CWE-420 · 40 kayıt
Unprotected Alternate Channel
Bu sınıftaki CVE’ler
40 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
100Hemen | CVE-2023-20198Silahlaştırılmış | Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.cisco · ios xe · CWE-420 | Kritik10,0 | KEV | %99,6 | 16 Eki 2023 |
97Hemen | CVE-2025-54309Silahlaştırılmış | CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allowscrushftp · crushftp · CWE-420 | Kritik9,8 | KEV | %94,9 | 18 Tem 2025 |
47Planlayın | CVE-2025-13315Silahlaştırılmış | Unauthenticated log access in Twonky Serverlinux · linux kernel · CWE-420 | Kritik9,3 | — | %32,3 | 19 Kas 2025 |
40Planlayın | CVE-2023-31241İstismar yok | Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.snapone · orvc · CWE-420 | Kritik10,0 | — | %0,8 | 22 May 2023 |
40Planlayın | CVE-2025-54351İstismar yok | In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).es · iperf3 · CWE-420 | Kritik10,0 | — | %0,4 | 2 Ağu 2025 |
39İzleyin | CVE-2025-52921İstismar yok | In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution oinnoshop · innoshop · CWE-420 | Kritik9,9 | — | %0,5 | 23 Haz 2025 |
36İzleyin | CVE-2020-8558Kavram kanıtı | Kubernetes node setting allows for neighboring hosts to bypass localhost boundarykubernetes · kubernetes · CWE-420 | Yüksek8,8 | — | %3,6 | 27 Tem 2020 |
36İzleyin | CVE-2026-40217Kavram kanıtı | LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.litellm · litellm · CWE-420 | Yüksek8,8 | — | %3,4 | 10 Nis 2026 |
35İzleyin | CVE-2023-28840İstismar yok | moby/moby's dockerd daemon encrypted overlay network may be unauthenticatedmobyproject · moby · CWE-420 | Yüksek8,7 | — | %2,6 | 4 Nis 2023 |
35İzleyin | CVE-2023-4570İstismar yok | Improper Restriction in NI MeasurementLink Python Servicesni · measurementlink · CWE-420 | Yüksek8,8 | — | %0,3 | 5 Eki 2023 |
35İzleyin | GHSA-3926-2jvf-fg29İstismar yok | Duplicate Advisory: LiteLLM has a sandbox escape in custom-code guardrailPyPI · litellm · CWE-420 | Yüksek8,8 | — | — | 10 Nis 2026 |
34İzleyin | CVE-2025-53967İstismar yok | Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a craftframelink · figma mcp server · CWE-420 | Yüksek8,0 | — | %5,8 | 8 Eki 2025 |
34İzleyin | CVE-2025-62001İstismar yok | BullWall Ransomware Containment hard-coded folder exclusionsbullwall · ransomware containment · CWE-420 | Yüksek8,7 | — | %0,4 | 18 Ara 2025 |
34İzleyin | CVE-2025-8557İstismar yok | An internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attacker with access to a lenovo · xclarity orchestrator (lxco) · CWE-420 | Yüksek8,7 | — | %0,3 | 11 Eyl 2025 |
32İzleyin | CVE-2024-6242İstismar yok | Rockwell Automation Chassis Restrictions Bypass Vulnerability in Select Logix Devicesrockwell automation · controllogix® 5580 (1756-l8z) · CWE-420 | Yüksek7,3 | — | %11,1 | 1 Ağu 2024 |
32İzleyin | CVE-2023-7266İstismar yok | Some Huawei home routers have a connection hijacking vulnerability.huawei · tc7001-10 firmware · CWE-420 | Yüksek8,1 | — | %0,3 | 28 Ara 2024 |
32İzleyin | CVE-2023-52718İstismar yok | A connection hijacking vulnerability exists in some Huawei home routers.huawei · pt9030-15 firmware · CWE-420 | Yüksek8,1 | — | %0,2 | 28 Ara 2024 |
31İzleyin | CVE-2025-41727İstismar yok | Beckhoff: Performing privileged operations and gaining administrator accessbeckhoff automation · beckhoff.device.manager.xar · CWE-420 | Yüksek7,8 | — | %0,2 | 27 Oca 2026 |
31İzleyin | CVE-2025-1095İstismar yok | IBM Personal Communications command executionibm · personal communications · CWE-420 | Yüksek7,8 | — | %0,1 | 8 Nis 2025 |
31İzleyin | GHSA-85qf-6845-m8p2İstismar yok | Duplicate Advisory: Juju Unprotected Alternate Channel vulnerabilityGo · github.com/juju/juju · CWE-420 | Yüksek7,9 | — | — | 2 Eki 2024 |
30İzleyin | CVE-2025-67303Kavram kanıtı | An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data.comfy · comfyui-manager · CWE-420 | Yüksek7,5 | — | %1,4 | 5 Oca 2026 |
30İzleyin | GHSA-2hc9-cc65-xwj8İstismar yok | Duplicate Advisory: ComfyUI-Manager has an Unprotected Alternate Channel (CWE-420)PyPI · comfyui-manager · CWE-420 | Yüksek7,5 | — | — | 5 Oca 2026 |
29İzleyin | CVE-2025-59033İstismar yok | The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy.microsoft · windows · CWE-420 | Yüksek7,4 | — | %0,3 | 8 Eyl 2025 |
27İzleyin | CVE-2023-28842İstismar yok | moby/moby's dockerd daemon encrypted overlay network with a single endpoint is unauthenticatedmobyproject · moby · CWE-420 | Orta6,8 | — | %1,4 | 4 Nis 2023 |
27İzleyin | CVE-2026-40435İstismar yok | BIG-IP httpd access control vulnerabilityf5 · big-ip access policy manager · CWE-420 | Orta6,9 | — | %0,3 | 13 May 2026 |
- CVE-2023-20198100Hemen
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100cisco · ios xe16 Eki 2023
- CVE-2025-5430997Hemen
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %95crushftp · crushftp18 Tem 2025
- CVE-2025-1331547Planlayın
Unauthenticated log access in Twonky Server
KritikCVSS 9,3SilahlaştırılmışEPSS %32linux · linux kernel19 Kas 2025
- CVE-2023-3124140Planlayın
Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.
KritikCVSS 10,0İstismar yokEPSS %1snapone · orvc22 May 2023
- CVE-2025-5435140Planlayın
In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).
KritikCVSS 10,0İstismar yokEPSS %0es · iperf32 Ağu 2025
- CVE-2025-5292139İzleyin
In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution o
KritikCVSS 9,9İstismar yokEPSS %1innoshop · innoshop23 Haz 2025
- CVE-2020-855836İzleyin
Kubernetes node setting allows for neighboring hosts to bypass localhost boundary
YüksekCVSS 8,8Kavram kanıtıEPSS %4kubernetes · kubernetes27 Tem 2020
- CVE-2026-4021736İzleyin
LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.
YüksekCVSS 8,8Kavram kanıtıEPSS %3litellm · litellm10 Nis 2026
- CVE-2023-2884035İzleyin
moby/moby's dockerd daemon encrypted overlay network may be unauthenticated
YüksekCVSS 8,7İstismar yokEPSS %3mobyproject · moby4 Nis 2023
- CVE-2023-457035İzleyin
Improper Restriction in NI MeasurementLink Python Services
YüksekCVSS 8,8İstismar yokEPSS %0ni · measurementlink5 Eki 2023
- GHSA-3926-2jvf-fg2935İzleyin
Duplicate Advisory: LiteLLM has a sandbox escape in custom-code guardrail
YüksekCVSS 8,8İstismar yokPyPI · litellm10 Nis 2026
- CVE-2025-5396734İzleyin
Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a craft
YüksekCVSS 8,0İstismar yokEPSS %6framelink · figma mcp server8 Eki 2025
- CVE-2025-6200134İzleyin
BullWall Ransomware Containment hard-coded folder exclusions
YüksekCVSS 8,7İstismar yokEPSS %0bullwall · ransomware containment18 Ara 2025
- CVE-2025-855734İzleyin
An internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attacker with access to a
YüksekCVSS 8,7İstismar yokEPSS %0lenovo · xclarity orchestrator (lxco)11 Eyl 2025
- CVE-2024-624232İzleyin
Rockwell Automation Chassis Restrictions Bypass Vulnerability in Select Logix Devices
YüksekCVSS 7,3İstismar yokEPSS %11rockwell automation · controllogix® 5580 (1756-l8z)1 Ağu 2024
- CVE-2023-726632İzleyin
Some Huawei home routers have a connection hijacking vulnerability.
YüksekCVSS 8,1İstismar yokEPSS %0huawei · tc7001-10 firmware28 Ara 2024
- CVE-2023-5271832İzleyin
A connection hijacking vulnerability exists in some Huawei home routers.
YüksekCVSS 8,1İstismar yokEPSS %0huawei · pt9030-15 firmware28 Ara 2024
- CVE-2025-4172731İzleyin
Beckhoff: Performing privileged operations and gaining administrator access
YüksekCVSS 7,8İstismar yokEPSS %0beckhoff automation · beckhoff.device.manager.xar27 Oca 2026
- CVE-2025-109531İzleyin
IBM Personal Communications command execution
YüksekCVSS 7,8İstismar yokEPSS %0ibm · personal communications8 Nis 2025
- GHSA-85qf-6845-m8p231İzleyin
Duplicate Advisory: Juju Unprotected Alternate Channel vulnerability
YüksekCVSS 7,9İstismar yokGo · github.com/juju/juju2 Eki 2024
- CVE-2025-6730330İzleyin
An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data.
YüksekCVSS 7,5Kavram kanıtıEPSS %1comfy · comfyui-manager5 Oca 2026
- GHSA-2hc9-cc65-xwj830İzleyin
Duplicate Advisory: ComfyUI-Manager has an Unprotected Alternate Channel (CWE-420)
YüksekCVSS 7,5İstismar yokPyPI · comfyui-manager5 Oca 2026
- CVE-2025-5903329İzleyin
The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy.
YüksekCVSS 7,4İstismar yokEPSS %0microsoft · windows8 Eyl 2025
- CVE-2023-2884227İzleyin
moby/moby's dockerd daemon encrypted overlay network with a single endpoint is unauthenticated
OrtaCVSS 6,8İstismar yokEPSS %1mobyproject · moby4 Nis 2023
- CVE-2026-4043527İzleyin
BIG-IP httpd access control vulnerability
OrtaCVSS 6,9İstismar yokEPSS %0f5 · big-ip access policy manager13 May 2026