Перейти к содержимому
Noroxi

CWE-424 · 38 записей

Improper Protection of Alternate Path

CVE этого класса

38 записей

  • CVE-2024-58136
    95Срочно

    Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited i

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 88 %

    yiiframework · yii9 апр. 2025 г.

  • CVE-2025-48827
    62На этой неделе

    vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running

    КритическаяCVSS 9,8Готовый эксплойтEPSS 76 %

    vbulletin · vbulletin27 мая 2025 г.

  • CVE-2025-48828
    49В плане

    Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine.

    ВысокаяCVSS 8,1Готовый эксплойтEPSS 58 %

    vbulletin · vbulletin27 мая 2025 г.

  • CVE-2023-52952
    37Наблюдать

    A vulnerability has been identified in HiMed Cockpit 12 pro (J31032-K2017-H259) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 14 pro+ (

    КритическаяCVSS 9,3Эксплойта нетEPSS 0 %

    siemens · himed cockpit 12 pro8 окт. 2024 г.

  • CVE-2023-20272
    35Наблюдать

    A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to upl

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    cisco · identity services engine21 нояб. 2023 г.

  • CVE-2023-5165
    35Наблюдать

    Docker Desktop before 4.23.0 allows Enhanced Container Isolation bypass via debug shell

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    docker · docker desktop25 сент. 2023 г.

  • CVE-2026-82586
    32Наблюдать

    AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes

    ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %

    ash-project · ash_lua7 сент. 2026 г.

  • CVE-2026-54423
    32Наблюдать

    In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use t

    ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %

    openstack · ironic10 июл. 2026 г.

  • CVE-2026-86145
    32Наблюдать

    PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching works

    ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %

    pcre · pcre25 сент. 2026 г.

  • CVE-2026-37008
    32Наблюдать

    CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    crewai · crewai13 сент. 2026 г.

  • CVE-2019-18996
    31Наблюдать

    ABB PB610 HMIStudio accepts malicious DLL file in an application

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    abb · pb610 panel builder 60018 дек. 2019 г.

  • CVE-2024-3459
    31Наблюдать

    KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    kioware · kioware14 мая 2024 г.

  • CVE-2023-46176
    31Наблюдать

    IBM MQ privilege escalation

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    ibm · mq appliance2 нояб. 2023 г.

  • CVE-2019-18997
    30Наблюдать

    PB610 HMISimulator provides interface with access to arbitrary files

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    abb · pb610 panel builder 60018 дек. 2019 г.

  • CVE-2026-0237
    29Наблюдать

    Prisma Browser: Improperly Restricted Automation Bridge Allows Security Bypass

    ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %

    paloaltonetworks · prisma browser13 мая 2026 г.

  • CVE-2024-3460
    28Наблюдать

    In KioWare for Windows (versions all through 8.34) it is possible to exit this software and use other already opened applications utilizing

    ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %

    kioware · kioware14 мая 2024 г.

  • CVE-2023-0629
    28Наблюдать

    Docker Desktop before 4.17.0 allows an unprivileged user to bypass Enhanced Container Isolation restrictions via the raw Docker socket and launch privileged con

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    docker · docker desktop13 мар. 2023 г.

  • CVE-2025-6250
    28Наблюдать

    Privilege Management for Windows - Elevation of Privilege

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    beyondtrust · privilege management for windows28 июл. 2025 г.

  • CVE-2026-66756
    27Наблюдать

    Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false

    СредняяCVSS 6,9Эксплойта нетEPSS 1 %

    apache · tika30 июл. 2026 г.

  • CVE-2022-1742
    27Наблюдать

    2.2.4 IMPROPER PROTECTION OF ALTERNATE PATH CWE-424

    СредняяCVSS 6,8Эксплойта нетEPSS 0 %

    dominionvoting · imagecast x24 июн. 2022 г.

  • CVE-2026-4270
    27Наблюдать

    AWS API MCP File Access Restriction Bypass

    СредняяCVSS 6,8Эксплойта нетEPSS 0 %

    amazon · aws api mcp server16 мар. 2026 г.

  • CVE-2024-8311
    26Наблюдать

    Improper Protection of Alternate Path in GitLab

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    gitlab · gitlab12 сент. 2024 г.

  • CVE-2026-58428
    26Наблюдать

    Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    gitea · gitea open source git server13 авг. 2026 г.

  • CVE-2025-49163
    26Наблюдать

    Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow booting an arbitrary image via a crafted /usr/bin/gunzip file.

    СредняяCVSS 6,7Эксплойта нетEPSS 0 %

    arris · vip11132 июн. 2025 г.

  • CVE-2026-82754
    25Наблюдать

    ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls

    СредняяCVSS 6,3Эксплойта нетEPSS 1 %

    ash-project · ash_authentication_oauth2_server7 сент. 2026 г.

Все классы уязвимостей