CWE-349: CWE-349
Yearly Trend
Top Affected Vendors
All CWE-349 CVEs (12)
This CVE describes a DNS cache poisoning vulnerability in BIND where the server accepts records too leniently from answers, allowing attackers to inje...
Oct 22, 2025A cache-poisoning vulnerability in BIND 9's named resolver when configured with ECS (EDNS Client Subnet) options allows attackers to inject malicious ...
Jul 16, 2025This vulnerability in Microsoft's UrlMon component allows attackers to bypass security features by mixing untrusted data with trusted data. It affects...
May 13, 2025This vulnerability allows attackers to bypass security features in Microsoft Word through improper input validation. Attackers can exploit this over a...
Apr 8, 2025This vulnerability allows attackers to poison CDN caches by sending crafted HTTP requests to Nuxt applications, causing JSON responses to be served to...
Mar 19, 2025This vulnerability in EC-CUBE 4 series allows attackers with administrative privileges to install arbitrary PHP packages. If exploited, this could lea...
Jul 30, 2024This vulnerability affects multiple Siemens industrial networking devices where improper validation of uploaded X509 certificates could allow attacker...
Nov 14, 2023This vulnerability in check-jsonschema allows cache confusion attacks where an attacker can replace legitimate JSON schemas with malicious ones. Users...
Nov 29, 2024This vulnerability in Windows BitLocker allows an attacker with physical access to bypass the encryption security feature by mixing untrusted data wit...
Jul 8, 2025A vulnerability in NGINX OSS and NGINX Plus allows attackers in a man-in-the-middle position on the upstream server side to inject plain text data int...
Feb 4, 2026This vulnerability in JetBrains IntelliJ IDEA allows attackers to trick users into opening untrusted remote projects over SSH without proper confirmat...
Dec 16, 2025This vulnerability in aiosmtpd allows man-in-the-middle attackers to inject unencrypted SMTP commands after STARTTLS negotiation, which are then proce...
May 18, 2024About CWE-349 (CWE-349)
Our database tracks 12 CVEs classified as CWE-349, with 0 rated critical and 8 rated high severity. The average CVSS score for CWE-349 vulnerabilities is 7.1.
External reference: View CWE-349 on MITRE CWE →
Monitor CWE-349 Vulnerabilities
Get alerted when new CWE-349 CVEs affect your infrastructure.
Start Monitoring Free