CWE-424 · 38 records
Improper Protection of Alternate Path
CVEs in this class
38 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
95Now | CVE-2024-58136Weaponized | Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited iyiiframework · yii · CWE-424 | Critical9.8 | KEV | 87.8% | Apr 9, 2025 |
62This week | CVE-2025-48827Weaponized | vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when runningvbulletin · vbulletin · CWE-424 | Critical9.8 | — | 75.8% | May 27, 2025 |
49Plan | CVE-2025-48828Weaponized | Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine.vbulletin · vbulletin · CWE-424 | High8.1 | — | 57.6% | May 27, 2025 |
37Monitor | CVE-2023-52952No exploit | A vulnerability has been identified in HiMed Cockpit 12 pro (J31032-K2017-H259) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 14 pro+ (siemens · himed cockpit 12 pro · CWE-424 | Critical9.3 | — | 0.2% | Oct 8, 2024 |
35Monitor | CVE-2023-20272No exploit | A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to uplcisco · identity services engine · CWE-424 | High8.8 | — | 0.9% | Nov 21, 2023 |
35Monitor | CVE-2023-5165No exploit | Docker Desktop before 4.23.0 allows Enhanced Container Isolation bypass via debug shelldocker · docker desktop · CWE-424 | High8.8 | — | 0.3% | Sep 25, 2023 |
32Monitor | CVE-2026-82586No exploit | AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributesash-project · ash_lua · CWE-424 | High8.2 | — | 0.5% | Sep 7, 2026 |
32Monitor | CVE-2026-54423No exploit | In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use topenstack · ironic · CWE-424 | High8.2 | — | 0.5% | Jul 10, 2026 |
32Monitor | CVE-2026-86145No exploit | PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspcre · pcre2 · CWE-424 | High8.2 | — | 0.4% | Sep 5, 2026 |
32Monitor | CVE-2026-37008No exploit | CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVEcrewai · crewai · CWE-424 | High8.1 | — | 0.2% | Sep 13, 2026 |
31Monitor | CVE-2019-18996No exploit | ABB PB610 HMIStudio accepts malicious DLL file in an applicationabb · pb610 panel builder 600 · CWE-424 | High7.8 | — | 0.4% | Dec 18, 2019 |
31Monitor | CVE-2024-3459No exploit | KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened kioware · kioware · CWE-424 | High7.8 | — | 0.3% | May 14, 2024 |
31Monitor | CVE-2023-46176No exploit | IBM MQ privilege escalationibm · mq appliance · CWE-424 | High7.8 | — | 0.2% | Nov 2, 2023 |
30Monitor | CVE-2019-18997No exploit | PB610 HMISimulator provides interface with access to arbitrary filesabb · pb610 panel builder 600 · CWE-424 | High7.5 | — | 1.5% | Dec 18, 2019 |
29Monitor | CVE-2026-0237No exploit | Prisma Browser: Improperly Restricted Automation Bridge Allows Security Bypasspaloaltonetworks · prisma browser · CWE-424 | High7.3 | — | 0.2% | May 13, 2026 |
28Monitor | CVE-2024-3460No exploit | In KioWare for Windows (versions all through 8.34) it is possible to exit this software and use other already opened applications utilizing kioware · kioware · CWE-424 | High7.0 | — | 0.3% | May 14, 2024 |
28Monitor | CVE-2023-0629No exploit | Docker Desktop before 4.17.0 allows an unprivileged user to bypass Enhanced Container Isolation restrictions via the raw Docker socket and launch privileged condocker · docker desktop · CWE-424 | High7.1 | — | 0.2% | Mar 13, 2023 |
28Monitor | CVE-2025-6250No exploit | Privilege Management for Windows - Elevation of Privilegebeyondtrust · privilege management for windows · CWE-424 | High7.1 | — | 0.2% | Jul 28, 2025 |
27Monitor | CVE-2026-66756No exploit | Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=falseapache · tika · CWE-424 | Medium6.9 | — | 0.7% | Jul 30, 2026 |
27Monitor | CVE-2022-1742No exploit | 2.2.4 IMPROPER PROTECTION OF ALTERNATE PATH CWE-424dominionvoting · imagecast x · CWE-424 | Medium6.8 | — | 0.3% | Jun 24, 2022 |
27Monitor | CVE-2026-4270No exploit | AWS API MCP File Access Restriction Bypassamazon · aws api mcp server · CWE-424 | Medium6.8 | — | 0.2% | Mar 16, 2026 |
26Monitor | CVE-2024-8311No exploit | Improper Protection of Alternate Path in GitLabgitlab · gitlab · CWE-424 | Medium6.5 | — | 0.6% | Sep 12, 2024 |
26Monitor | CVE-2026-58428No exploit | Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)gitea · gitea open source git server · CWE-424 | Medium6.5 | — | 0.5% | Aug 13, 2026 |
26Monitor | CVE-2025-49163No exploit | Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow booting an arbitrary image via a crafted /usr/bin/gunzip file.arris · vip1113 · CWE-424 | Medium6.7 | — | 0.2% | Jun 2, 2025 |
25Monitor | CVE-2026-82754No exploit | ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controlsash-project · ash_authentication_oauth2_server · CWE-424 | Medium6.3 | — | 0.7% | Sep 7, 2026 |
- CVE-2024-5813695Now
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited i
CriticalCVSS 9.8KEVWeaponizedEPSS 88%yiiframework · yiiApr 9, 2025
- CVE-2025-4882762This week
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running
CriticalCVSS 9.8WeaponizedEPSS 76%vbulletin · vbulletinMay 27, 2025
- CVE-2025-4882849Plan
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine.
HighCVSS 8.1WeaponizedEPSS 58%vbulletin · vbulletinMay 27, 2025
- CVE-2023-5295237Monitor
A vulnerability has been identified in HiMed Cockpit 12 pro (J31032-K2017-H259) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 14 pro+ (
CriticalCVSS 9.3No exploitEPSS 0%siemens · himed cockpit 12 proOct 8, 2024
- CVE-2023-2027235Monitor
A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to upl
HighCVSS 8.8No exploitEPSS 1%cisco · identity services engineNov 21, 2023
- CVE-2023-516535Monitor
Docker Desktop before 4.23.0 allows Enhanced Container Isolation bypass via debug shell
HighCVSS 8.8No exploitEPSS 0%docker · docker desktopSep 25, 2023
- CVE-2026-8258632Monitor
AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
HighCVSS 8.2No exploitEPSS 1%ash-project · ash_luaSep 7, 2026
- CVE-2026-5442332Monitor
In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use t
HighCVSS 8.2No exploitEPSS 0%openstack · ironicJul 10, 2026
- CVE-2026-8614532Monitor
PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching works
HighCVSS 8.2No exploitEPSS 0%pcre · pcre2Sep 5, 2026
- CVE-2026-3700832Monitor
CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE
HighCVSS 8.1No exploitEPSS 0%crewai · crewaiSep 13, 2026
- CVE-2019-1899631Monitor
ABB PB610 HMIStudio accepts malicious DLL file in an application
HighCVSS 7.8No exploitEPSS 0%abb · pb610 panel builder 600Dec 18, 2019
- CVE-2024-345931Monitor
KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened
HighCVSS 7.8No exploitEPSS 0%kioware · kiowareMay 14, 2024
- CVE-2023-4617631Monitor
IBM MQ privilege escalation
HighCVSS 7.8No exploitEPSS 0%ibm · mq applianceNov 2, 2023
- CVE-2019-1899730Monitor
PB610 HMISimulator provides interface with access to arbitrary files
HighCVSS 7.5No exploitEPSS 2%abb · pb610 panel builder 600Dec 18, 2019
- CVE-2026-023729Monitor
Prisma Browser: Improperly Restricted Automation Bridge Allows Security Bypass
HighCVSS 7.3No exploitEPSS 0%paloaltonetworks · prisma browserMay 13, 2026
- CVE-2024-346028Monitor
In KioWare for Windows (versions all through 8.34) it is possible to exit this software and use other already opened applications utilizing
HighCVSS 7.0No exploitEPSS 0%kioware · kiowareMay 14, 2024
- CVE-2023-062928Monitor
Docker Desktop before 4.17.0 allows an unprivileged user to bypass Enhanced Container Isolation restrictions via the raw Docker socket and launch privileged con
HighCVSS 7.1No exploitEPSS 0%docker · docker desktopMar 13, 2023
- CVE-2025-625028Monitor
Privilege Management for Windows - Elevation of Privilege
HighCVSS 7.1No exploitEPSS 0%beyondtrust · privilege management for windowsJul 28, 2025
- CVE-2026-6675627Monitor
Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false
MediumCVSS 6.9No exploitEPSS 1%apache · tikaJul 30, 2026
- CVE-2022-174227Monitor
2.2.4 IMPROPER PROTECTION OF ALTERNATE PATH CWE-424
MediumCVSS 6.8No exploitEPSS 0%dominionvoting · imagecast xJun 24, 2022
- CVE-2026-427027Monitor
AWS API MCP File Access Restriction Bypass
MediumCVSS 6.8No exploitEPSS 0%amazon · aws api mcp serverMar 16, 2026
- CVE-2024-831126Monitor
Improper Protection of Alternate Path in GitLab
MediumCVSS 6.5No exploitEPSS 1%gitlab · gitlabSep 12, 2024
- CVE-2026-5842826Monitor
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
MediumCVSS 6.5No exploitEPSS 0%gitea · gitea open source git serverAug 13, 2026
- CVE-2025-4916326Monitor
Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow booting an arbitrary image via a crafted /usr/bin/gunzip file.
MediumCVSS 6.7No exploitEPSS 0%arris · vip1113Jun 2, 2025
- CVE-2026-8275425Monitor
ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls
MediumCVSS 6.3No exploitEPSS 1%ash-project · ash_authentication_oauth2_serverSep 7, 2026