CWE-424 · 38 записей
Improper Protection of Alternate Path
CVE этого класса
38 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
95Срочно | CVE-2024-58136Готовый эксплойт | Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited iyiiframework · yii · CWE-424 | Критическая9,8 | KEV | 87,8 % | 9 апр. 2025 г. |
62На этой неделе | CVE-2025-48827Готовый эксплойт | vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when runningvbulletin · vbulletin · CWE-424 | Критическая9,8 | — | 75,8 % | 27 мая 2025 г. |
49В плане | CVE-2025-48828Готовый эксплойт | Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine.vbulletin · vbulletin · CWE-424 | Высокая8,1 | — | 57,6 % | 27 мая 2025 г. |
37Наблюдать | CVE-2023-52952Эксплойта нет | A vulnerability has been identified in HiMed Cockpit 12 pro (J31032-K2017-H259) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 14 pro+ (siemens · himed cockpit 12 pro · CWE-424 | Критическая9,3 | — | 0,2 % | 8 окт. 2024 г. |
35Наблюдать | CVE-2023-20272Эксплойта нет | A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to uplcisco · identity services engine · CWE-424 | Высокая8,8 | — | 0,9 % | 21 нояб. 2023 г. |
35Наблюдать | CVE-2023-5165Эксплойта нет | Docker Desktop before 4.23.0 allows Enhanced Container Isolation bypass via debug shelldocker · docker desktop · CWE-424 | Высокая8,8 | — | 0,3 % | 25 сент. 2023 г. |
32Наблюдать | CVE-2026-82586Эксплойта нет | AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributesash-project · ash_lua · CWE-424 | Высокая8,2 | — | 0,5 % | 7 сент. 2026 г. |
32Наблюдать | CVE-2026-54423Эксплойта нет | In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use topenstack · ironic · CWE-424 | Высокая8,2 | — | 0,5 % | 10 июл. 2026 г. |
32Наблюдать | CVE-2026-86145Эксплойта нет | PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspcre · pcre2 · CWE-424 | Высокая8,2 | — | 0,4 % | 5 сент. 2026 г. |
32Наблюдать | CVE-2026-37008Эксплойта нет | CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVEcrewai · crewai · CWE-424 | Высокая8,1 | — | 0,2 % | 13 сент. 2026 г. |
31Наблюдать | CVE-2019-18996Эксплойта нет | ABB PB610 HMIStudio accepts malicious DLL file in an applicationabb · pb610 panel builder 600 · CWE-424 | Высокая7,8 | — | 0,4 % | 18 дек. 2019 г. |
31Наблюдать | CVE-2024-3459Эксплойта нет | KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened kioware · kioware · CWE-424 | Высокая7,8 | — | 0,3 % | 14 мая 2024 г. |
31Наблюдать | CVE-2023-46176Эксплойта нет | IBM MQ privilege escalationibm · mq appliance · CWE-424 | Высокая7,8 | — | 0,2 % | 2 нояб. 2023 г. |
30Наблюдать | CVE-2019-18997Эксплойта нет | PB610 HMISimulator provides interface with access to arbitrary filesabb · pb610 panel builder 600 · CWE-424 | Высокая7,5 | — | 1,5 % | 18 дек. 2019 г. |
29Наблюдать | CVE-2026-0237Эксплойта нет | Prisma Browser: Improperly Restricted Automation Bridge Allows Security Bypasspaloaltonetworks · prisma browser · CWE-424 | Высокая7,3 | — | 0,2 % | 13 мая 2026 г. |
28Наблюдать | CVE-2024-3460Эксплойта нет | In KioWare for Windows (versions all through 8.34) it is possible to exit this software and use other already opened applications utilizing kioware · kioware · CWE-424 | Высокая7,0 | — | 0,3 % | 14 мая 2024 г. |
28Наблюдать | CVE-2023-0629Эксплойта нет | Docker Desktop before 4.17.0 allows an unprivileged user to bypass Enhanced Container Isolation restrictions via the raw Docker socket and launch privileged condocker · docker desktop · CWE-424 | Высокая7,1 | — | 0,2 % | 13 мар. 2023 г. |
28Наблюдать | CVE-2025-6250Эксплойта нет | Privilege Management for Windows - Elevation of Privilegebeyondtrust · privilege management for windows · CWE-424 | Высокая7,1 | — | 0,2 % | 28 июл. 2025 г. |
27Наблюдать | CVE-2026-66756Эксплойта нет | Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=falseapache · tika · CWE-424 | Средняя6,9 | — | 0,7 % | 30 июл. 2026 г. |
27Наблюдать | CVE-2022-1742Эксплойта нет | 2.2.4 IMPROPER PROTECTION OF ALTERNATE PATH CWE-424dominionvoting · imagecast x · CWE-424 | Средняя6,8 | — | 0,3 % | 24 июн. 2022 г. |
27Наблюдать | CVE-2026-4270Эксплойта нет | AWS API MCP File Access Restriction Bypassamazon · aws api mcp server · CWE-424 | Средняя6,8 | — | 0,2 % | 16 мар. 2026 г. |
26Наблюдать | CVE-2024-8311Эксплойта нет | Improper Protection of Alternate Path in GitLabgitlab · gitlab · CWE-424 | Средняя6,5 | — | 0,6 % | 12 сент. 2024 г. |
26Наблюдать | CVE-2026-58428Эксплойта нет | Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)gitea · gitea open source git server · CWE-424 | Средняя6,5 | — | 0,5 % | 13 авг. 2026 г. |
26Наблюдать | CVE-2025-49163Эксплойта нет | Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow booting an arbitrary image via a crafted /usr/bin/gunzip file.arris · vip1113 · CWE-424 | Средняя6,7 | — | 0,2 % | 2 июн. 2025 г. |
25Наблюдать | CVE-2026-82754Эксплойта нет | ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controlsash-project · ash_authentication_oauth2_server · CWE-424 | Средняя6,3 | — | 0,7 % | 7 сент. 2026 г. |
- CVE-2024-5813695Срочно
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited i
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 88 %yiiframework · yii9 апр. 2025 г.
- CVE-2025-4882762На этой неделе
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running
КритическаяCVSS 9,8Готовый эксплойтEPSS 76 %vbulletin · vbulletin27 мая 2025 г.
- CVE-2025-4882849В плане
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine.
ВысокаяCVSS 8,1Готовый эксплойтEPSS 58 %vbulletin · vbulletin27 мая 2025 г.
- CVE-2023-5295237Наблюдать
A vulnerability has been identified in HiMed Cockpit 12 pro (J31032-K2017-H259) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 14 pro+ (
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %siemens · himed cockpit 12 pro8 окт. 2024 г.
- CVE-2023-2027235Наблюдать
A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to upl
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %cisco · identity services engine21 нояб. 2023 г.
- CVE-2023-516535Наблюдать
Docker Desktop before 4.23.0 allows Enhanced Container Isolation bypass via debug shell
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %docker · docker desktop25 сент. 2023 г.
- CVE-2026-8258632Наблюдать
AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %ash-project · ash_lua7 сент. 2026 г.
- CVE-2026-5442332Наблюдать
In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use t
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %openstack · ironic10 июл. 2026 г.
- CVE-2026-8614532Наблюдать
PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching works
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %pcre · pcre25 сент. 2026 г.
- CVE-2026-3700832Наблюдать
CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %crewai · crewai13 сент. 2026 г.
- CVE-2019-1899631Наблюдать
ABB PB610 HMIStudio accepts malicious DLL file in an application
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %abb · pb610 panel builder 60018 дек. 2019 г.
- CVE-2024-345931Наблюдать
KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %kioware · kioware14 мая 2024 г.
- CVE-2023-4617631Наблюдать
IBM MQ privilege escalation
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %ibm · mq appliance2 нояб. 2023 г.
- CVE-2019-1899730Наблюдать
PB610 HMISimulator provides interface with access to arbitrary files
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %abb · pb610 panel builder 60018 дек. 2019 г.
- CVE-2026-023729Наблюдать
Prisma Browser: Improperly Restricted Automation Bridge Allows Security Bypass
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %paloaltonetworks · prisma browser13 мая 2026 г.
- CVE-2024-346028Наблюдать
In KioWare for Windows (versions all through 8.34) it is possible to exit this software and use other already opened applications utilizing
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %kioware · kioware14 мая 2024 г.
- CVE-2023-062928Наблюдать
Docker Desktop before 4.17.0 allows an unprivileged user to bypass Enhanced Container Isolation restrictions via the raw Docker socket and launch privileged con
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %docker · docker desktop13 мар. 2023 г.
- CVE-2025-625028Наблюдать
Privilege Management for Windows - Elevation of Privilege
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %beyondtrust · privilege management for windows28 июл. 2025 г.
- CVE-2026-6675627Наблюдать
Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false
СредняяCVSS 6,9Эксплойта нетEPSS 1 %apache · tika30 июл. 2026 г.
- CVE-2022-174227Наблюдать
2.2.4 IMPROPER PROTECTION OF ALTERNATE PATH CWE-424
СредняяCVSS 6,8Эксплойта нетEPSS 0 %dominionvoting · imagecast x24 июн. 2022 г.
- CVE-2026-427027Наблюдать
AWS API MCP File Access Restriction Bypass
СредняяCVSS 6,8Эксплойта нетEPSS 0 %amazon · aws api mcp server16 мар. 2026 г.
- CVE-2024-831126Наблюдать
Improper Protection of Alternate Path in GitLab
СредняяCVSS 6,5Эксплойта нетEPSS 1 %gitlab · gitlab12 сент. 2024 г.
- CVE-2026-5842826Наблюдать
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
СредняяCVSS 6,5Эксплойта нетEPSS 0 %gitea · gitea open source git server13 авг. 2026 г.
- CVE-2025-4916326Наблюдать
Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow booting an arbitrary image via a crafted /usr/bin/gunzip file.
СредняяCVSS 6,7Эксплойта нетEPSS 0 %arris · vip11132 июн. 2025 г.
- CVE-2026-8275425Наблюдать
ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls
СредняяCVSS 6,3Эксплойта нетEPSS 1 %ash-project · ash_authentication_oauth2_server7 сент. 2026 г.