Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel t
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly h
A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-man
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the abi
Unintended Proxy or Intermediary vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Network Boundary B
Kofax Capture, now referred to as Tungsten Capture, version 6.0.0.0 (other versions may be affected) exposes a deprecate
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the @better-auth/sso plugin'
A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerabil
Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. Plack::Middle
A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external ports to
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vuln
Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by conca
A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes
Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0
In multiple functions of MediaProvider.java, there is a possible external storage write permission bypass due to a confu
In multiple locations, there is a possible privilege escalation due to a confused deputy. This could lead to local esca
In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confuse
In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible cross-user permission bypass due to a c
In gmc_ddr_handle_mba_mr_req of gmc_mba_ddr.c, there is a possible escalation of privileges due to a confused deputy. Th
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API
9Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* acce
Appium Java Client is the Java language binding for writing Appium tests that conform to the W3C WebDriver protocol. Fro
Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.24.0, when running Skipper as an
In executeRequest of ActivityStarter.java, there is a possible launch anywhere due to a confused deputy. This could lead
In multiple functions of PipTaskOrganizer.java, there is a possible way to launch an activity from the background due to
In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictions due to a confused
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when
Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel CXF SOAP c
An unintended proxy or intermediary in the AMD power management firmware (PMFW) could allow a privileged attacker to sen
Coturn is a free open source implementation of TURN and STUN Server. Coturn is commonly configured to block loopback and
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influe
A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exp
Aiven Operator allows you to provision and manage Aiven Services from your Kubernetes cluster. From 0.31.0 to before 0.3
Astro is a web framework. Prior to version 10.0.2, the @astrojs/vercel serverless entrypoint reads the x-astro-path head
Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel DAPR compo
An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal
In versions of the Datadog Android application prior to v545-5.9.2, OnCallNotificationActivity is declared exported with
A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can ex
The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret references from an annotation on secrets it manage
Astro is a web framework for content-driven websites. From 10.0.3 until 11.0.3, the Astro Vercel adapter in packages/int
FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, while testing the GitHubProvide
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other
swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resol
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.9.7, 18.10 before 18.10.6, and
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,
OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability in MS Teams thread history fetched via Graph
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authentication c
Frequently Asked Questions
What is CWE-441?
CWE-441 (CWE-441) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-441?
There are 63 CVE records associated with CWE-441 in our database. Of these, 11 are critical severity, 24 are high severity, and 21 are medium severity.
How can I protect against CWE-441 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-441 using AI-powered security agents.
Detect CWE-441 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-441 vulnerabilities across your infrastructure.
Get Started