Перейти к содержимому
Noroxi

CWE-420 · 40 записей

Unprotected Alternate Channel

CVE этого класса

40 записей

  • CVE-2023-20198
    100Срочно

    Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %

    cisco · ios xe16 окт. 2023 г.

  • CVE-2025-54309
    97Срочно

    CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 95 %

    crushftp · crushftp18 июл. 2025 г.

  • CVE-2025-13315
    47В плане

    Unauthenticated log access in Twonky Server

    КритическаяCVSS 9,3Готовый эксплойтEPSS 32 %

    linux · linux kernel19 нояб. 2025 г.

  • CVE-2023-31241
    40В плане

    Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    snapone · orvc22 мая 2023 г.

  • CVE-2025-54351
    40В плане

    In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).

    КритическаяCVSS 10,0Эксплойта нетEPSS 0 %

    es · iperf32 авг. 2025 г.

  • CVE-2025-52921
    39Наблюдать

    In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution o

    КритическаяCVSS 9,9Эксплойта нетEPSS 1 %

    innoshop · innoshop23 июн. 2025 г.

  • CVE-2020-8558
    36Наблюдать

    Kubernetes node setting allows for neighboring hosts to bypass localhost boundary

    ВысокаяCVSS 8,8Proof of conceptEPSS 4 %

    kubernetes · kubernetes27 июл. 2020 г.

  • CVE-2026-40217
    36Наблюдать

    LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.

    ВысокаяCVSS 8,8Proof of conceptEPSS 3 %

    litellm · litellm10 апр. 2026 г.

  • CVE-2023-28840
    35Наблюдать

    moby/moby's dockerd daemon encrypted overlay network may be unauthenticated

    ВысокаяCVSS 8,7Эксплойта нетEPSS 3 %

    mobyproject · moby4 апр. 2023 г.

  • CVE-2023-4570
    35Наблюдать

    Improper Restriction in NI MeasurementLink Python Services

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    ni · measurementlink5 окт. 2023 г.

  • GHSA-3926-2jvf-fg29
    35Наблюдать

    Duplicate Advisory: LiteLLM has a sandbox escape in custom-code guardrail

    ВысокаяCVSS 8,8Эксплойта нет

    PyPI · litellm10 апр. 2026 г.

  • CVE-2025-53967
    34Наблюдать

    Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a craft

    ВысокаяCVSS 8,0Эксплойта нетEPSS 6 %

    framelink · figma mcp server8 окт. 2025 г.

  • CVE-2025-62001
    34Наблюдать

    BullWall Ransomware Containment hard-coded folder exclusions

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    bullwall · ransomware containment18 дек. 2025 г.

  • CVE-2025-8557
    34Наблюдать

    An internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attacker with access to a

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    lenovo · xclarity orchestrator (lxco)11 сент. 2025 г.

  • CVE-2024-6242
    32Наблюдать

    Rockwell Automation Chassis Restrictions Bypass Vulnerability in Select Logix Devices

    ВысокаяCVSS 7,3Эксплойта нетEPSS 11 %

    rockwell automation · controllogix® 5580 (1756-l8z)1 авг. 2024 г.

  • CVE-2023-7266
    32Наблюдать

    Some Huawei home routers have a connection hijacking vulnerability.

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    huawei · tc7001-10 firmware28 дек. 2024 г.

  • CVE-2023-52718
    32Наблюдать

    A connection hijacking vulnerability exists in some Huawei home routers.

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    huawei · pt9030-15 firmware28 дек. 2024 г.

  • CVE-2025-41727
    31Наблюдать

    Beckhoff: Performing privileged operations and gaining administrator access

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    beckhoff automation · beckhoff.device.manager.xar27 янв. 2026 г.

  • CVE-2025-1095
    31Наблюдать

    IBM Personal Communications command execution

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    ibm · personal communications8 апр. 2025 г.

  • GHSA-85qf-6845-m8p2
    31Наблюдать

    Duplicate Advisory: Juju Unprotected Alternate Channel vulnerability

    ВысокаяCVSS 7,9Эксплойта нет

    Go · github.com/juju/juju2 окт. 2024 г.

  • CVE-2025-67303
    30Наблюдать

    An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data.

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    comfy · comfyui-manager5 янв. 2026 г.

  • GHSA-2hc9-cc65-xwj8
    30Наблюдать

    Duplicate Advisory: ComfyUI-Manager has an Unprotected Alternate Channel (CWE-420)

    ВысокаяCVSS 7,5Эксплойта нет

    PyPI · comfyui-manager5 янв. 2026 г.

  • CVE-2025-59033
    29Наблюдать

    The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy.

    ВысокаяCVSS 7,4Эксплойта нетEPSS 0 %

    microsoft · windows8 сент. 2025 г.

  • CVE-2023-28842
    27Наблюдать

    moby/moby's dockerd daemon encrypted overlay network with a single endpoint is unauthenticated

    СредняяCVSS 6,8Эксплойта нетEPSS 1 %

    mobyproject · moby4 апр. 2023 г.

  • CVE-2026-40435
    27Наблюдать

    BIG-IP httpd access control vulnerability

    СредняяCVSS 6,9Эксплойта нетEPSS 0 %

    f5 · big-ip access policy manager13 мая 2026 г.

Все классы уязвимостей