CWE-441: CWE-441

27
Total CVEs
2
Critical
16
High
7.3
Avg CVSS

Yearly Trend

2026
3
2025
20
2024
2
2021
2

Top Affected Vendors

1 Google 18
2 Hcltech 1
3 Fastify 1
4 Gitea 1
5 Sonicwall 1
6 Projectcontour 1
7 Nuvationenergy 1

All CWE-441 CVEs (27)

CVE-2025-64123
9.8

This vulnerability in Nuvation Energy Multi-Stack Controller allows the device to act as an unintended proxy or intermediary, potentially bridging net...

Jan 2, 2026
CVE-2021-20042
9.8

CVE-2021-20042 allows unauthenticated remote attackers to use SonicWall SMA 100 series appliances as unintended proxies to bypass firewall rules. This...

Dec 8, 2021
CVE-2025-11393
8.7

A misconfigured proxy in runtimes-inventory-rhel8-operator attaches cluster administrative credentials to all commands instead of only authorized repo...

Dec 15, 2025
CVE-2024-30128
8.6

HCL Nomad server on Domino has an open proxy vulnerability allowing unauthenticated attackers to mask their source IP address. This enables attackers ...

Sep 25, 2024
CVE-2021-32783
8.5

This vulnerability in Contour Kubernetes ingress controller allows attackers to access Envoy's admin interface via specially crafted ExternalName Serv...

Jul 23, 2021
CVE-2025-48628
7.8

This vulnerability allows a malicious app to access images from other user profiles on the same Android device without proper authorization. It affect...

Dec 8, 2025
CVE-2025-48586
7.8

This vulnerability allows malicious apps to access contacts from the work profile on Android devices through a confused deputy attack in the telephony...

Dec 8, 2025
CVE-2025-48536
7.8

This vulnerability allows a third-party Android app to modify secure system settings without user interaction, enabling local privilege escalation. It...

Dec 8, 2025
CVE-2025-48555
7.8

This vulnerability allows malicious apps to access sensitive information from other user profiles on Android devices through a confused deputy attack ...

Dec 8, 2025
CVE-2025-22420
7.8

This CVE describes a confused deputy vulnerability in Android that allows unauthorized access to audio files across user profiles. An attacker could l...

Dec 8, 2025
CVE-2025-32346
7.8

This vulnerability allows a malicious app to access work profile contact numbers from the voicemail settings component without proper permission check...

Sep 4, 2025
CVE-2025-32326
7.8

This vulnerability in Android's Settings app allows a malicious app to bypass intent security checks through a confused deputy attack, enabling local ...

Sep 4, 2025
CVE-2025-26454
7.8

This vulnerability in Android's ManagedProvisioning component allows a malicious app to access another user's data through a confused deputy attack, l...

Sep 4, 2025
CVE-2025-32321
7.8

This CVE describes a confused deputy vulnerability in Android's Settings app that allows bypassing intent type checks. Attackers can exploit this to e...

Sep 4, 2025
CVE-2025-32324
7.8

This vulnerability allows a malicious app to launch arbitrary activities on Android devices without user interaction, potentially leading to local pri...

Sep 4, 2025
CVE-2023-40111
7.8

This vulnerability in Android's MediaSessionRecord allows a malicious app to send a pending intent on behalf of the system_server process, enabling lo...

Feb 15, 2024
CVE-2025-48532
7.3

This vulnerability allows an attacker to bypass the WRITE_EXTERNAL_STORAGE permission in Android's MediaProvider component, enabling unauthorized writ...

Sep 4, 2025
CVE-2025-48545
7.1

This vulnerability allows a malicious Android app to bypass user ID checks and access privileged system APIs, potentially gaining elevated privileges ...

Sep 4, 2025
CVE-2025-36889
5.5

This vulnerability allows local attackers to bypass camera permissions on affected Android devices, potentially accessing camera data without user con...

Dec 11, 2025
CVE-2025-32317
5.5

This CVE describes an information disclosure vulnerability in Android's App Widget component where a malicious app could trick the system into reveali...

Sep 5, 2025
CVE-2025-48560
5.5

This CVE describes a confused deputy vulnerability in Android's Wear OS where a malicious app can monitor motion events without user interaction. This...

Sep 4, 2025
CVE-2025-48529
5.5

This vulnerability allows a malicious app to access voicemail notification settings from other user profiles on the same Android device without requir...

Sep 4, 2025
CVE-2025-66415
5.4

CVE-2025-66415 is an authorization bypass vulnerability in fastify-reply-from, a Fastify plugin for HTTP request forwarding. Attackers can craft malic...

Dec 1, 2025
CVE-2025-68944
5.0

Gitea versions before 1.22.2 have a token scope propagation flaw in package registries that could allow authenticated users to access resources beyond...

Dec 26, 2025
CVE-2025-48551
5.0

This Android vulnerability allows malicious apps to leak images across user isolation boundaries via a confused deputy attack. It requires user intera...

Sep 4, 2025
CVE-2026-24471
N/A

This vulnerability in Matrix homeserver software allows a malicious remote server to trick a vulnerable server into signing arbitrary events during us...

Feb 2, 2026
CVE-2025-64125
N/A

A vulnerability in Nuvation Energy nCloud VPN Service allowed network boundary bridging, potentially enabling unauthorized network access. This affect...

Jan 3, 2026

About CWE-441 (CWE-441)

Our database tracks 27 CVEs classified as CWE-441, with 2 rated critical and 16 rated high severity. The average CVSS score for CWE-441 vulnerabilities is 7.3.

External reference: View CWE-441 on MITRE CWE →

Monitor CWE-441 Vulnerabilities

Get alerted when new CWE-441 CVEs affect your infrastructure.

Start Monitoring Free