Threats Tagged 'cwe-1327'
View all threats tagged with 'cwe-1327'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-1327'
Click on any threat for detailed analysis and mitigation recommendations
0 PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and launch_tools_mcp_server bind to 0.0.0.0 and create /sse and /messages/ routes without invoking the available SecurityConfig authentication, origin-validation, or DNS-rebinding controls. Any reachable client can list and invoke registered tools, and a browser can target a local instance through DNS rebinding, with impact determined by the registered file, shell, and code-execution tools. This vulnerability is fixed in praisonaiagents 1.6.59. Join the discussion | CVE Database V5 | 09/14/2026, 14:46:12 UTC Added: 09/14/2026, 15:02:02 UTC |
0 IBM Documentation Offline 1.0.0 through 1.4.1 IBM Documentation could allow a remote attacker to obtain sensitive information due to a security misconfiguration where the documentation server binds to an unrestricted IP address. Join the discussion | CVE Database V5 | 08/13/2026, 19:40:09 UTC Added: 08/13/2026, 19:56:43 UTC |
0 Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres". Because Docker installs its own iptables rules, this exposure bypasses a standard host UFW configuration. Join the discussion | CVE Database V5 | 07/31/2026, 15:18:33 UTC Added: 07/31/2026, 15:34:06 UTC |
0 The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier Join the discussion | CVE Database V5 | 07/30/2026, 05:23:59 UTC Added: 07/30/2026, 06:24:12 UTC |
9Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by reading the client-controlled Host header, allowing a remote unauthenticated attacker to send Host: localhost and bypass API-key authentication. In the default configuration, this exposes the /v1 proxy to upstream provider calls using stored provider credentials and allows /v1/search with the searxng provider_options.baseUrl parameter to drive server-side requests to internal or cloud-metadata hosts. This issue is fixed in version 0.5.2. Join the discussion | CVE Database V5 | 07/10/2026, 15:36:05 UTC Added: 07/10/2026, 16:33:24 UTC |
0 Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to perform unauthorized changes to the GPU configuration, potentially resulting in loss of availability Join the discussion | CVE Database V5 | 05/15/2026, 03:04:56 UTC Added: 05/15/2026, 04:21:50 UTC |
0 The golang.org/x/tools/gopls language server has a vulnerability where it may bind to the unrestricted IP address 0.0.0.0 when started with certain debugging flags (-listen without explicit host or -port). This behavior can expose the service to network attackers on the same network, potentially allowing arbitrary code execution. The vulnerability is rated high severity with a CVSS score of 8.8. No official patch or remediation guidance is currently provided by the vendor. Users should be cautious when using these flags and avoid binding gopls to all network interfaces unless necessary. Join the discussion | CVE Database V5 | 05/06/2026, 16:20:01 UTC Added: 05/06/2026, 16:51:29 UTC |
0 A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users are recommended to upgrade to version 1.3.7 or 2.0.7, which fixes the issue. Join the discussion | CVE Database V5 | 03/09/2026, 08:57:45 UTC Added: 03/09/2026, 09:07:46 UTC |
0 Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. Join the discussion | CVE Database V5 | 02/10/2026, 17:51:30 UTC Added: 02/10/2026, 18:16:39 UTC |
A binding to an unrestricted IP address vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and read, write, or delete arbitrary files and folders on the target machine Join the discussion | CVE Database V5 | 10/23/2025, 22:01:28 UTC Added: 10/23/2025, 22:08:45 UTC |
Showing 1 to 10 of 13 results