CWE-940

CWE-940 · 3 records · 1 with a public proof-of-concept

Records the NVD classes under CWE-940, highest CVSS first.

  1. HIGH 7.2CVE-2026-102117public PoC

    On deployments where the remote-support capability is licensed and enabled, an authenticated System Administrator who also possessed the key protecting the submitted data could redirect the underlying system's outbound support connection to a destination of th…

    AI risk analysis on Exploit-DB.ai →

  2. UNSCOREDCVE-2026-59786

    Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone with access to the Zabbix trapper port can report an arbitrary host using an active agent as available, resulti…

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-102511

    Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacker able to send UDP datagrams to the discovering host to redirect subsequent connections to an arbitrary, attacker…

    AI risk analysis on Exploit-DB.ai →