The product assigns the address 0.0.0.0 for a database server, a cloud service/instance, or any computing resource that communicates remotely.
Volume of CVEs assigned to CWE-1327 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-47176MEDIUM CUPS is a standards-based, open-source printing system, and `cups-browsed` contains network printing functionality including, but not limited to, auto-discovering print services an | Sep 26, 2024 | 5.3 | 67 | NO | YES |
CVE-2026-55641HIGH 9Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by reading the client-controlled Host header, allowing a remote u | Jul 10, 2026 | 8.2 | 36 | NO | NO |
CVE-2026-0481CRITICAL Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to perform unauthorized changes to the GPU configuration, potentia | May 15, 2026 | 9.2 | 34 | NO | NO |
CVE-2025-61934CRITICAL A binding to an unrestricted IP address vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an unauthenticated remote attacker t | Oct 23, 2025 | 10.0 | 34 | NO | NO |
CVE-2026-42503HIGH gopls by default communicates via pipe. However, -port and -listen flags are supported as means of debugging.
If -listen is given a value without an explicit host (e.g. :8080), or | May 6, 2026 | 8.8 | 32 | NO | NO |
CVE-2026-24015CRITICAL A vulnerability in Apache IoTDB.
This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7.
Users are recommended to upgrade to version 1.3.7 or 2.0.7, wh | Mar 9, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-28395CRITICAL OpenClaw version 2026.1.14-1 prior to 2026.2.12 contains an improper network binding vulnerability in the Chrome extension (must be installed and enabled) relay server that treats | Mar 5, 2026 | 9.1 | 29 | NO | NO |
CVE-2025-3621CRITICAL Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems.
* vulnerabilities:
*
Improper Neutraliza | Jul 15, 2025 | 9.6 | 28 | NO | NO |
CVE-2025-55322HIGH Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network. | Sep 24, 2025 | 7.3 | 26 | NO | NO |
CVE-2023-1968HIGH
Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an unrestricted IP address. An unauthenticated malicious actor could use UCS to listen on al | Apr 28, 2023 | 7.5 | 25 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.