CWE-441 · 143 kayıt
Unintended Proxy or Intermediary ('Confused Deputy')
Bu sınıftaki CVE’ler
143 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
73Bu hafta | CVE-2026-83548Silahlaştırılmış | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path.sonicwall · sma8200v · CWE-441 | Kritik10,0 | KEV | %8,8 | 1 Eyl 2026 |
46Planlayın | CVE-2025-47269İstismar yok | code-server session cookie can be extracted by having user visit specially crafted proxy URLcoder · code-server · CWE-441 | Yüksek8,3 | — | %42,7 | 9 May 2025 |
40Planlayın | CVE-2021-20042İstismar yok | An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules.sonicwall · sma 200 firmware · CWE-441 | Kritik9,8 | — | %2,6 | 8 Ara 2021 |
40Planlayın | CVE-2026-42933İstismar yok | Unintended Proxy or Intermediary in Panduit IntraVUE by Pronetiqspronetiqs · panduit intravue · CWE-441 | Kritik10,0 | — | %0,5 | 23 Tem 2026 |
40Planlayın | CVE-2026-16158İstismar yok | @fastify/reply-from vulnerable to cross-upstream request routing via URL cache key collisionfastify · fastify\/reply-from · CWE-441 | Kritik10,0 | — | %0,4 | 18 Tem 2026 |
39İzleyin | CVE-2026-72526İstismar yok | Multicloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-clusterred hat · red hat advanced cluster management for kubernetes 2.11 · CWE-441 | Kritik9,9 | — | %0,7 | 11 Ağu 2026 |
39İzleyin | CVE-2026-67567İstismar yok | Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart applied with controller sa without gvk or namespace restrictionred hat · red hat advanced cluster management for kubernetes 2.11 · CWE-441 | Kritik9,9 | — | %0,6 | 20 Ağu 2026 |
39İzleyin | CVE-2026-69399İstismar yok | Azure Arc Elevation of Privilege Vulnerabilitymicrosoft · azure arc · CWE-441 | Kritik9,8 | — | %0,5 | 17 Eyl 2026 |
38İzleyin | CVE-2026-70398İstismar yok | Multicloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonamespace writes spoke bearer tokens to attacker-chosen namespacered hat · red hat advanced cluster management for kubernetes 2.11 · CWE-441 | Kritik9,6 | — | %0,5 | 11 Ağu 2026 |
37İzleyin | CVE-2026-100706İstismar yok | kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPathkyverno · kyverno · CWE-441 | Kritik9,4 | — | %0,6 | 3 gün önce |
37İzleyin | CVE-2026-24471İstismar yok | Improper Validation in Conduit-derived homeservers resulting in Unintended Proxy or Intermediary ('Confused Deputy')continuwuity · continuwuity · CWE-441 | Kritik9,3 | — | %0,3 | 2 Şub 2026 |
37İzleyin | CVE-2025-64125İstismar yok | Nuvation Energy nCloud Client-to-Client Communicationnuvation energy · ncloud vpn service · CWE-441 | Kritik9,4 | — | %0,3 | 2 Oca 2026 |
36İzleyin | CVE-2015-2947İstismar yok | KanColleViewer versions 3.8.1 and earlier operates as an open proxy which allows remote attackers to trigger outbound network traffic.grabacr.net · kancolleviewer · CWE-441 | Kritik9,1 | — | %1,5 | 13 Nis 2017 |
36İzleyin | CVE-2026-44945İstismar yok | Cross-Cluster Impersonation Confused-Deputy Privilege Escalationsuse · rancher · CWE-441 | Kritik9,1 | — | %0,6 | 5 Ağu 2026 |
36İzleyin | CVE-2026-33768İstismar yok | Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`astro · \@astrojs\/vercel · CWE-441 | Kritik9,1 | — | %0,5 | 24 Mar 2026 |
35İzleyin | CVE-2019-3924Kavram kanıtı | MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability.mikrotik · routeros · CWE-441 | Yüksek7,5 | — | %15,7 | 20 Şub 2019 |
35İzleyin | CVE-2024-9870İstismar yok | Unintended Proxy or Intermediary ('Confused Deputy') in GitLabgitlab · gitlab · CWE-441 | Yüksek8,8 | — | %0,4 | 12 Şub 2025 |
35İzleyin | CVE-2026-36608İstismar yok | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external ports to the router's own admCWE-441 | Yüksek8,8 | — | %0,3 | 3 Haz 2026 |
34İzleyin | CVE-2021-32783İstismar yok | Authorization bypass in Contourprojectcontour · contour · CWE-441 | Yüksek8,5 | — | %1,2 | 23 Tem 2021 |
34İzleyin | CVE-2026-44494İstismar yok | Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`axios · axios · CWE-441 | Yüksek8,7 | — | %0,9 | 11 Haz 2026 |
34İzleyin | CVE-2026-17107İstismar yok | Cluster-proxy: impersonation-header injection grants cluster-admin on every managed clusterred hat · multicluster engine for kubernetes 2.1 · CWE-441 | Yüksek8,5 | — | %0,6 | 24 Tem 2026 |
34İzleyin | CVE-2026-100625İstismar yok | Capgo Build Upload Proxy Authorization Bypass via TUS Resourcecap-go · capgo.app · CWE-441 | Yüksek8,7 | — | %0,3 | 3 gün önce |
34İzleyin | CVE-2025-11393İstismar yok | Insights-runtimes-tech-preview/runtimes-inventory-rhel8-operator: improper proxy configuration allows unauthorized administrative commandsred hat · red hat lightspeed (formerly insights) for runtimes 1.0 · CWE-441 | Yüksek8,7 | — | %0,2 | 15 Ara 2025 |
33İzleyin | CVE-2019-1841İstismar yok | Cisco DNA Center Unintended Proxy Via SWIM Import Interface Vulnerabilitycisco · catalyst center · CWE-441 | Yüksek8,1 | — | %2,6 | 17 Nis 2019 |
33İzleyin | CVE-2026-87582İstismar yok | Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process tgoogle · chrome · CWE-441 | Yüksek8,3 | — | %0,4 | 8 Eyl 2026 |
- CVE-2026-8354873Bu hafta
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path.
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %9sonicwall · sma8200v1 Eyl 2026
- CVE-2025-4726946Planlayın
code-server session cookie can be extracted by having user visit specially crafted proxy URL
YüksekCVSS 8,3İstismar yokEPSS %43coder · code-server9 May 2025
- CVE-2021-2004240Planlayın
An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules.
KritikCVSS 9,8İstismar yokEPSS %3sonicwall · sma 200 firmware8 Ara 2021
- CVE-2026-4293340Planlayın
Unintended Proxy or Intermediary in Panduit IntraVUE by Pronetiqs
KritikCVSS 10,0İstismar yokEPSS %1pronetiqs · panduit intravue23 Tem 2026
- CVE-2026-1615840Planlayın
@fastify/reply-from vulnerable to cross-upstream request routing via URL cache key collision
KritikCVSS 10,0İstismar yokEPSS %0fastify · fastify\/reply-from18 Tem 2026
- CVE-2026-7252639İzleyin
Multicloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster
KritikCVSS 9,9İstismar yokEPSS %1red hat · red hat advanced cluster management for kubernetes 2.1111 Ağu 2026
- CVE-2026-6756739İzleyin
Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart applied with controller sa without gvk or namespace restriction
KritikCVSS 9,9İstismar yokEPSS %1red hat · red hat advanced cluster management for kubernetes 2.1120 Ağu 2026
- CVE-2026-6939939İzleyin
Azure Arc Elevation of Privilege Vulnerability
KritikCVSS 9,8İstismar yokEPSS %0microsoft · azure arc17 Eyl 2026
- CVE-2026-7039838İzleyin
Multicloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonamespace writes spoke bearer tokens to attacker-chosen namespace
KritikCVSS 9,6İstismar yokEPSS %1red hat · red hat advanced cluster management for kubernetes 2.1111 Ağu 2026
- CVE-2026-10070637İzleyin
kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPath
KritikCVSS 9,4İstismar yokEPSS %1kyverno · kyverno3 gün önce
- CVE-2026-2447137İzleyin
Improper Validation in Conduit-derived homeservers resulting in Unintended Proxy or Intermediary ('Confused Deputy')
KritikCVSS 9,3İstismar yokEPSS %0continuwuity · continuwuity2 Şub 2026
- CVE-2025-6412537İzleyin
Nuvation Energy nCloud Client-to-Client Communication
KritikCVSS 9,4İstismar yokEPSS %0nuvation energy · ncloud vpn service2 Oca 2026
- CVE-2015-294736İzleyin
KanColleViewer versions 3.8.1 and earlier operates as an open proxy which allows remote attackers to trigger outbound network traffic.
KritikCVSS 9,1İstismar yokEPSS %2grabacr.net · kancolleviewer13 Nis 2017
- CVE-2026-4494536İzleyin
Cross-Cluster Impersonation Confused-Deputy Privilege Escalation
KritikCVSS 9,1İstismar yokEPSS %1suse · rancher5 Ağu 2026
- CVE-2026-3376836İzleyin
Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`
KritikCVSS 9,1İstismar yokEPSS %0astro · \@astrojs\/vercel24 Mar 2026
- CVE-2019-392435İzleyin
MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability.
YüksekCVSS 7,5Kavram kanıtıEPSS %16mikrotik · routeros20 Şub 2019
- CVE-2024-987035İzleyin
Unintended Proxy or Intermediary ('Confused Deputy') in GitLab
YüksekCVSS 8,8İstismar yokEPSS %0gitlab · gitlab12 Şub 2025
- CVE-2026-3660835İzleyin
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external ports to the router's own adm
YüksekCVSS 8,8İstismar yokEPSS %03 Haz 2026
- CVE-2021-3278334İzleyin
Authorization bypass in Contour
YüksekCVSS 8,5İstismar yokEPSS %1projectcontour · contour23 Tem 2021
- CVE-2026-4449434İzleyin
Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
YüksekCVSS 8,7İstismar yokEPSS %1axios · axios11 Haz 2026
- CVE-2026-1710734İzleyin
Cluster-proxy: impersonation-header injection grants cluster-admin on every managed cluster
YüksekCVSS 8,5İstismar yokEPSS %1red hat · multicluster engine for kubernetes 2.124 Tem 2026
- CVE-2026-10062534İzleyin
Capgo Build Upload Proxy Authorization Bypass via TUS Resource
YüksekCVSS 8,7İstismar yokEPSS %0cap-go · capgo.app3 gün önce
- CVE-2025-1139334İzleyin
Insights-runtimes-tech-preview/runtimes-inventory-rhel8-operator: improper proxy configuration allows unauthorized administrative commands
YüksekCVSS 8,7İstismar yokEPSS %0red hat · red hat lightspeed (formerly insights) for runtimes 1.015 Ara 2025
- CVE-2019-184133İzleyin
Cisco DNA Center Unintended Proxy Via SWIM Import Interface Vulnerability
YüksekCVSS 8,1İstismar yokEPSS %3cisco · catalyst center17 Nis 2019
- CVE-2026-8758233İzleyin
Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process t
YüksekCVSS 8,3İstismar yokEPSS %0google · chrome8 Eyl 2026