Skip to content
Noroxi

CWE-424 · 38 records

Improper Protection of Alternate Path

CVEs in this class

38 records

  • Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited i

    CriticalCVSS 9.8KEVWeaponizedEPSS 88%

    yiiframework · yiiApr 9, 2025

  • CVE-2025-48827
    62This week

    vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running

    CriticalCVSS 9.8WeaponizedEPSS 76%

    vbulletin · vbulletinMay 27, 2025

  • Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine.

    HighCVSS 8.1WeaponizedEPSS 58%

    vbulletin · vbulletinMay 27, 2025

  • A vulnerability has been identified in HiMed Cockpit 12 pro (J31032-K2017-H259) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 14 pro+ (

    CriticalCVSS 9.3No exploitEPSS 0%

    siemens · himed cockpit 12 proOct 8, 2024

  • A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to upl

    HighCVSS 8.8No exploitEPSS 1%

    cisco · identity services engineNov 21, 2023

  • CVE-2023-5165
    35Monitor

    Docker Desktop before 4.23.0 allows Enhanced Container Isolation bypass via debug shell

    HighCVSS 8.8No exploitEPSS 0%

    docker · docker desktopSep 25, 2023

  • AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes

    HighCVSS 8.2No exploitEPSS 1%

    ash-project · ash_luaSep 7, 2026

  • In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use t

    HighCVSS 8.2No exploitEPSS 0%

    openstack · ironicJul 10, 2026

  • PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching works

    HighCVSS 8.2No exploitEPSS 0%

    pcre · pcre2Sep 5, 2026

  • CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE

    HighCVSS 8.1No exploitEPSS 0%

    crewai · crewaiSep 13, 2026

  • ABB PB610 HMIStudio accepts malicious DLL file in an application

    HighCVSS 7.8No exploitEPSS 0%

    abb · pb610 panel builder 600Dec 18, 2019

  • CVE-2024-3459
    31Monitor

    KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened

    HighCVSS 7.8No exploitEPSS 0%

    kioware · kiowareMay 14, 2024

  • IBM MQ privilege escalation

    HighCVSS 7.8No exploitEPSS 0%

    ibm · mq applianceNov 2, 2023

  • PB610 HMISimulator provides interface with access to arbitrary files

    HighCVSS 7.5No exploitEPSS 2%

    abb · pb610 panel builder 600Dec 18, 2019

  • CVE-2026-0237
    29Monitor

    Prisma Browser: Improperly Restricted Automation Bridge Allows Security Bypass

    HighCVSS 7.3No exploitEPSS 0%

    paloaltonetworks · prisma browserMay 13, 2026

  • CVE-2024-3460
    28Monitor

    In KioWare for Windows (versions all through 8.34) it is possible to exit this software and use other already opened applications utilizing

    HighCVSS 7.0No exploitEPSS 0%

    kioware · kiowareMay 14, 2024

  • CVE-2023-0629
    28Monitor

    Docker Desktop before 4.17.0 allows an unprivileged user to bypass Enhanced Container Isolation restrictions via the raw Docker socket and launch privileged con

    HighCVSS 7.1No exploitEPSS 0%

    docker · docker desktopMar 13, 2023

  • CVE-2025-6250
    28Monitor

    Privilege Management for Windows - Elevation of Privilege

    HighCVSS 7.1No exploitEPSS 0%

    beyondtrust · privilege management for windowsJul 28, 2025

  • Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false

    MediumCVSS 6.9No exploitEPSS 1%

    apache · tikaJul 30, 2026

  • CVE-2022-1742
    27Monitor

    2.2.4 IMPROPER PROTECTION OF ALTERNATE PATH CWE-424

    MediumCVSS 6.8No exploitEPSS 0%

    dominionvoting · imagecast xJun 24, 2022

  • CVE-2026-4270
    27Monitor

    AWS API MCP File Access Restriction Bypass

    MediumCVSS 6.8No exploitEPSS 0%

    amazon · aws api mcp serverMar 16, 2026

  • CVE-2024-8311
    26Monitor

    Improper Protection of Alternate Path in GitLab

    MediumCVSS 6.5No exploitEPSS 1%

    gitlab · gitlabSep 12, 2024

  • Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

    MediumCVSS 6.5No exploitEPSS 0%

    gitea · gitea open source git serverAug 13, 2026

  • Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow booting an arbitrary image via a crafted /usr/bin/gunzip file.

    MediumCVSS 6.7No exploitEPSS 0%

    arris · vip1113Jun 2, 2025

  • ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls

    MediumCVSS 6.3No exploitEPSS 1%

    ash-project · ash_authentication_oauth2_serverSep 7, 2026

All vulnerability classes