CWE-348: CWE-348

13
Total CVEs
1
Critical
4
High
6.4
Avg CVSS

Yearly Trend

2026
3
2025
7
2024
2
2022
1

Top Affected Vendors

1 Fedoraproject 1
2 Apache 1
3 Netapp 1
4 Pbootcms 1
5 Cyberark 1
6 Meshtastic 1
7 Miniorange 1
8 Passbolt 1
9 Unitronics 1

All CWE-348 CVEs (13)

CVE-2022-31813
9.8

This vulnerability in Apache HTTP Server allows attackers to bypass IP-based authentication by manipulating the Connection header to prevent X-Forward...

Jun 9, 2022
CVE-2024-27773
8.8

CVE-2024-27773 is a critical vulnerability in Unitronics Unistream Unilogic software that allows remote code execution by exploiting trust in less sec...

Mar 18, 2024
CVE-2025-55292
8.2

This vulnerability allows attackers to impersonate legitimate nodes in Meshtastic mesh networks by forging NodeInfo packets that claim HAM mode is ena...

Jan 28, 2026
CVE-2025-27913
7.5

This vulnerability allows attackers to manipulate email messages sent by Passbolt API by injecting malicious domain names via HTTP Host headers. It af...

Mar 10, 2025
CVE-2025-47424
7.1

This vulnerability allows attackers to manipulate the HTTP Host header in self-hosted Retool instances when the BASE_DOMAIN environment variable is no...

May 9, 2025
CVE-2025-43918
6.4

This vulnerability allows attackers to obtain trusted TLS certificates for domains they don't control by exploiting a flaw in SSL.com's domain validat...

Apr 19, 2025
CVE-2026-24910
5.9

This vulnerability allows attackers to spoof trusted dependencies in Bun by using non-npm packages with matching names, potentially leading to executi...

Jan 27, 2026
CVE-2025-13694
5.3

The AA Block Country WordPress plugin versions up to 1.0.1 trust user-supplied HTTP headers like X-Forwarded-For to determine client IP addresses with...

Jan 7, 2026
CVE-2025-15154
5.3

This vulnerability in PbootCMS allows attackers to spoof IP addresses by manipulating the X-Forwarded-For header. The system incorrectly trusts this h...

Dec 28, 2025
CVE-2025-53522
5.3

CVE-2025-53522 is a security vulnerability in Movable Type that allows remote unauthenticated attackers to send tampered password reset emails. This c...

Aug 20, 2025
CVE-2022-4539
5.3

The Web Application Firewall plugin for WordPress versions up to 2.1.2 is vulnerable to IP address spoofing. Attackers can manipulate the X-Forwarded-...

Aug 31, 2024
CVE-2025-24856
4.2

This vulnerability in TYPO3's OpenID Connect extension allows account takeover through pre-hijacking attacks. Attackers can link their own accounts to...

Mar 16, 2025
CVE-2024-54840
4.2

This vulnerability in CyberArk's Password Vault Web Access (PVWA) allows attackers to perform Host header injection attacks when environment issues ar...

Feb 3, 2025

About CWE-348 (CWE-348)

Our database tracks 13 CVEs classified as CWE-348, with 1 rated critical and 4 rated high severity. The average CVSS score for CWE-348 vulnerabilities is 6.4.

External reference: View CWE-348 on MITRE CWE →

Monitor CWE-348 Vulnerabilities

Get alerted when new CWE-348 CVEs affect your infrastructure.

Start Monitoring Free