Skip to main content

CWE archive

CWE-350 CVEs

Programmatic archive

24 CVEs tagged with CWE-3501 Critical, 9 High, 11 Medium, 2 Low, 1 Unrated.

CVE-2026-46611

Published Jun 25, 2026

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances XML-RPC server (glances -s, implemented in glances/server.py) does not validate the HT…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-12635

Published Jun 25, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have…

CVSS 0.0 · Unrated
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-36604

Published Jun 3, 2026

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 does not validate the HTTP Host header, enabling DNS rebinding attacks. An external attacker can rebind a domain to…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-42559

Published May 14, 2026

RMCP is an official Rust SDK for the Model Context Protocol. Prior to version 1.4.0, the rmcp crate's Streamable HTTP server transport (crates/rmcp/src/transport/streamable_http_s…

CVSS 8.8 · High
evidence mentions
5
Buzz score
22.9

CVE-2026-6874

Published Apr 23, 2026

A vulnerability was determined in ericc-ch copilot-api up to 0.7.0. This impacts an unknown function of the file /token of the component Header Handler. Executing a manipulation o…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-33002

Published Mar 18, 2026

Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made through the CLI WebSocket endpoint by co…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-24281

Published Mar 7, 2026

Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to imper…

CVSS 7.4 · High
evidence mentions
10
Buzz score
38.5
Vendor/product tagsBeta · best-effort

CVE-2026-28271

Published Feb 27, 2026

Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration functionality allows bypassing of SSRF protections through DNS rebind…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-1490

Published Feb 15, 2026

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse D…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
22.6

CVE-2025-61430

Published Oct 24, 2025

Improper handling of DNS over TCP in Simple DNS Plus v9 allows a remote attacker with querying access to the DNS server to cause the server to return request payloads from other c…

CVSS 6.5 · Medium

CVE-2025-59956

Published Sep 30, 2025

AgentAPI is an HTTP API for Claude Code, Goose, Aider, Gemini, Amp, and Codex. Versions 0.3.3 and below are susceptible to a client-side DNS rebinding attack when hosted over plai…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59163

Published Sep 29, 2025

vet is an open source software supply chain security tool. Versions 1.12.4 and below are vulnerable to a DNS rebinding attack due to lack of HTTP Host and Origin header validation…

CVSS 2.1 · Low

CVE-2025-8036

Published Jul 22, 2025

Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability was fixed in Firefox 141, Firefox ESR…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-24010

Published Jan 20, 2025

Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings an…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-53275

Published Dec 23, 2024

Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. In 1.15.0 and earlier, the default setup of home-gallery is vulnerable to DNS rebin…

CVSS 5.3 · Medium

CVE-2024-42364

Published Aug 23, 2024

Homepage is a highly customizable homepage with Docker and service API integrations. The default setup of homepage 0.9.1 is vulnerable to DNS rebinding. Homepage is setup without…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22364

Published May 3, 2024

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to external service interaction attack, caused by improper validation of user-supplied input. A remote attacker coul…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-52235

Published Apr 5, 2024

SpaceX Starlink Wi-Fi router GEN 2 before 2023.53.0 and Starlink Dish before 07dd2798-ff15-4722-a9ee-de28928aed34 allow CSRF (e.g., for a reboot) via a DNS Rebinding attack.

CVSS 8.8 · High

CVE-2020-11091

Published Jun 3, 2020

In Weave Net before version 2.6.3, an attacker able to run a process as root in a container is able to respond to DNS requests from the host and thereby insert themselves as a fak…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-7160

Published May 17, 2018

The Node.js inspector, in 6.x and later is vulnerable to a DNS rebinding attack which could be exploited to perform remote code execution. An attack is possible from malicious web…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-0902

Published Aug 31, 2017

RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a ser…

CVSS 8.1 · High
Showing 1-24 of 24 CVEsPage 1 of 1