Skip to content
Noroxi

CWE-420 · 40 records

Unprotected Alternate Channel

CVEs in this class

40 records

  • Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    cisco · ios xeOct 16, 2023

  • CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows

    CriticalCVSS 9.8KEVWeaponizedEPSS 95%

    crushftp · crushftpJul 18, 2025

  • Unauthenticated log access in Twonky Server

    CriticalCVSS 9.3WeaponizedEPSS 32%

    linux · linux kernelNov 19, 2025

  • Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.

    CriticalCVSS 10.0No exploitEPSS 1%

    snapone · orvcMay 22, 2023

  • In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).

    CriticalCVSS 10.0No exploitEPSS 0%

    es · iperf3Aug 2, 2025

  • In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution o

    CriticalCVSS 9.9No exploitEPSS 1%

    innoshop · innoshopJun 23, 2025

  • CVE-2020-8558
    36Monitor

    Kubernetes node setting allows for neighboring hosts to bypass localhost boundary

    HighCVSS 8.8Proof of conceptEPSS 4%

    kubernetes · kubernetesJul 27, 2020

  • LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.

    HighCVSS 8.8Proof of conceptEPSS 3%

    litellm · litellmApr 10, 2026

  • moby/moby's dockerd daemon encrypted overlay network may be unauthenticated

    HighCVSS 8.7No exploitEPSS 3%

    mobyproject · mobyApr 4, 2023

  • CVE-2023-4570
    35Monitor

    Improper Restriction in NI MeasurementLink Python Services

    HighCVSS 8.8No exploitEPSS 0%

    ni · measurementlinkOct 5, 2023

  • Duplicate Advisory: LiteLLM has a sandbox escape in custom-code guardrail

    HighCVSS 8.8No exploit

    PyPI · litellmApr 10, 2026

  • Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a craft

    HighCVSS 8.0No exploitEPSS 6%

    framelink · figma mcp serverOct 8, 2025

  • BullWall Ransomware Containment hard-coded folder exclusions

    HighCVSS 8.7No exploitEPSS 0%

    bullwall · ransomware containmentDec 18, 2025

  • CVE-2025-8557
    34Monitor

    An internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attacker with access to a

    HighCVSS 8.7No exploitEPSS 0%

    lenovo · xclarity orchestrator (lxco)Sep 11, 2025

  • CVE-2024-6242
    32Monitor

    Rockwell Automation Chassis Restrictions Bypass Vulnerability in Select Logix Devices

    HighCVSS 7.3No exploitEPSS 11%

    rockwell automation · controllogix® 5580 (1756-l8z)Aug 1, 2024

  • CVE-2023-7266
    32Monitor

    Some Huawei home routers have a connection hijacking vulnerability.

    HighCVSS 8.1No exploitEPSS 0%

    huawei · tc7001-10 firmwareDec 28, 2024

  • A connection hijacking vulnerability exists in some Huawei home routers.

    HighCVSS 8.1No exploitEPSS 0%

    huawei · pt9030-15 firmwareDec 28, 2024

  • Beckhoff: Performing privileged operations and gaining administrator access

    HighCVSS 7.8No exploitEPSS 0%

    beckhoff automation · beckhoff.device.manager.xarJan 27, 2026

  • CVE-2025-1095
    31Monitor

    IBM Personal Communications command execution

    HighCVSS 7.8No exploitEPSS 0%

    ibm · personal communicationsApr 8, 2025

  • Duplicate Advisory: Juju Unprotected Alternate Channel vulnerability

    HighCVSS 7.9No exploit

    Go · github.com/juju/jujuOct 2, 2024

  • An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data.

    HighCVSS 7.5Proof of conceptEPSS 1%

    comfy · comfyui-managerJan 5, 2026

  • Duplicate Advisory: ComfyUI-Manager has an Unprotected Alternate Channel (CWE-420)

    HighCVSS 7.5No exploit

    PyPI · comfyui-managerJan 5, 2026

  • The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy.

    HighCVSS 7.4No exploitEPSS 0%

    microsoft · windowsSep 8, 2025

  • moby/moby's dockerd daemon encrypted overlay network with a single endpoint is unauthenticated

    MediumCVSS 6.8No exploitEPSS 1%

    mobyproject · mobyApr 4, 2023

  • BIG-IP httpd access control vulnerability

    MediumCVSS 6.9No exploitEPSS 0%

    f5 · big-ip access policy managerMay 13, 2026

All vulnerability classes