismar yokEPSS %0

    xemle · home-gallery23 Ara 2024

Tüm zafiyet sınıfları