CWE-420 · 40 записей
Unprotected Alternate Channel
CVE этого класса
40 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2023-20198Готовый эксплойт | Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.cisco · ios xe · CWE-420 | Критическая10,0 | KEV | 99,6 % | 16 окт. 2023 г. |
97Срочно | CVE-2025-54309Готовый эксплойт | CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allowscrushftp · crushftp · CWE-420 | Критическая9,8 | KEV | 94,9 % | 18 июл. 2025 г. |
47В плане | CVE-2025-13315Готовый эксплойт | Unauthenticated log access in Twonky Serverlinux · linux kernel · CWE-420 | Критическая9,3 | — | 32,3 % | 19 нояб. 2025 г. |
40В плане | CVE-2023-31241Эксплойта нет | Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.snapone · orvc · CWE-420 | Критическая10,0 | — | 0,8 % | 22 мая 2023 г. |
40В плане | CVE-2025-54351Эксплойта нет | In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).es · iperf3 · CWE-420 | Критическая10,0 | — | 0,4 % | 2 авг. 2025 г. |
39Наблюдать | CVE-2025-52921Эксплойта нет | In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution oinnoshop · innoshop · CWE-420 | Критическая9,9 | — | 0,5 % | 23 июн. 2025 г. |
36Наблюдать | CVE-2020-8558Proof of concept | Kubernetes node setting allows for neighboring hosts to bypass localhost boundarykubernetes · kubernetes · CWE-420 | Высокая8,8 | — | 3,6 % | 27 июл. 2020 г. |
36Наблюдать | CVE-2026-40217Proof of concept | LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.litellm · litellm · CWE-420 | Высокая8,8 | — | 3,4 % | 10 апр. 2026 г. |
35Наблюдать | CVE-2023-28840Эксплойта нет | moby/moby's dockerd daemon encrypted overlay network may be unauthenticatedmobyproject · moby · CWE-420 | Высокая8,7 | — | 2,6 % | 4 апр. 2023 г. |
35Наблюдать | CVE-2023-4570Эксплойта нет | Improper Restriction in NI MeasurementLink Python Servicesni · measurementlink · CWE-420 | Высокая8,8 | — | 0,3 % | 5 окт. 2023 г. |
35Наблюдать | GHSA-3926-2jvf-fg29Эксплойта нет | Duplicate Advisory: LiteLLM has a sandbox escape in custom-code guardrailPyPI · litellm · CWE-420 | Высокая8,8 | — | — | 10 апр. 2026 г. |
34Наблюдать | CVE-2025-53967Эксплойта нет | Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a craftframelink · figma mcp server · CWE-420 | Высокая8,0 | — | 5,8 % | 8 окт. 2025 г. |
34Наблюдать | CVE-2025-62001Эксплойта нет | BullWall Ransomware Containment hard-coded folder exclusionsbullwall · ransomware containment · CWE-420 | Высокая8,7 | — | 0,4 % | 18 дек. 2025 г. |
34Наблюдать | CVE-2025-8557Эксплойта нет | An internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attacker with access to a lenovo · xclarity orchestrator (lxco) · CWE-420 | Высокая8,7 | — | 0,3 % | 11 сент. 2025 г. |
32Наблюдать | CVE-2024-6242Эксплойта нет | Rockwell Automation Chassis Restrictions Bypass Vulnerability in Select Logix Devicesrockwell automation · controllogix® 5580 (1756-l8z) · CWE-420 | Высокая7,3 | — | 11,1 % | 1 авг. 2024 г. |
32Наблюдать | CVE-2023-7266Эксплойта нет | Some Huawei home routers have a connection hijacking vulnerability.huawei · tc7001-10 firmware · CWE-420 | Высокая8,1 | — | 0,3 % | 28 дек. 2024 г. |
32Наблюдать | CVE-2023-52718Эксплойта нет | A connection hijacking vulnerability exists in some Huawei home routers.huawei · pt9030-15 firmware · CWE-420 | Высокая8,1 | — | 0,2 % | 28 дек. 2024 г. |
31Наблюдать | CVE-2025-41727Эксплойта нет | Beckhoff: Performing privileged operations and gaining administrator accessbeckhoff automation · beckhoff.device.manager.xar · CWE-420 | Высокая7,8 | — | 0,2 % | 27 янв. 2026 г. |
31Наблюдать | CVE-2025-1095Эксплойта нет | IBM Personal Communications command executionibm · personal communications · CWE-420 | Высокая7,8 | — | 0,1 % | 8 апр. 2025 г. |
31Наблюдать | GHSA-85qf-6845-m8p2Эксплойта нет | Duplicate Advisory: Juju Unprotected Alternate Channel vulnerabilityGo · github.com/juju/juju · CWE-420 | Высокая7,9 | — | — | 2 окт. 2024 г. |
30Наблюдать | CVE-2025-67303Proof of concept | An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data.comfy · comfyui-manager · CWE-420 | Высокая7,5 | — | 1,4 % | 5 янв. 2026 г. |
30Наблюдать | GHSA-2hc9-cc65-xwj8Эксплойта нет | Duplicate Advisory: ComfyUI-Manager has an Unprotected Alternate Channel (CWE-420)PyPI · comfyui-manager · CWE-420 | Высокая7,5 | — | — | 5 янв. 2026 г. |
29Наблюдать | CVE-2025-59033Эксплойта нет | The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy.microsoft · windows · CWE-420 | Высокая7,4 | — | 0,3 % | 8 сент. 2025 г. |
27Наблюдать | CVE-2023-28842Эксплойта нет | moby/moby's dockerd daemon encrypted overlay network with a single endpoint is unauthenticatedmobyproject · moby · CWE-420 | Средняя6,8 | — | 1,4 % | 4 апр. 2023 г. |
27Наблюдать | CVE-2026-40435Эксплойта нет | BIG-IP httpd access control vulnerabilityf5 · big-ip access policy manager · CWE-420 | Средняя6,9 | — | 0,3 % | 13 мая 2026 г. |
- CVE-2023-20198100Срочно
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %cisco · ios xe16 окт. 2023 г.
- CVE-2025-5430997Срочно
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 95 %crushftp · crushftp18 июл. 2025 г.
- CVE-2025-1331547В плане
Unauthenticated log access in Twonky Server
КритическаяCVSS 9,3Готовый эксплойтEPSS 32 %linux · linux kernel19 нояб. 2025 г.
- CVE-2023-3124140В плане
Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %snapone · orvc22 мая 2023 г.
- CVE-2025-5435140В плане
In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %es · iperf32 авг. 2025 г.
- CVE-2025-5292139Наблюдать
In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution o
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %innoshop · innoshop23 июн. 2025 г.
- CVE-2020-855836Наблюдать
Kubernetes node setting allows for neighboring hosts to bypass localhost boundary
ВысокаяCVSS 8,8Proof of conceptEPSS 4 %kubernetes · kubernetes27 июл. 2020 г.
- CVE-2026-4021736Наблюдать
LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.
ВысокаяCVSS 8,8Proof of conceptEPSS 3 %litellm · litellm10 апр. 2026 г.
- CVE-2023-2884035Наблюдать
moby/moby's dockerd daemon encrypted overlay network may be unauthenticated
ВысокаяCVSS 8,7Эксплойта нетEPSS 3 %mobyproject · moby4 апр. 2023 г.
- CVE-2023-457035Наблюдать
Improper Restriction in NI MeasurementLink Python Services
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %ni · measurementlink5 окт. 2023 г.
- GHSA-3926-2jvf-fg2935Наблюдать
Duplicate Advisory: LiteLLM has a sandbox escape in custom-code guardrail
ВысокаяCVSS 8,8Эксплойта нетPyPI · litellm10 апр. 2026 г.
- CVE-2025-5396734Наблюдать
Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a craft
ВысокаяCVSS 8,0Эксплойта нетEPSS 6 %framelink · figma mcp server8 окт. 2025 г.
- CVE-2025-6200134Наблюдать
BullWall Ransomware Containment hard-coded folder exclusions
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %bullwall · ransomware containment18 дек. 2025 г.
- CVE-2025-855734Наблюдать
An internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attacker with access to a
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %lenovo · xclarity orchestrator (lxco)11 сент. 2025 г.
- CVE-2024-624232Наблюдать
Rockwell Automation Chassis Restrictions Bypass Vulnerability in Select Logix Devices
ВысокаяCVSS 7,3Эксплойта нетEPSS 11 %rockwell automation · controllogix® 5580 (1756-l8z)1 авг. 2024 г.
- CVE-2023-726632Наблюдать
Some Huawei home routers have a connection hijacking vulnerability.
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %huawei · tc7001-10 firmware28 дек. 2024 г.
- CVE-2023-5271832Наблюдать
A connection hijacking vulnerability exists in some Huawei home routers.
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %huawei · pt9030-15 firmware28 дек. 2024 г.
- CVE-2025-4172731Наблюдать
Beckhoff: Performing privileged operations and gaining administrator access
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %beckhoff automation · beckhoff.device.manager.xar27 янв. 2026 г.
- CVE-2025-109531Наблюдать
IBM Personal Communications command execution
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %ibm · personal communications8 апр. 2025 г.
- GHSA-85qf-6845-m8p231Наблюдать
Duplicate Advisory: Juju Unprotected Alternate Channel vulnerability
ВысокаяCVSS 7,9Эксплойта нетGo · github.com/juju/juju2 окт. 2024 г.
- CVE-2025-6730330Наблюдать
An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data.
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %comfy · comfyui-manager5 янв. 2026 г.
- GHSA-2hc9-cc65-xwj830Наблюдать
Duplicate Advisory: ComfyUI-Manager has an Unprotected Alternate Channel (CWE-420)
ВысокаяCVSS 7,5Эксплойта нетPyPI · comfyui-manager5 янв. 2026 г.
- CVE-2025-5903329Наблюдать
The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy.
ВысокаяCVSS 7,4Эксплойта нетEPSS 0 %microsoft · windows8 сент. 2025 г.
- CVE-2023-2884227Наблюдать
moby/moby's dockerd daemon encrypted overlay network with a single endpoint is unauthenticated
СредняяCVSS 6,8Эксплойта нетEPSS 1 %mobyproject · moby4 апр. 2023 г.
- CVE-2026-4043527Наблюдать
BIG-IP httpd access control vulnerability
СредняяCVSS 6,9Эксплойта нетEPSS 0 %f5 · big-ip access policy manager13 мая 2026 г.