CWE-923: CWE-923
Yearly Trend
Top Affected Vendors
All CWE-923 CVEs (18)
This vulnerability allows remote unauthenticated attackers to execute arbitrary code on affected Pimax devices by exploiting improper WebSocket endpoi...
Aug 5, 2024Dell OS10 Networking Switches running 10.5.2.x and above contain a zeroMQ vulnerability when VLT (Virtual Link Trunking) is configured. Remote unauthe...
Feb 15, 2024This vulnerability in MicroServer allows an attacker with local network admin access and DNS manipulation capability to redirect a reverse SSH connect...
Jan 7, 2026This vulnerability allows authenticated remote attackers to bypass SSH restrictions on Cisco UCS servers' IMC, gaining elevated privileges to access i...
Jun 4, 2025Element Android versions 1.4.3 through 1.6.10 are vulnerable to intent redirection, allowing malicious apps to launch internal activities with arbitra...
Feb 29, 2024This vulnerability allows attackers to perform man-in-the-middle attacks between electric vehicles and ISO 15118-2 compliant chargers by manipulating ...
Oct 31, 2025Dell Common Event Enabler version 9.0.0.0 contains an improper restriction of communication channel vulnerability in its Common Anti-Virus Agent (CAVA...
Apr 8, 2025An unauthenticated attacker can send specific MPLS packets to Juniper ACX 7000 Series devices running vulnerable Junos OS Evolved versions, causing th...
Oct 11, 2024The goTenna Pro App fails to authenticate public keys, allowing unauthenticated attackers to intercept and manipulate messages. This affects all users...
Sep 26, 2024CVE-2024-24974 allows remote attackers to interact with the privileged OpenVPN interactive service pipe, potentially enabling unauthorized access or c...
Jul 8, 2024This vulnerability allows attackers to bypass firewall rules that restrict communication between Test Agents and the Control Center in Juniper Paragon...
Apr 17, 2023This vulnerability allows local authenticated attackers to modify registry values or execute arbitrary code by sending malicious data to UpdateNavi so...
Jun 12, 2025This vulnerability allows an attacker who has already broken out of a Docker container into the Docker Desktop VM to further escape to the host operat...
Jul 9, 2024This vulnerability in Windows Hyper-V allows an authorized attacker to bypass communication channel restrictions and execute arbitrary code locally on...
Aug 12, 2025Quick Agent V3 and V2 contain an improper restriction of communication channel vulnerability (CWE-923) that allows remote unauthenticated attackers to...
Apr 28, 2025CVE-2024-43571 is a spoofing vulnerability in Sudo for Windows that allows attackers to impersonate legitimate processes or users. This affects Window...
Oct 8, 2024This vulnerability allows local attackers to intercept sensitive data transmitted by goTenna v1 devices. When packets are sent over RF, they are also ...
May 1, 2025IBM Fusion and IBM Fusion HCI versions 2.3.0 through 2.8.2 allow insecure network connections from compromised containers. An attacker who gains acces...
Jan 28, 2025About CWE-923 (CWE-923)
Our database tracks 18 CVEs classified as CWE-923, with 2 rated critical and 11 rated high severity. The average CVSS score for CWE-923 vulnerabilities is 7.4.
External reference: View CWE-923 on MITRE CWE →
Monitor CWE-923 Vulnerabilities
Get alerted when new CWE-923 CVEs affect your infrastructure.
Start Monitoring Free