İçeriğe atla
Noroxi

CWE-420 · 40 kayıt

Unprotected Alternate Channel

Bu sınıftaki CVE’ler

40 kayıt

  • Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100

    cisco · ios xe16 Eki 2023

  • CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %95

    crushftp · crushftp18 Tem 2025

  • CVE-2025-13315
    47Planlayın

    Unauthenticated log access in Twonky Server

    KritikCVSS 9,3SilahlaştırılmışEPSS %32

    linux · linux kernel19 Kas 2025

  • CVE-2023-31241
    40Planlayın

    Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.

    KritikCVSS 10,0İstismar yokEPSS %1

    snapone · orvc22 May 2023

  • CVE-2025-54351
    40Planlayın

    In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).

    KritikCVSS 10,0İstismar yokEPSS %0

    es · iperf32 Ağu 2025

  • CVE-2025-52921
    39İzleyin

    In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution o

    KritikCVSS 9,9İstismar yokEPSS %1

    innoshop · innoshop23 Haz 2025

  • CVE-2020-8558
    36İzleyin

    Kubernetes node setting allows for neighboring hosts to bypass localhost boundary

    YüksekCVSS 8,8Kavram kanıtıEPSS %4

    kubernetes · kubernetes27 Tem 2020

  • CVE-2026-40217
    36İzleyin

    LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.

    YüksekCVSS 8,8Kavram kanıtıEPSS %3

    litellm · litellm10 Nis 2026

  • CVE-2023-28840
    35İzleyin

    moby/moby's dockerd daemon encrypted overlay network may be unauthenticated

    YüksekCVSS 8,7İstismar yokEPSS %3

    mobyproject · moby4 Nis 2023

  • CVE-2023-4570
    35İzleyin

    Improper Restriction in NI MeasurementLink Python Services

    YüksekCVSS 8,8İstismar yokEPSS %0

    ni · measurementlink5 Eki 2023

  • Duplicate Advisory: LiteLLM has a sandbox escape in custom-code guardrail

    YüksekCVSS 8,8İstismar yok

    PyPI · litellm10 Nis 2026

  • CVE-2025-53967
    34İzleyin

    Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a craft

    YüksekCVSS 8,0İstismar yokEPSS %6

    framelink · figma mcp server8 Eki 2025

  • CVE-2025-62001
    34İzleyin

    BullWall Ransomware Containment hard-coded folder exclusions

    YüksekCVSS 8,7İstismar yokEPSS %0

    bullwall · ransomware containment18 Ara 2025

  • CVE-2025-8557
    34İzleyin

    An internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attacker with access to a

    YüksekCVSS 8,7İstismar yokEPSS %0

    lenovo · xclarity orchestrator (lxco)11 Eyl 2025

  • CVE-2024-6242
    32İzleyin

    Rockwell Automation Chassis Restrictions Bypass Vulnerability in Select Logix Devices

    YüksekCVSS 7,3İstismar yokEPSS %11

    rockwell automation · controllogix® 5580 (1756-l8z)1 Ağu 2024

  • CVE-2023-7266
    32İzleyin

    Some Huawei home routers have a connection hijacking vulnerability.

    YüksekCVSS 8,1İstismar yokEPSS %0

    huawei · tc7001-10 firmware28 Ara 2024

  • CVE-2023-52718
    32İzleyin

    A connection hijacking vulnerability exists in some Huawei home routers.

    YüksekCVSS 8,1İstismar yokEPSS %0

    huawei · pt9030-15 firmware28 Ara 2024

  • CVE-2025-41727
    31İzleyin

    Beckhoff: Performing privileged operations and gaining administrator access

    YüksekCVSS 7,8İstismar yokEPSS %0

    beckhoff automation · beckhoff.device.manager.xar27 Oca 2026

  • CVE-2025-1095
    31İzleyin

    IBM Personal Communications command execution

    YüksekCVSS 7,8İstismar yokEPSS %0

    ibm · personal communications8 Nis 2025

  • Duplicate Advisory: Juju Unprotected Alternate Channel vulnerability

    YüksekCVSS 7,9İstismar yok

    Go · github.com/juju/juju2 Eki 2024

  • CVE-2025-67303
    30İzleyin

    An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data.

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    comfy · comfyui-manager5 Oca 2026

  • Duplicate Advisory: ComfyUI-Manager has an Unprotected Alternate Channel (CWE-420)

    YüksekCVSS 7,5İstismar yok

    PyPI · comfyui-manager5 Oca 2026

  • CVE-2025-59033
    29İzleyin

    The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy.

    YüksekCVSS 7,4İstismar yokEPSS %0

    microsoft · windows8 Eyl 2025

  • CVE-2023-28842
    27İzleyin

    moby/moby's dockerd daemon encrypted overlay network with a single endpoint is unauthenticated

    OrtaCVSS 6,8İstismar yokEPSS %1

    mobyproject · moby4 Nis 2023

  • CVE-2026-40435
    27İzleyin

    BIG-IP httpd access control vulnerability

    OrtaCVSS 6,9İstismar yokEPSS %0

    f5 · big-ip access policy manager13 May 2026

Tüm zafiyet sınıfları