CWE-322
CWE-322 · 3 records · 2 with a public proof-of-concept
Records the NVD classes under CWE-322, highest CVSS first.
- MEDIUM 5.9CVE-2026-107675public PoC
FFmpeg through 9.0.2 contains a missing host key verification vulnerability in the libssh-based sftp protocol handler that allows network attackers to impersonate SFTP servers. Attackers performing man-in-the-middle, DNS, or ARP spoofing can capture passwords …
- MEDIUM 5.9CVE-2026-77703
Key exchange without entity authentication vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM). This issue affects Liman Render Engine: from 1.0 before 1.2-75.
- UNSCOREDCVE-2026-89422public PoC
Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A pre_shared_key extension in the ServerHello that the client never offered causes the client …