İçeriğe atla
Noroxi

CWE-441 · 143 kayıt

Unintended Proxy or Intermediary ('Confused Deputy')

Bu sınıftaki CVE’ler

143 kayıt

  • CVE-2026-83548
    73Bu hafta

    A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path.

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %9

    sonicwall · sma8200v1 Eyl 2026

  • CVE-2025-47269
    46Planlayın

    code-server session cookie can be extracted by having user visit specially crafted proxy URL

    YüksekCVSS 8,3İstismar yokEPSS %43

    coder · code-server9 May 2025

  • CVE-2021-20042
    40Planlayın

    An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules.

    KritikCVSS 9,8İstismar yokEPSS %3

    sonicwall · sma 200 firmware8 Ara 2021

  • CVE-2026-42933
    40Planlayın

    Unintended Proxy or Intermediary in Panduit IntraVUE by Pronetiqs

    KritikCVSS 10,0İstismar yokEPSS %1

    pronetiqs · panduit intravue23 Tem 2026

  • CVE-2026-16158
    40Planlayın

    @fastify/reply-from vulnerable to cross-upstream request routing via URL cache key collision

    KritikCVSS 10,0İstismar yokEPSS %0

    fastify · fastify\/reply-from18 Tem 2026

  • CVE-2026-72526
    39İzleyin

    Multicloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster

    KritikCVSS 9,9İstismar yokEPSS %1

    red hat · red hat advanced cluster management for kubernetes 2.1111 Ağu 2026

  • CVE-2026-67567
    39İzleyin

    Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart applied with controller sa without gvk or namespace restriction

    KritikCVSS 9,9İstismar yokEPSS %1

    red hat · red hat advanced cluster management for kubernetes 2.1120 Ağu 2026

  • CVE-2026-69399
    39İzleyin

    Azure Arc Elevation of Privilege Vulnerability

    KritikCVSS 9,8İstismar yokEPSS %0

    microsoft · azure arc17 Eyl 2026

  • CVE-2026-70398
    38İzleyin

    Multicloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonamespace writes spoke bearer tokens to attacker-chosen namespace

    KritikCVSS 9,6İstismar yokEPSS %1

    red hat · red hat advanced cluster management for kubernetes 2.1111 Ağu 2026

  • CVE-2026-100706
    37İzleyin

    kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPath

    KritikCVSS 9,4İstismar yokEPSS %1

    kyverno · kyverno3 gün önce

  • CVE-2026-24471
    37İzleyin

    Improper Validation in Conduit-derived homeservers resulting in Unintended Proxy or Intermediary ('Confused Deputy')

    KritikCVSS 9,3İstismar yokEPSS %0

    continuwuity · continuwuity2 Şub 2026

  • CVE-2025-64125
    37İzleyin

    Nuvation Energy nCloud Client-to-Client Communication

    KritikCVSS 9,4İstismar yokEPSS %0

    nuvation energy · ncloud vpn service2 Oca 2026

  • CVE-2015-2947
    36İzleyin

    KanColleViewer versions 3.8.1 and earlier operates as an open proxy which allows remote attackers to trigger outbound network traffic.

    KritikCVSS 9,1İstismar yokEPSS %2

    grabacr.net · kancolleviewer13 Nis 2017

  • CVE-2026-44945
    36İzleyin

    Cross-Cluster Impersonation Confused-Deputy Privilege Escalation

    KritikCVSS 9,1İstismar yokEPSS %1

    suse · rancher5 Ağu 2026

  • CVE-2026-33768
    36İzleyin

    Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`

    KritikCVSS 9,1İstismar yokEPSS %0

    astro · \@astrojs\/vercel24 Mar 2026

  • CVE-2019-3924
    35İzleyin

    MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability.

    YüksekCVSS 7,5Kavram kanıtıEPSS %16

    mikrotik · routeros20 Şub 2019

  • CVE-2024-9870
    35İzleyin

    Unintended Proxy or Intermediary ('Confused Deputy') in GitLab

    YüksekCVSS 8,8İstismar yokEPSS %0

    gitlab · gitlab12 Şub 2025

  • CVE-2026-36608
    35İzleyin

    Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external ports to the router's own adm

    YüksekCVSS 8,8İstismar yokEPSS %0

    3 Haz 2026

  • CVE-2021-32783
    34İzleyin

    Authorization bypass in Contour

    YüksekCVSS 8,5İstismar yokEPSS %1

    projectcontour · contour23 Tem 2021

  • CVE-2026-44494
    34İzleyin

    Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

    YüksekCVSS 8,7İstismar yokEPSS %1

    axios · axios11 Haz 2026

  • CVE-2026-17107
    34İzleyin

    Cluster-proxy: impersonation-header injection grants cluster-admin on every managed cluster

    YüksekCVSS 8,5İstismar yokEPSS %1

    red hat · multicluster engine for kubernetes 2.124 Tem 2026

  • CVE-2026-100625
    34İzleyin

    Capgo Build Upload Proxy Authorization Bypass via TUS Resource

    YüksekCVSS 8,7İstismar yokEPSS %0

    cap-go · capgo.app3 gün önce

  • CVE-2025-11393
    34İzleyin

    Insights-runtimes-tech-preview/runtimes-inventory-rhel8-operator: improper proxy configuration allows unauthorized administrative commands

    YüksekCVSS 8,7İstismar yokEPSS %0

    red hat · red hat lightspeed (formerly insights) for runtimes 1.015 Ara 2025

  • CVE-2019-1841
    33İzleyin

    Cisco DNA Center Unintended Proxy Via SWIM Import Interface Vulnerability

    YüksekCVSS 8,1İstismar yokEPSS %3

    cisco · catalyst center17 Nis 2019

  • CVE-2026-87582
    33İzleyin

    Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process t

    YüksekCVSS 8,3İstismar yokEPSS %0

    google · chrome8 Eyl 2026

Tüm zafiyet sınıfları