Skip to main content

CWE archive

CWE-349 CVEs

Programmatic archive

39 CVEs tagged with CWE-3493 Critical, 18 High, 13 Medium, 4 Low, 1 Unrated.

CVE-2026-50252

Published Jul 22, 2026

In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When…

CVSS 5.7 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-41120

Published Jun 25, 2026

Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trusted Data vulnerability. A low privileged attacker with remot…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33612

Published Jun 25, 2026

A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to cache poisoning.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-46342

Published Jun 12, 2026

Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.1.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6 and @nuxt/nitro-server versions 3.20.0 to be…

CVSS 2.3 · Low
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-42960

Published May 20, 2026

NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies…

CVSS 5.7 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-44572

Published May 13, 2026

Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an external client could send a x-nextjs-data header on a normal r…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-32162

Published Apr 14, 2026

Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized attacker to elevate privileges locally.

CVSS 8.4 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-35641

Published Apr 10, 2026

OpenClaw before 2026.3.24 contains an arbitrary code execution vulnerability in local plugin and hook installation that allows attackers to execute malicious code by crafting a .n…

CVSS 8.4 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-68269

Published Dec 16, 2025

In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1680

Published Oct 23, 2025

An acceptance of extraneous untrusted data with trusted data vulnerability has been identified in Moxa’s Ethernet switches, which allows attackers with administrative privileges t…

CVSS 0.0 · Unrated
evidence mentions
2
Buzz score
21.0

CVE-2025-40778

Published Oct 22, 2025

Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. This issue affects BIND 9 versions…

CVSS 8.6 · High
evidence mentions
3
Buzz score
20.4

CVE-2025-11411

Published Oct 22, 2025

NLnet Labs Unbound up to and including version 1.24.1 is vulnerable to possible domain hijack attacks. Promiscuous NS RRSets that complement positive DNS replies in the authority…

CVSS 5.7 · Medium
evidence mentions
4
Buzz score
27.6

CVE-2025-11703

Published Oct 18, 2025

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 9.0.48. This is due to the plugin not serving…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2025-5994

Published Jul 16, 2025

A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in caching resolvers that support EDNS Client Subnet (ECS). Unbound is also vulnerable w…

CVSS 8.7 · High

CVE-2025-40776

Published Jul 16, 2025

A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack. This issue affects BIND 9 versions 9.11.3-S1…

CVSS 8.6 · High

CVE-2025-46339

Published Jun 4, 2025

FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, it's possible to poison feed favicons by adding a given URL as a feed with the proxy set to an attacker-con…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-20255

Published May 21, 2025

A vulnerability in client join services of Cisco Webex Meetings could allow an unauthenticated, remote attacker to manipulate cached HTTP responses within the meeting join service…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-27415

Published Mar 19, 2025

Nuxt is an open-source web development framework for Vue.js. Prior to 3.16.0, by sending a crafted HTTP request to a server behind an CDN, it is possible in some circumstances to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53848

Published Nov 29, 2024

check-jsonschema is a CLI and set of pre-commit hooks for jsonschema validation. The default cache strategy uses the basename of a remote schema as the name of the file in the cac…

CVSS 7.1 · High

CVE-2024-52555

Published Nov 15, 2024

In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer script

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 39 CVEsPage 1 of 2