Skip to main content

CWE archive

CWE-322 CVEs

Programmatic archive

25 CVEs tagged with CWE-3221 Critical, 20 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2026-58065

Published Jul 13, 2026

The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification. An attacker who can intercept the…

CVSS 8.1 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-11745

Published Jun 22, 2026

A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// con…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-45361

Published May 25, 2026

Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to i…

CVSS 8.1 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-44467

Published May 13, 2026

The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side. From 1.2581.0 to before 1.4304.0, Claude Desktop's SSH re…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-1354

Published Apr 21, 2026

Zero Motorcycles firmware versions 44 and prior enable an attacker to forcibly pair a device with the motorcycle via Bluetooth. Once paired, an attacker can utilize over-the-air…

CVSS 5.9 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2025-13914

Published Apr 9, 2026

A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed de…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33697

Published Mar 27, 2026

Cocos AI is a confidential computing system for AI. The current implementation of attested TLS (aTLS) in CoCoS is vulnerable to a relay attack affecting all versions from v0.4.0 t…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-1709

Published Feb 6, 2026

A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vu…

CVSS 9.4 · Critical
evidence mentions
6
Buzz score
31.0

CVE-2025-20163

Published Jun 4, 2025

A vulnerability in the SSH implementation of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to impersonate Cisco NDFC-managed devic…

CVSS 8.7 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-7516

Published Nov 12, 2024

A vulnerability in Brocade Fabric OS versions before 9.2.2 could allow man-in-the-middle attackers to conduct remote Service Session Hijacking that may arise from the attacker's a…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6572

Published Sep 9, 2024

Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem' in Checkmk before Checkmk 2.3.0p15, 2.2.0p33, 2.1.0p48 and 2.0.0 (EOL…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4871

Published May 14, 2024

A vulnerability was found in Satellite. When running a remote execution job on a host, the host's SSH key is not being checked. When the key changes, the Satellite still connects…

CVSS 6.8 · Medium

CVE-2022-39254

Published Sep 29, 2022

matrix-nio is a Python Matrix client library, designed according to sans I/O principles. Prior to version 0.20, when a users requests a room key from their devices, the software c…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39252

Published Sep 29, 2022

matrix-rust-sdk is an implementation of a Matrix client-server library in Rust, and matrix-sdk-crypto is the Matrix encryption library. Prior to version 0.6, when a user requests…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39250

Published Sep 29, 2022

Matrix JavaScript SDK is the Matrix Client-Server software development kit (SDK) for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver could…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39257

Published Sep 28, 2022

Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker cooperating with a malicious homeserver can construct messages app…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39255

Published Sep 28, 2022

Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker cooperating with a malicious homeserver can construct messages tha…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39251

Published Sep 28, 2022

Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages that legi…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39249

Published Sep 28, 2022

Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages appearing…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39248

Published Sep 28, 2022

matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to h…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39246

Published Sep 28, 2022

matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-34433

Published Aug 20, 2021

In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally succeeds without verifying the server sid…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 25 CVEsPage 1 of 1