CWE-349
19 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-349page 1 of 1
- CVE-2018-1131HIGHCVSS 8.82018-05-15
Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticated access to the server could send a malicious object to a cache configured to accept cert…
- CVE-2019-9535CRITICALCVSS 9.8EG 9.82019-10-09
A vulnerability exists in the way that iTerm2 integrates with tmux's control mode, which may allow an attacker to execute arbitrary commands by providing malicious output to the terminal. This affects versions of iTerm2 up to and including…
- CVE-2020-10751MEDIUMCVSS 6.1EG 6.12020-05-26
A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed that an skb would only contain a single netlink message. The hook would incorrectly only validate the first netlink mess…
- CVE-2020-8023HIGHCVSS 7.7EG 7.72020-09-01
A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the start script of openldap2 of SUSE Enterprise Storage 5, SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise …
- CVE-2021-21374HIGHCVSS 8.1EG 8.12021-03-26
Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, "nimble refresh" fetches a list of Nimble packages over HTTPS without full verification of the SSL/TLS certificate due …
- CVE-2023-3749HIGHCVSS 7.1EG 7.12023-08-03
A local user could edit the VideoEdge configuration file and interfere with VideoEdge operation.
- CVE-2023-44317HIGHCVSS 7.2EG 7.22023-11-14
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.2.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V7.2.2), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions …
- CVE-2023-51655MEDIUMCVSS 6.3EG 6.32023-12-21
In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the project configuration
- CVE-2023-5548LOWCVSS 3.3EG 3.32023-11-09
Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.
- CVE-2024-21094LOWCVSS 3.7EG 3.72024-04-16
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u401, 8u401-perf, 11.0.22, 17.0.10, 2…
- CVE-2024-25638HIGHCVSS 8.9EG 8.92024-07-22
dnsjava is an implementation of DNS in Java. Records in DNS replies are not checked for their relevance to the query, allowing an attacker to respond with RRs from different zones. This vulnerability is fixed in 3.6.0.
- CVE-2024-27185CRITICALCVSS 9.1EG 9.12024-08-20
The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors.
- CVE-2024-3367MEDIUMCVSS 6.5EG 6.52024-04-16
Argument injection in websphere_mq agent plugin in Checkmk 2.0.0, 2.1.0, <2.2.0p26 and <2.3.0b5 allows local attacker to inject one argument to runmqsc
- CVE-2024-34083MEDIUMCVSS 5.4EG 5.42024-05-18
aiosmptd is a reimplementation of the Python stdlib smtpd.py based on asyncio. Prior to version 1.4.6, servers based on aiosmtpd accept extra unencrypted commands after STARTTLS, treating them as if they came from inside the encrypted con…
- CVE-2024-41924HIGHCVSS 7.2EG 7.22024-07-30
Acceptance of extraneous untrusted data with trusted data vulnerability exists in EC-CUBE 4 series. If this vulnerability is exploited, an attacker who obtained the administrative privilege may install an arbitrary PHP package. If the obso…
- CVE-2024-42483MEDIUMCVSS 6.5EG 6.52024-09-12
ESP-NOW Component provides a connectionless Wi-Fi communication protocol. An replay attacks vulnerability was discovered in the implementation of the ESP-NOW because the caches is not differentiated by message types, it is a single, shared…
- CVE-2024-52555MEDIUMCVSS 6.3EG 6.32024-11-15
In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer script
- CVE-2024-53848HIGHCVSS 7.1EG 7.12024-11-29
check-jsonschema is a CLI and set of pre-commit hooks for jsonschema validation. The default cache strategy uses the basename of a remote schema as the name of the file in the cache, e.g. `https://example.org/schema.json` will be stored as…
- CVE-2026-42960CRITICALCVSS 10.0EG 10.02026-05-20
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used to trick Unbound to cac…
Map vulnerabilities like CWE-349 to your infrastructure
EchelonGraph correlates every CVE — across CWE-349 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →