CWE-349: CWE-349

12
Total CVEs
0
Critical
8
High
7.1
Avg CVSS

Yearly Trend

2026
1
2025
7
2024
3
2023
1

Top Affected Vendors

1 Microsoft 3
2 F5 1
3 Nuxt 1
4 Siemens 1
5 Jetbrains 1

All CWE-349 CVEs (12)

CVE-2025-40778
8.6

This CVE describes a DNS cache poisoning vulnerability in BIND where the server accepts records too leniently from answers, allowing attackers to inje...

Oct 22, 2025
CVE-2025-40776
8.6

A cache-poisoning vulnerability in BIND 9's named resolver when configured with ECS (EDNS Client Subnet) options allows attackers to inject malicious ...

Jul 16, 2025
CVE-2025-29842
7.5

This vulnerability in Microsoft's UrlMon component allows attackers to bypass security features by mixing untrusted data with trusted data. It affects...

May 13, 2025
CVE-2025-29816
7.5

This vulnerability allows attackers to bypass security features in Microsoft Word through improper input validation. Attackers can exploit this over a...

Apr 8, 2025
CVE-2025-27415
7.5

This vulnerability allows attackers to poison CDN caches by sending crafted HTTP requests to Nuxt applications, causing JSON responses to be served to...

Mar 19, 2025
CVE-2024-41924
7.2

This vulnerability in EC-CUBE 4 series allows attackers with administrative privileges to install arbitrary PHP packages. If exploited, this could lea...

Jul 30, 2024
CVE-2023-44317
7.2

This vulnerability affects multiple Siemens industrial networking devices where improper validation of uploaded X509 certificates could allow attacker...

Nov 14, 2023
CVE-2024-53848
7.1

This vulnerability in check-jsonschema allows cache confusion attacks where an attacker can replace legitimate JSON schemas with malicious ones. Users...

Nov 29, 2024
CVE-2025-48804
6.8

This vulnerability in Windows BitLocker allows an attacker with physical access to bypass the encryption security feature by mixing untrusted data wit...

Jul 8, 2025
CVE-2026-1642
5.9

A vulnerability in NGINX OSS and NGINX Plus allows attackers in a man-in-the-middle position on the upstream server side to inject plain text data int...

Feb 4, 2026
CVE-2025-68269
5.4

This vulnerability in JetBrains IntelliJ IDEA allows attackers to trick users into opening untrusted remote projects over SSH without proper confirmat...

Dec 16, 2025
CVE-2024-34083
5.4

This vulnerability in aiosmtpd allows man-in-the-middle attackers to inject unencrypted SMTP commands after STARTTLS negotiation, which are then proce...

May 18, 2024

About CWE-349 (CWE-349)

Our database tracks 12 CVEs classified as CWE-349, with 0 rated critical and 8 rated high severity. The average CVSS score for CWE-349 vulnerabilities is 7.1.

External reference: View CWE-349 on MITRE CWE →

Monitor CWE-349 Vulnerabilities

Get alerted when new CWE-349 CVEs affect your infrastructure.

Start Monitoring Free