Skip to main content

CWE archive

CWE-348 CVEs

Programmatic archive

65 CVEs tagged with CWE-3488 Critical, 16 High, 33 Medium, 8 Low, 0 Unrated.

CVE-2026-25552

Published Jul 31, 2026

Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rate-limiting controls by manipulating the X-Forwarded-For hea…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-63220

Published Jul 31, 2026

CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-Forwarded-Proto and Front-End-Https headers from any incoming…

CVSS 4.8 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-50243

Published Jul 22, 2026

In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of the validator together with a 'response-ip' redirect rule o…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-64619

Published Jul 20, 2026

FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateLimit class that allows unauthenticated attackers to circumvent request throttling by supplying atta…

CVSS 8.7 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-63770

Published Jul 20, 2026

Glance through 0.8.5 contains an IP address spoofing vulnerability in the authentication handler that allows unauthenticated attackers to bypass brute-force lockout protections by…

CVSS 8.2 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-46415

Published Jul 20, 2026

The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the client's IP address. Prior to version 0.10.1, Caddy Defender use…

CVSS 8.2 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-9561

Published Jul 14, 2026

Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log entries. The org.eclip…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-55641

Published Jul 10, 2026

9Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by reading the client-controlled Host header, allowing a remote…

CVSS 8.2 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-58122

Published Jul 9, 2026

Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding…

CVSS 9.3 · Critical
evidence mentions
4
Buzz score
22.6

CVE-2026-59897

Published Jul 8, 2026

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS API Gateway v1 adapter can drop a distinct repeated reques…

CVSS 4.8 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-59999

Published Jul 8, 2026

In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.

CVSS 5.9 · Medium
evidence mentions
4
Buzz score
36.1
Vendor/product tagsBeta · best-effort

CVE-2026-46466

Published Jul 3, 2026

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release ve…

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-57942

Published Jun 29, 2026

LibreTranslate through 1.9.7, fixed in commit 397fd22, contains an IP spoofing vulnerability in the get_remote_address() function that allows unauthenticated attackers to spoof cl…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-54289

Published Jun 22, 2026

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda@Edge, CloudFront delivers a request header that appears more…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-12249

Published Jun 22, 2026

An issue was discovered in Canonical ADSys upstream versions through v0.16.2. During Active Directory Certificate Services (AD CS) certificate auto-enrollment via the vendored Sam…

CVSS 9.0 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-48772

Published Jun 19, 2026

ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL frontend accepts the `PROXY UNKNOWN <addr> <addr> <port> <p…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-44046

Published Jun 19, 2026

Use of Less Trusted Source vulnerability in Apache APISIX. Attacker can take advantage of wolf-rbac plugin under default configuration to potentially pollute logs with spoofed id…

CVSS 2.3 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2020-37248

Published Jun 8, 2026

OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS/man-in-the-middle attacks, taking over the connection and…

CVSS 6.5 · Medium
evidence mentions
5
Buzz score
29.4

CVE-2026-43634

Published May 19, 2026

HestiaCP versions 1.2.0 through 1.9.4 contain an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass authentication security controls by supplying an…

CVSS 8.7 · High
evidence mentions
5
Buzz score
29.4

CVE-2026-44183

Published May 12, 2026

Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, TrustedNetworkAu…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-40226

Published Apr 10, 2026

In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.

CVSS 6.4 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-35391

Published Apr 6, 2026

Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the getClientIP() function in lib/admin/session.ts trusted the first (leftmost) entry of…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-35507

Published Apr 3, 2026

Shynet before 0.14.0 allows Host header injection in the password reset flow.

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-26927

Published Apr 2, 2026

Szafir SDK Web is a browser plug-in that can run SzafirHost application which download the necessary files when launched. In Szafir SDK Web it is possible to change the URL (HTTP…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-33690

Published Mar 23, 2026

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `getRealIpAddr()` function in `objects/functions.php` trusts user-controlled HTTP headers t…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort
Showing 1-25 of 65 CVEsPage 1 of 3