CWE-300: Channel Accessible by Non-Endpoint
The product does not adequately verify the identity of actors at both ends of a communication channel, or does not adequately ensure the integrity of the channel, in a way that allows the channel to be accessed or influenced by an actor that is not an endpoint.
49 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-54792 — LocalSend is Vulnerable to Man-in-the-Middle Attacks, Leading to File Interception
- CVE-2025-20122 — Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability
- CVE-2026-74232 — Zbtlink MQWrt yunmgrd Cloud C2 Implant
- CVE-2026-84197 — In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from
- CVE-2025-40770 — A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions). The affected applicat
- CVE-2024-32049 — BIG-IP Next Central Manager vulnerability
- CVE-2026-12991 — Multiple vulnerabilities in Ghost Robotics' Vision 60
- CVE-2024-12602 — Identity verification vulnerability in the ParamWatcher module Impact: Successful exploitation of this vulnerability may
- CVE-2024-27263 — IBM Sterling B2B Integrator information disclosure
Recently published
- CVE-2026-84197 — In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from
- CVE-2026-74232 — Zbtlink MQWrt yunmgrd Cloud C2 Implant
- CVE-2026-12991 — Multiple vulnerabilities in Ghost Robotics' Vision 60
- CVE-2025-40770 — A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions). The affected applicat
- CVE-2025-54792 — LocalSend is Vulnerable to Man-in-the-Middle Attacks, Leading to File Interception
- CVE-2025-20122 — Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability
- CVE-2024-12602 — Identity verification vulnerability in the ParamWatcher module Impact: Successful exploitation of this vulnerability may
- CVE-2024-27263 — IBM Sterling B2B Integrator information disclosure
- CVE-2024-32049 — BIG-IP Next Central Manager vulnerability