CWE-923: CWE-923

18
Total CVEs
2
Critical
11
High
7.4
Avg CVSS

Yearly Trend

2026
1
2025
8
2024
8
2023
1

Top Affected Vendors

1 Microsoft 2
2 Dell 2
3 Juniper 2
4 Gotenna 2
5 Ibm 1
6 Columbiaweather 1
7 Openvpn 1
8 Docker 1
9 Element 1
10 Pimax 1

All CWE-923 CVEs (18)

CVE-2024-41889
9.8

This vulnerability allows remote unauthenticated attackers to execute arbitrary code on affected Pimax devices by exploiting improper WebSocket endpoi...

Aug 5, 2024
CVE-2023-28078
9.1

Dell OS10 Networking Switches running 10.5.2.x and above contain a zeroMQ vulnerability when VLT (Virtual Link Trunking) is configured. Remote unauthe...

Feb 15, 2024
CVE-2025-61939
8.8

This vulnerability in MicroServer allows an attacker with local network admin access and DNS manipulation capability to redirect a reverse SSH connect...

Jan 7, 2026
CVE-2025-20261
8.8

This vulnerability allows authenticated remote attackers to bypass SSH restrictions on Cisco UCS servers' IMC, gaining elevated privileges to access i...

Jun 4, 2025
CVE-2024-26131
8.4

Element Android versions 1.4.3 through 1.6.10 are vulnerable to intent redirection, allowing malicious apps to launch internal activities with arbitra...

Feb 29, 2024
CVE-2025-12357
8.3

This vulnerability allows attackers to perform man-in-the-middle attacks between electric vehicles and ISO 15118-2 compliant chargers by manipulating ...

Oct 31, 2025
CVE-2025-29986
8.3

Dell Common Event Enabler version 9.0.0.0 contains an improper restriction of communication channel vulnerability in its Common Anti-Virus Agent (CAVA...

Apr 8, 2025
CVE-2024-47490
8.2

An unauthenticated attacker can send specific MPLS packets to Juniper ACX 7000 Series devices running vulnerable Junos OS Evolved versions, causing th...

Oct 11, 2024
CVE-2024-47125
8.1

The goTenna Pro App fails to authenticate public keys, allowing unauthenticated attackers to intercept and manipulate messages. This affects all users...

Sep 26, 2024
CVE-2024-24974
7.5

CVE-2024-24974 allows remote attackers to interact with the privileged OpenVPN interactive service pipe, potentially enabling unauthorized access or c...

Jul 8, 2024
CVE-2023-28971
7.2

This vulnerability allows attackers to bypass firewall rules that restrict communication between Test Agents and the Control Center in Juniper Paragon...

Apr 17, 2023
CVE-2025-35978
7.1

This vulnerability allows local authenticated attackers to modify registry values or execute arbitrary code by sending malicious data to UpdateNavi so...

Jun 12, 2025
CVE-2024-6222
7.0

This vulnerability allows an attacker who has already broken out of a Docker container into the Docker Desktop VM to further escape to the host operat...

Jul 9, 2024
CVE-2025-48807
6.7

This vulnerability in Windows Hyper-V allows an authorized attacker to bypass communication channel restrictions and execute arbitrary code locally on...

Aug 12, 2025
CVE-2025-31144
5.8

Quick Agent V3 and V2 contain an improper restriction of communication channel vulnerability (CWE-923) that allows remote unauthenticated attackers to...

Apr 28, 2025
CVE-2024-43571
5.6

CVE-2024-43571 is a spoofing vulnerability in Sudo for Windows that allows attackers to impersonate legitimate processes or users. This affects Window...

Oct 8, 2024
CVE-2025-32886
4.0

This vulnerability allows local attackers to intercept sensitive data transmitted by goTenna v1 devices. When packets are sent over RF, they are also ...

May 1, 2025
CVE-2024-22315
4.0

IBM Fusion and IBM Fusion HCI versions 2.3.0 through 2.8.2 allow insecure network connections from compromised containers. An attacker who gains acces...

Jan 28, 2025

About CWE-923 (CWE-923)

Our database tracks 18 CVEs classified as CWE-923, with 2 rated critical and 11 rated high severity. The average CVSS score for CWE-923 vulnerabilities is 7.4.

External reference: View CWE-923 on MITRE CWE →

Monitor CWE-923 Vulnerabilities

Get alerted when new CWE-923 CVEs affect your infrastructure.

Start Monitoring Free