CWE-441: CWE-441
Yearly Trend
Top Affected Vendors
All CWE-441 CVEs (27)
This vulnerability in Nuvation Energy Multi-Stack Controller allows the device to act as an unintended proxy or intermediary, potentially bridging net...
Jan 2, 2026CVE-2021-20042 allows unauthenticated remote attackers to use SonicWall SMA 100 series appliances as unintended proxies to bypass firewall rules. This...
Dec 8, 2021A misconfigured proxy in runtimes-inventory-rhel8-operator attaches cluster administrative credentials to all commands instead of only authorized repo...
Dec 15, 2025HCL Nomad server on Domino has an open proxy vulnerability allowing unauthenticated attackers to mask their source IP address. This enables attackers ...
Sep 25, 2024This vulnerability in Contour Kubernetes ingress controller allows attackers to access Envoy's admin interface via specially crafted ExternalName Serv...
Jul 23, 2021This vulnerability allows a malicious app to access images from other user profiles on the same Android device without proper authorization. It affect...
Dec 8, 2025This vulnerability allows malicious apps to access contacts from the work profile on Android devices through a confused deputy attack in the telephony...
Dec 8, 2025This vulnerability allows a third-party Android app to modify secure system settings without user interaction, enabling local privilege escalation. It...
Dec 8, 2025This vulnerability allows malicious apps to access sensitive information from other user profiles on Android devices through a confused deputy attack ...
Dec 8, 2025This CVE describes a confused deputy vulnerability in Android that allows unauthorized access to audio files across user profiles. An attacker could l...
Dec 8, 2025This vulnerability allows a malicious app to access work profile contact numbers from the voicemail settings component without proper permission check...
Sep 4, 2025This vulnerability in Android's Settings app allows a malicious app to bypass intent security checks through a confused deputy attack, enabling local ...
Sep 4, 2025This vulnerability in Android's ManagedProvisioning component allows a malicious app to access another user's data through a confused deputy attack, l...
Sep 4, 2025This CVE describes a confused deputy vulnerability in Android's Settings app that allows bypassing intent type checks. Attackers can exploit this to e...
Sep 4, 2025This vulnerability allows a malicious app to launch arbitrary activities on Android devices without user interaction, potentially leading to local pri...
Sep 4, 2025This vulnerability in Android's MediaSessionRecord allows a malicious app to send a pending intent on behalf of the system_server process, enabling lo...
Feb 15, 2024This vulnerability allows an attacker to bypass the WRITE_EXTERNAL_STORAGE permission in Android's MediaProvider component, enabling unauthorized writ...
Sep 4, 2025This vulnerability allows a malicious Android app to bypass user ID checks and access privileged system APIs, potentially gaining elevated privileges ...
Sep 4, 2025This vulnerability allows local attackers to bypass camera permissions on affected Android devices, potentially accessing camera data without user con...
Dec 11, 2025This CVE describes an information disclosure vulnerability in Android's App Widget component where a malicious app could trick the system into reveali...
Sep 5, 2025This CVE describes a confused deputy vulnerability in Android's Wear OS where a malicious app can monitor motion events without user interaction. This...
Sep 4, 2025This vulnerability allows a malicious app to access voicemail notification settings from other user profiles on the same Android device without requir...
Sep 4, 2025CVE-2025-66415 is an authorization bypass vulnerability in fastify-reply-from, a Fastify plugin for HTTP request forwarding. Attackers can craft malic...
Dec 1, 2025Gitea versions before 1.22.2 have a token scope propagation flaw in package registries that could allow authenticated users to access resources beyond...
Dec 26, 2025This Android vulnerability allows malicious apps to leak images across user isolation boundaries via a confused deputy attack. It requires user intera...
Sep 4, 2025This vulnerability in Matrix homeserver software allows a malicious remote server to trick a vulnerable server into signing arbitrary events during us...
Feb 2, 2026A vulnerability in Nuvation Energy nCloud VPN Service allowed network boundary bridging, potentially enabling unauthorized network access. This affect...
Jan 3, 2026About CWE-441 (CWE-441)
Our database tracks 27 CVEs classified as CWE-441, with 2 rated critical and 16 rated high severity. The average CVSS score for CWE-441 vulnerabilities is 7.3.
External reference: View CWE-441 on MITRE CWE →
Monitor CWE-441 Vulnerabilities
Get alerted when new CWE-441 CVEs affect your infrastructure.
Start Monitoring Free