The product creates a communication channel to initiate an outgoing request to an actor, but it does not correctly specify the intended destination for that actor.
Volume of CVEs assigned to CWE-941 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-69515CRITICAL An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system into accepting falsified GPS signals as legitimate, resulting i | Apr 7, 2026 | 9.1 | 31 | NO | NO |
CVE-2024-29415HIGH The ip package through 2.0.1 for Node.js might allow SSRF because some IP addresses (such as 127.1, 01200034567, 012.1.2.3, 000:0:0000::01, and ::fFFf:127.0.0.1) are improperly cat | May 27, 2024 | 8.1 | 30 | NO | NO |
CVE-2025-53899HIGH Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, the back-end of Kiteworks MFT is vulnerable to an incorrectly specified destination in a comm | Nov 29, 2025 | 7.2 | 25 | NO | NO |
CVE-2024-34947CRITICAL Quanxun Huiju Network Technology (Beijing) Co.,Ltd IK-Q3000 3.7.10 x64 Build202401261655 was discovered to be vulnerable to an ICMP redirect attack. | May 20, 2024 | 9.4 | 25 | NO | NO |
CVE-2019-18242HIGH In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, frequent and multiple requests for short-term use may cause | Mar 24, 2020 | 7.5 | 23 | NO | NO |
CVE-2026-40118MEDIUM UDP Console provided by Arcserve contains an incorrectly specified destination in a communication channel vulnerability. When a user configures an activation server hostname of the | Apr 16, 2026 | 6.3 | 22 | NO | NO |
CVE-2023-33198HIGH tgstation-server is a production scale tool for BYOND server management. The DreamMaker API (DMAPI) chat channel cache can possibly be poisoned by a tgstation-server (TGS) restart | May 30, 2023 | 7.5 | 22 | NO | NO |
CVE-2022-4847MEDIUM Incorrectly Specified Destination in a Communication Channel in GitHub repository usememos/memos prior to 0.9.1. | Dec 29, 2022 | 6.5 | 20 | NO | NO |
In AMD Versal Adaptive SoC devices, the incorrect configuration of the SSS during runtime (post-boot) cryptographic operations could cause data to be incorrectly written to and rea | Jun 10, 2025 | 3.2 | 14 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.