CWE-322

CWE-322 · 3 records · 2 with a public proof-of-concept

Records the NVD classes under CWE-322, highest CVSS first.

  1. MEDIUM 5.9CVE-2026-107675public PoC

    FFmpeg through 9.0.2 contains a missing host key verification vulnerability in the libssh-based sftp protocol handler that allows network attackers to impersonate SFTP servers. Attackers performing man-in-the-middle, DNS, or ARP spoofing can capture passwords …

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 5.9CVE-2026-77703

    Key exchange without entity authentication vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM). This issue affects Liman Render Engine: from 1.0 before 1.2-75.

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-89422public PoC

    Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A pre_shared_key extension in the ServerHello that the client never offered causes the client …

    AI risk analysis on Exploit-DB.ai →