CWE-940 · 52 kayıt
Improper Verification of Source of a Communication Channel
Bu sınıftaki CVE’ler
52 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
68Bu hafta | CVE-2025-61932Silahlaştırılmış | Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, motex · lanscope endpoint manager · CWE-940 | Kritik9,3 | KEV | %2,8 | 20 Eki 2025 |
39İzleyin | CVE-2024-40515İstismar yok | An issue in SHENZHEN TENDA TECHNOLOGY CO.,LTD Tenda AX2pro V16.03.29.48_cn allows a remote attacker to execute arbitrary code via the Routintenda · ax2 pro firmware · CWE-940 | Kritik9,8 | — | %0,7 | 16 Tem 2024 |
39İzleyin | CVE-2024-38886İstismar yok | An issue in Horizon Business Services Inc.horizoncloud · caterease · CWE-940 | Kritik9,8 | — | %0,6 | 2 Ağu 2024 |
39İzleyin | CVE-2023-41355İstismar yok | Chunghwa Telecom NOKIA G-040W-Q - Improper Input Validationnokia · g-040w-q firmware · CWE-940 | Kritik9,8 | — | %0,6 | 3 Kas 2023 |
39İzleyin | CVE-2023-41094İstismar yok | Touchlink authentication bypass due to packets processed after timeout or out of range in Ember ZNetsilabs · emberznet · CWE-940 | Kritik9,8 | — | %0,6 | 4 Eki 2023 |
38İzleyin | CVE-2026-85085İstismar yok | The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView.canva · canva · CWE-940 | Kritik9,6 | — | %0,4 | 4 Eyl 2026 |
37İzleyin | CVE-2026-33875İstismar yok | Authenticator Vulnerable to Authentication Flow Hijackgematik · authenticator · CWE-940 | Kritik9,3 | — | %0,5 | 27 Mar 2026 |
37İzleyin | CVE-2026-48745İstismar yok | Traccar Client: silent configuration hijack via unverified deep link redirects all GPS telemetrytraccar · traccar-client · CWE-940 | Kritik9,3 | — | %0,4 | 17 Haz 2026 |
35İzleyin | CVE-2023-48387İstismar yok | TAIWAN-CA(TWCA) JCICSecurityTool - Improper Input Validationtwca · jcicsecuritytool · CWE-940 | Yüksek8,8 | — | %1,0 | 15 Ara 2023 |
35İzleyin | CVE-2023-3663İstismar yok | CODESYS: Missing integrity check in CODESYS Development Systemcodesys · development system · CWE-940 | Yüksek8,8 | — | %1,0 | 3 Ağu 2023 |
35İzleyin | CVE-2024-40516İstismar yok | An issue in H3C Technologies Co., Limited H3C Magic RC3000 RC3000V100R009 allows a remote attacker to execute arbitrary code via the RoutingCWE-940 | Yüksek8,8 | — | %0,3 | 16 Tem 2024 |
34İzleyin | CVE-2026-78685İstismar yok | Le-yan|Medical Practice Management System - Remote Code Executionle-yan · medical practice management system · CWE-940 | Yüksek8,6 | — | %0,6 | 24 Ağu 2026 |
34İzleyin | CVE-2026-35643İstismar yok | OpenClaw < 2026.3.22 - Arbitrary Code Execution via Unvalidated WebView JavascriptInterfaceopenclaw · openclaw · CWE-940 | Yüksek8,6 | — | %0,5 | 10 Nis 2026 |
34İzleyin | CVE-2019-25613İstismar yok | Easy Chat Server 3.1 Denial of Service via message Parameterechatserver · easy chat server · CWE-940 | Yüksek8,7 | — | %0,5 | 22 Mar 2026 |
34İzleyin | CVE-2025-40820İstismar yok | Affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within a broad range.siemens · sidoor atd430w · CWE-940 | Yüksek8,7 | — | %0,5 | 9 Ara 2025 |
34İzleyin | CVE-2026-89178İstismar yok | Howyar|WeenyGenius - Origin Validation Errorhowyar · weenygenius · CWE-940 | Yüksek8,7 | — | %0,4 | 11 Eyl 2026 |
33İzleyin | CVE-2024-1621İstismar yok | uniFLOW Online device registration susceptible to compromisent-ware · uniflow online · CWE-940 | Yüksek8,3 | — | %0,4 | 2 Eyl 2024 |
33İzleyin | CVE-2025-23222İstismar yok | An issue was discovered in Deepin dde-api-proxy through 1.0.19 in which unprivileged users can access D-Bus services as root.deepin · dde-api-proxy · CWE-940 | Yüksek8,4 | — | %0,2 | 24 Oca 2025 |
32İzleyin | CVE-2026-40434İstismar yok | Anviz CrossChex Standard Improper Verification of Source of a Communication Channelanviz · crosschex standard · CWE-940 | Yüksek8,1 | — | %0,4 | 17 Nis 2026 |
32İzleyin | GHSA-g8fc-vrcg-8vjgİstismar yok | Constallation has pods exposed to peers in VPCGo · github.com/edgelesssys/constellation/v2 · CWE-940 | Yüksek8,0 | — | — | 15 Nis 2024 |
30İzleyin | CVE-2023-51440İstismar yok | A vulnerability has been identified in SIMATIC CP 343-1 (6GK7343-1EX30-0XE0) (All versions), SIMATIC CP 343-1 Lean (6GK7343-1CX10-0XE0) (Allsiemens · simatic cp 343-1 · CWE-940 | Yüksek7,5 | — | %0,6 | 13 Şub 2024 |
30İzleyin | CVE-2026-44894İstismar yok | Netty's Default QUIC token handler accepts any client-supplied tokennetty · netty · CWE-940 | Yüksek7,5 | — | %0,2 | 12 Haz 2026 |
30İzleyin | CVE-2025-9999İstismar yok | Improper validation of payload elementsarcinfo · pcvue · CWE-940 | Yüksek7,6 | — | %0,2 | 5 Eyl 2025 |
28İzleyin | CVE-2025-25305İstismar yok | SSL validation for outgoing requests in Home Assistant Core and used libs not correcthome-assistant · core · CWE-940 | Yüksek7,0 | — | %0,3 | 18 Şub 2025 |
26İzleyin | CVE-2025-23018İstismar yok | IPv4-in-IPv6 and IPv6-in-IPv6 tunneling (RFC 2473) do not require the validation or verification of the source of a network packet, allowingietf · ipv6 · CWE-940 | Orta6,5 | — | %1,0 | 14 Oca 2025 |
- CVE-2025-6193268Bu hafta
Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests,
KritikCVSS 9,3KEVSilahlaştırılmışEPSS %3motex · lanscope endpoint manager20 Eki 2025
- CVE-2024-4051539İzleyin
An issue in SHENZHEN TENDA TECHNOLOGY CO.,LTD Tenda AX2pro V16.03.29.48_cn allows a remote attacker to execute arbitrary code via the Routin
KritikCVSS 9,8İstismar yokEPSS %1tenda · ax2 pro firmware16 Tem 2024
- CVE-2024-3888639İzleyin
An issue in Horizon Business Services Inc.
KritikCVSS 9,8İstismar yokEPSS %1horizoncloud · caterease2 Ağu 2024
- CVE-2023-4135539İzleyin
Chunghwa Telecom NOKIA G-040W-Q - Improper Input Validation
KritikCVSS 9,8İstismar yokEPSS %1nokia · g-040w-q firmware3 Kas 2023
- CVE-2023-4109439İzleyin
Touchlink authentication bypass due to packets processed after timeout or out of range in Ember ZNet
KritikCVSS 9,8İstismar yokEPSS %1silabs · emberznet4 Eki 2023
- CVE-2026-8508538İzleyin
The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView.
KritikCVSS 9,6İstismar yokEPSS %0canva · canva4 Eyl 2026
- CVE-2026-3387537İzleyin
Authenticator Vulnerable to Authentication Flow Hijack
KritikCVSS 9,3İstismar yokEPSS %0gematik · authenticator27 Mar 2026
- CVE-2026-4874537İzleyin
Traccar Client: silent configuration hijack via unverified deep link redirects all GPS telemetry
KritikCVSS 9,3İstismar yokEPSS %0traccar · traccar-client17 Haz 2026
- CVE-2023-4838735İzleyin
TAIWAN-CA(TWCA) JCICSecurityTool - Improper Input Validation
YüksekCVSS 8,8İstismar yokEPSS %1twca · jcicsecuritytool15 Ara 2023
- CVE-2023-366335İzleyin
CODESYS: Missing integrity check in CODESYS Development System
YüksekCVSS 8,8İstismar yokEPSS %1codesys · development system3 Ağu 2023
- CVE-2024-4051635İzleyin
An issue in H3C Technologies Co., Limited H3C Magic RC3000 RC3000V100R009 allows a remote attacker to execute arbitrary code via the Routing
YüksekCVSS 8,8İstismar yokEPSS %016 Tem 2024
- CVE-2026-7868534İzleyin
Le-yan|Medical Practice Management System - Remote Code Execution
YüksekCVSS 8,6İstismar yokEPSS %1le-yan · medical practice management system24 Ağu 2026
- CVE-2026-3564334İzleyin
OpenClaw < 2026.3.22 - Arbitrary Code Execution via Unvalidated WebView JavascriptInterface
YüksekCVSS 8,6İstismar yokEPSS %1openclaw · openclaw10 Nis 2026
- CVE-2019-2561334İzleyin
Easy Chat Server 3.1 Denial of Service via message Parameter
YüksekCVSS 8,7İstismar yokEPSS %1echatserver · easy chat server22 Mar 2026
- CVE-2025-4082034İzleyin
Affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within a broad range.
YüksekCVSS 8,7İstismar yokEPSS %0siemens · sidoor atd430w9 Ara 2025
- CVE-2026-8917834İzleyin
Howyar|WeenyGenius - Origin Validation Error
YüksekCVSS 8,7İstismar yokEPSS %0howyar · weenygenius11 Eyl 2026
- CVE-2024-162133İzleyin
uniFLOW Online device registration susceptible to compromise
YüksekCVSS 8,3İstismar yokEPSS %0nt-ware · uniflow online2 Eyl 2024
- CVE-2025-2322233İzleyin
An issue was discovered in Deepin dde-api-proxy through 1.0.19 in which unprivileged users can access D-Bus services as root.
YüksekCVSS 8,4İstismar yokEPSS %0deepin · dde-api-proxy24 Oca 2025
- CVE-2026-4043432İzleyin
Anviz CrossChex Standard Improper Verification of Source of a Communication Channel
YüksekCVSS 8,1İstismar yokEPSS %0anviz · crosschex standard17 Nis 2026
- GHSA-g8fc-vrcg-8vjg32İzleyin
Constallation has pods exposed to peers in VPC
YüksekCVSS 8,0İstismar yokGo · github.com/edgelesssys/constellation/v215 Nis 2024
- CVE-2023-5144030İzleyin
A vulnerability has been identified in SIMATIC CP 343-1 (6GK7343-1EX30-0XE0) (All versions), SIMATIC CP 343-1 Lean (6GK7343-1CX10-0XE0) (All
YüksekCVSS 7,5İstismar yokEPSS %1siemens · simatic cp 343-113 Şub 2024
- CVE-2026-4489430İzleyin
Netty's Default QUIC token handler accepts any client-supplied token
YüksekCVSS 7,5İstismar yokEPSS %0netty · netty12 Haz 2026
- CVE-2025-999930İzleyin
Improper validation of payload elements
YüksekCVSS 7,6İstismar yokEPSS %0arcinfo · pcvue5 Eyl 2025
- CVE-2025-2530528İzleyin
SSL validation for outgoing requests in Home Assistant Core and used libs not correct
YüksekCVSS 7,0İstismar yokEPSS %0home-assistant · core18 Şub 2025
- CVE-2025-2301826İzleyin
IPv4-in-IPv6 and IPv6-in-IPv6 tunneling (RFC 2473) do not require the validation or verification of the source of a network packet, allowing
OrtaCVSS 6,5İstismar yokEPSS %1ietf · ipv614 Oca 2025