NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authori
Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trust
In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret
No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.
Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized attacker to elevate priv
OpenClaw before 2026.3.24 contains an arbitrary code execution vulnerability in local plugin and hook installation that
A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to cache poisoning.
A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) s
Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.1.0 to before 3.21.6 and 4.0.0-alpha.1 t
django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.7, 19.2 before 19.2.5, and 19.3
Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an exte
Frequently Asked Questions
What is CWE-349?
CWE-349 (CWE-349) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-349?
There are 12 CVE records associated with CWE-349 in our database. Of these, 4 are critical severity, 3 are high severity, and 4 are medium severity.
How can I protect against CWE-349 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-349 using AI-powered security agents.
Detect CWE-349 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-349 vulnerabilities across your infrastructure.
Get Started