CWE-300: CWE-300
Yearly Trend
Top Affected Vendors
All CWE-300 CVEs (9)
The dectalk-tts Node package versions 1.0.0 sends API requests over unencrypted HTTP, allowing attackers to intercept and modify traffic in man-in-the...
Apr 4, 2024The Forever KidsWatch Call Me KW-50 smartwatch is vulnerable to man-in-the-middle (MITM) attacks due to insufficient security in its communication pro...
Feb 6, 2025This vulnerability allows man-in-the-middle attacks when Eclipse Equinox installations use HTTP repositories for p2 updates. Attackers can intercept a...
Sep 13, 2021This vulnerability allows authenticated local attackers with read-only privileges on Cisco Catalyst SD-WAN Manager to escalate to root privileges on t...
May 7, 2025An authentication bypass vulnerability in SoftEther VPN allows local attackers to perform man-in-the-middle attacks against the CiRpcServerThread func...
Oct 12, 2023This vulnerability allows an authenticated attacker to intercept password change requests and replace the legitimate password hash with their own, loc...
Jun 3, 2021This vulnerability in Sunshine game streaming software allows an attacker to gain unauthorized access by exploiting a flaw in the pairing process. Dur...
Sep 10, 2024This vulnerability in IBM Cloud Pak System allows authenticated users with network access to view sensitive information from command-line interface ar...
Mar 27, 2025This vulnerability allows attackers to bypass client isolation mechanisms in network devices, potentially enabling traffic redirection and man-in-the-...
Mar 4, 2026About CWE-300 (CWE-300)
Our database tracks 9 CVEs classified as CWE-300, with 0 rated critical and 6 rated high severity. The average CVSS score for CWE-300 vulnerabilities is 7.1.
External reference: View CWE-300 on MITRE CWE →
Monitor CWE-300 Vulnerabilities
Get alerted when new CWE-300 CVEs affect your infrastructure.
Start Monitoring Free