CWE-441
Unintended Proxy or Intermediary ('Confused Deputy')
The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.
69 vulnerabilities with CWE-441
CVE-2026-30225
MEDIUM
OliveTin <3000.11.1 - Privilege Escalation
CVSS 5.3
CVE-2026-0021
HIGH
AppInfoBase.java - Privilege Escalation
CVSS 8.4
CVE-2026-0013
HIGH
DocumentsUI - Privilege Escalation
CVSS 8.4
CVE-2026-0008
HIGH
Android - Privilege Escalation
CVSS 8.4
CVE-2025-48646
HIGH
ActivityStarter.java - Privilege Escalation
CVSS 7.8
CVE-2025-48579
HIGH
MediaProvider.java - Privilege Escalation
CVSS 8.4
CVE-2026-27624
HIGH
Coturn - Auth Bypass
CVSS 7.2
CVE-2023-31313
HIGH
AMD PMFW - RCE
CVSS 7.2
CVE-2026-24471
continuity - SSRF
CVE-2026-24470
HIGH
Skipper <0.24.0 - Privilege Escalation
CVSS 8.1
CVE-2025-64125
Nuvation Energy nCloud VPN Service - Info Disclosure
CVE-2025-64123
CRITICAL
Nuvation Energy MSC <2.5.1 - SSRF
CVSS 9.8
CVE-2025-68944
MEDIUM
Gitea <1.22.2 - Info Disclosure
CVSS 5.0
CVE-2025-68667
Conduit <0.10.10 - SSRF
CVE-2025-11393
HIGH
Runtimes-Inventory-Rhel8-Operator - Privilege Escalation
CVSS 8.7
CVE-2025-36889
MEDIUM
Google Android - Information Disclosure
CVSS 5.5
CVE-2025-48628
HIGH
PrintManagerService - Privilege Escalation
CVSS 7.8
CVE-2025-48598
MEDIUM
Face Unlock Settings - Privilege Escalation
CVSS 6.6
CVE-2025-48586
HIGH
EditFdnContactScreen - Info Disclosure
CVSS 7.8
CVE-2025-48555
HIGH
NotificationStation - Info Disclosure
CVSS 7.8
CVE-2025-48536
HIGH
SettingsSliceProvider - Privilege Escalation
CVSS 7.8
CVE-2025-22420
HIGH
Multiple Locations - Info Disclosure
CVSS 7.8
CVE-2025-66415
MEDIUM
Fastify-reply-from <12.5.0 - SSRF
CVSS 5.4
CVE-2025-61780
MEDIUM
Rack < 2.2.20 - Information Disclosure
CVSS 5.8
CVE-2025-32320
HIGH
System UI - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities
69