Skip to main content

CWE archive

CWE-923 CVEs

Programmatic archive

65 CVEs tagged with CWE-9235 Critical, 23 High, 30 Medium, 7 Low, 0 Unrated.

CVE-2026-63226

Published Jul 23, 2026

Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. Whe…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2026-8920

Published Jul 15, 2026

Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operatio…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-59841

Published Jul 14, 2026

A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privi…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-57028

Published Jul 9, 2026

An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to caus…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33803

Published Jul 9, 2026

An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to caus…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-55655

Published Jun 23, 2026

A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred…

CVSS 5.0 · Medium
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2026-12539

Published Jun 18, 2026

Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time, and does not re-apply it to networks rebuilt from disk when the Docker daemon r…

CVSS 5.7 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-12039

Published Jun 18, 2026

Docker Sandboxes (sbx) enforces an HTTP/S-only egress allowlist but does not apply it to DNS resolution: the per-network embedded DNS server forwards any queried name to the host…

CVSS 5.7 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-36145

Published May 26, 2026

IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound connections which could allow an attacker to transfer or modify files without rest…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-36180

Published Apr 30, 2026

IBM watsonx.data 2.2 through 2.3 IBM Lakehouse does not properly restrict communication between pods which could allow an attacker to transfer data between pods without restrictio…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-34205

Published Mar 27, 2026

Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (formerly add-ons) configured with host network mode expose u…

CVSS 9.6 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2025-36438

Published Mar 25, 2026

IBM Concert 1.0.0 through 2.2.0 could allow a privileged user to perform unauthorized actions due to improper restriction of channel communication to intended endpoints.

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-32303

Published Mar 20, 2026

Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, an integrity check vulnerability allows an attacker to tamper with the vault configuration…

CVSS 7.6 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2025-62843

Published Mar 20, 2026

An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora. If an attacker gains physical access, they can then exploit…

CVSS 0.9 · Low
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-23664

Published Mar 10, 2026

Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

CVSS 7.5 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2025-27769

Published Mar 10, 2026

A vulnerability has been identified in Heliox Flex 180 kW EV Charging Station (All versions < F4.11.1), Heliox Mobile DC 40 kW EV Charging Station (All versions < L4.10.1). Affect…

CVSS 2.4 · Low

CVE-2026-22715

Published Feb 26, 2026

VMWare Workstation and Fusion contain a logic flaw in the management of network packets.  Known attack vectors: A malicious actor with administrative privileges on a Guest VM may…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-33176

Published Nov 4, 2025

NVIDIA RunAI for all platforms contains a vulnerability where a user could cause an improper restriction of communications channels on an adjacent network. A successful exploit of…

CVSS 6.2 · Medium

CVE-2025-12357

Published Oct 31, 2025

By manipulating the Signal Level Attenuation Characterization (SLAC) protocol with spoofed measurements, an attacker can stage a man-in-the-middle attack between an electric veh…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
28.9
Showing 1-25 of 65 CVEsPage 1 of 3