Skip to main content

CWE archive

CWE-300 CVEs

Programmatic archive

55 CVEs tagged with CWE-3004 Critical, 22 High, 25 Medium, 4 Low, 0 Unrated.

CVE-2026-12991

Published Jul 27, 2026

The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Vision 60 robot (APK v5.5.0) exposes the system to man-in-the-mi…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-23812

Published Mar 4, 2026

A vulnerability has been identified where an attacker connecting to an access point as a standard wired or wireless client can impersonate a gateway by leveraging an address-based…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-23811

Published Mar 4, 2026

A vulnerability in the client isolation mechanism may allow an attacker to bypass Layer 2 (L2) communication restrictions between clients and redirect traffic at Layer 3 (L3). In…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-23810

Published Mar 4, 2026

A vulnerability in the packet processing logic may allow an authenticated attacker to craft and transmit a malicious Wi-Fi frame that causes an Access Point (AP) to classify the f…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-40770

Published Aug 12, 2025

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions). The affected application uses a monitoring interface that is not operating in a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54792

Published Aug 1, 2025

LocalSend is an open-source app to securely share files and messages with nearby devices over local networks without needing an internet connection. In versions 1.16.1 and below,…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-50568

Published Jun 10, 2025

A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 & FortiProxy version 7.4.0 thro…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-31214

Published May 12, 2025

This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPadOS 18.5. An attacker in a privileged network position may be able to intercept…

CVSS 8.1 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-20122

Published May 7, 2025

A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, local attacker to gain privileges of the root user on the…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-38272

Published Mar 27, 2025

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.3.4.1 could allow a user wit…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36553

Published Feb 6, 2025

Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h is vulnerable to MITM attack.

CVSS 8.1 · High

CVE-2024-12602

Published Feb 6, 2025

Identity verification vulnerability in the ParamWatcher module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-27263

Published Jan 28, 2025

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to obtain sensitive information from the dashboard UI using man i…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45407

Published Sep 10, 2024

Sunshine is a self-hosted game stream host for Moonlight. Clients that experience a MITM attack during the pairing process may inadvertantly allow access to an unintended client r…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32049

Published May 8, 2024

BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instance credentials.  Note: Software versions which have reached…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19751

Published Apr 30, 2024

easyMINE before 2019-12-05 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes tri…

CVSS 5.6 · Medium

CVE-2023-32634

Published Oct 12, 2023

An authentication bypass vulnerability exists in the CiRpcServerThread() functionality of SoftEther VPN 5.01.9674 and 4.41-9782-beta. An attacker can perform a local man-in-the-mi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-4885

Published Oct 3, 2023

Man in the Middle vulnerability, which could allow an attacker to intercept VNF (Virtual Network Function) communications resulting in the exposure of sensitive information.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-27768

Published May 12, 2022

Using the ability to perform a Man-in-the-Middle (MITM) attack, which indicates a lack of hostname verification, sensitive account information was able to be intercepted. In this…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 55 CVEsPage 1 of 3