The product has two different sources of the same data or information, but it uses the source that has less support for verification, is less trusted, or is less resistant to attack.
Volume of CVEs assigned to CWE-348 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
63 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-48772CRITICAL ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL frontend accepts the `PROXY UNKNOWN <addr> <addr> <port> <po | Jun 19, 2026 | 10.0 | 42 | NO | NO |
CVE-2026-58122CRITICAL Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding e | Jul 9, 2026 | 9.1 | 40 | NO | NO |
CVE-2026-9561HIGH Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log entries. The org.eclips | Jul 14, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-59999HIGH In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not. | Jul 8, 2026 | 7.5 | 37 | NO | NO |
CVE-2026-46415HIGH The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the client's IP address. Prior to version 0.10.1, Caddy Defender used | Jul 20, 2026 | 8.2 | 36 | NO | NO |
CVE-2026-55641HIGH 9Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by reading the client-controlled Host header, allowing a remote u | Jul 10, 2026 | 8.2 | 36 | NO | NO |
CVE-2025-59951CRITICAL Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The official Docker image for Termix versions 1.5.0 and below, due to | Oct 1, 2025 | 9.1 | 36 | NO | NO |
CVE-2026-44183CRITICAL Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, TrustedNetworkAut | May 12, 2026 | 9.8 | 35 | NO | NO |
CVE-2026-64619HIGH FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateLimit class that allows unauthenticated attackers to circumvent request throttling by supplying attac | Jul 20, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-12249CRITICAL An issue was discovered in Canonical ADSys upstream versions through v0.16.2. During Active Directory Certificate Services (AD CS) certificate auto-enrollment via the vendored Samb | Jun 22, 2026 | 9.0 | 33 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.