CWE-348: CWE-348
Yearly Trend
Top Affected Vendors
All CWE-348 CVEs (13)
This vulnerability in Apache HTTP Server allows attackers to bypass IP-based authentication by manipulating the Connection header to prevent X-Forward...
Jun 9, 2022CVE-2024-27773 is a critical vulnerability in Unitronics Unistream Unilogic software that allows remote code execution by exploiting trust in less sec...
Mar 18, 2024This vulnerability allows attackers to impersonate legitimate nodes in Meshtastic mesh networks by forging NodeInfo packets that claim HAM mode is ena...
Jan 28, 2026This vulnerability allows attackers to manipulate email messages sent by Passbolt API by injecting malicious domain names via HTTP Host headers. It af...
Mar 10, 2025This vulnerability allows attackers to manipulate the HTTP Host header in self-hosted Retool instances when the BASE_DOMAIN environment variable is no...
May 9, 2025This vulnerability allows attackers to obtain trusted TLS certificates for domains they don't control by exploiting a flaw in SSL.com's domain validat...
Apr 19, 2025This vulnerability allows attackers to spoof trusted dependencies in Bun by using non-npm packages with matching names, potentially leading to executi...
Jan 27, 2026The AA Block Country WordPress plugin versions up to 1.0.1 trust user-supplied HTTP headers like X-Forwarded-For to determine client IP addresses with...
Jan 7, 2026This vulnerability in PbootCMS allows attackers to spoof IP addresses by manipulating the X-Forwarded-For header. The system incorrectly trusts this h...
Dec 28, 2025CVE-2025-53522 is a security vulnerability in Movable Type that allows remote unauthenticated attackers to send tampered password reset emails. This c...
Aug 20, 2025The Web Application Firewall plugin for WordPress versions up to 2.1.2 is vulnerable to IP address spoofing. Attackers can manipulate the X-Forwarded-...
Aug 31, 2024This vulnerability in TYPO3's OpenID Connect extension allows account takeover through pre-hijacking attacks. Attackers can link their own accounts to...
Mar 16, 2025This vulnerability in CyberArk's Password Vault Web Access (PVWA) allows attackers to perform Host header injection attacks when environment issues ar...
Feb 3, 2025About CWE-348 (CWE-348)
Our database tracks 13 CVEs classified as CWE-348, with 1 rated critical and 4 rated high severity. The average CVSS score for CWE-348 vulnerabilities is 6.4.
External reference: View CWE-348 on MITRE CWE →
Monitor CWE-348 Vulnerabilities
Get alerted when new CWE-348 CVEs affect your infrastructure.
Start Monitoring Free