CWE-424 · 38 kayıt
Improper Protection of Alternate Path
Bu sınıftaki CVE’ler
38 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
95Hemen | CVE-2024-58136Silahlaştırılmış | Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited iyiiframework · yii · CWE-424 | Kritik9,8 | KEV | %87,8 | 9 Nis 2025 |
62Bu hafta | CVE-2025-48827Silahlaştırılmış | vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when runningvbulletin · vbulletin · CWE-424 | Kritik9,8 | — | %75,8 | 27 May 2025 |
49Planlayın | CVE-2025-48828Silahlaştırılmış | Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine.vbulletin · vbulletin · CWE-424 | Yüksek8,1 | — | %57,6 | 27 May 2025 |
37İzleyin | CVE-2023-52952İstismar yok | A vulnerability has been identified in HiMed Cockpit 12 pro (J31032-K2017-H259) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 14 pro+ (siemens · himed cockpit 12 pro · CWE-424 | Kritik9,3 | — | %0,2 | 8 Eki 2024 |
35İzleyin | CVE-2023-20272İstismar yok | A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to uplcisco · identity services engine · CWE-424 | Yüksek8,8 | — | %0,9 | 21 Kas 2023 |
35İzleyin | CVE-2023-5165İstismar yok | Docker Desktop before 4.23.0 allows Enhanced Container Isolation bypass via debug shelldocker · docker desktop · CWE-424 | Yüksek8,8 | — | %0,3 | 25 Eyl 2023 |
32İzleyin | CVE-2026-82586İstismar yok | AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributesash-project · ash_lua · CWE-424 | Yüksek8,2 | — | %0,5 | 7 Eyl 2026 |
32İzleyin | CVE-2026-54423İstismar yok | In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use topenstack · ironic · CWE-424 | Yüksek8,2 | — | %0,5 | 10 Tem 2026 |
32İzleyin | CVE-2026-86145İstismar yok | PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspcre · pcre2 · CWE-424 | Yüksek8,2 | — | %0,4 | 5 Eyl 2026 |
32İzleyin | CVE-2026-37008İstismar yok | CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVEcrewai · crewai · CWE-424 | Yüksek8,1 | — | %0,2 | 13 Eyl 2026 |
31İzleyin | CVE-2019-18996İstismar yok | ABB PB610 HMIStudio accepts malicious DLL file in an applicationabb · pb610 panel builder 600 · CWE-424 | Yüksek7,8 | — | %0,4 | 18 Ara 2019 |
31İzleyin | CVE-2024-3459İstismar yok | KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened kioware · kioware · CWE-424 | Yüksek7,8 | — | %0,3 | 14 May 2024 |
31İzleyin | CVE-2023-46176İstismar yok | IBM MQ privilege escalationibm · mq appliance · CWE-424 | Yüksek7,8 | — | %0,2 | 2 Kas 2023 |
30İzleyin | CVE-2019-18997İstismar yok | PB610 HMISimulator provides interface with access to arbitrary filesabb · pb610 panel builder 600 · CWE-424 | Yüksek7,5 | — | %1,5 | 18 Ara 2019 |
29İzleyin | CVE-2026-0237İstismar yok | Prisma Browser: Improperly Restricted Automation Bridge Allows Security Bypasspaloaltonetworks · prisma browser · CWE-424 | Yüksek7,3 | — | %0,2 | 13 May 2026 |
28İzleyin | CVE-2024-3460İstismar yok | In KioWare for Windows (versions all through 8.34) it is possible to exit this software and use other already opened applications utilizing kioware · kioware · CWE-424 | Yüksek7,0 | — | %0,3 | 14 May 2024 |
28İzleyin | CVE-2023-0629İstismar yok | Docker Desktop before 4.17.0 allows an unprivileged user to bypass Enhanced Container Isolation restrictions via the raw Docker socket and launch privileged condocker · docker desktop · CWE-424 | Yüksek7,1 | — | %0,2 | 13 Mar 2023 |
28İzleyin | CVE-2025-6250İstismar yok | Privilege Management for Windows - Elevation of Privilegebeyondtrust · privilege management for windows · CWE-424 | Yüksek7,1 | — | %0,2 | 28 Tem 2025 |
27İzleyin | CVE-2026-66756İstismar yok | Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=falseapache · tika · CWE-424 | Orta6,9 | — | %0,7 | 30 Tem 2026 |
27İzleyin | CVE-2022-1742İstismar yok | 2.2.4 IMPROPER PROTECTION OF ALTERNATE PATH CWE-424dominionvoting · imagecast x · CWE-424 | Orta6,8 | — | %0,3 | 24 Haz 2022 |
27İzleyin | CVE-2026-4270İstismar yok | AWS API MCP File Access Restriction Bypassamazon · aws api mcp server · CWE-424 | Orta6,8 | — | %0,2 | 16 Mar 2026 |
26İzleyin | CVE-2024-8311İstismar yok | Improper Protection of Alternate Path in GitLabgitlab · gitlab · CWE-424 | Orta6,5 | — | %0,6 | 12 Eyl 2024 |
26İzleyin | CVE-2026-58428İstismar yok | Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)gitea · gitea open source git server · CWE-424 | Orta6,5 | — | %0,5 | 13 Ağu 2026 |
26İzleyin | CVE-2025-49163İstismar yok | Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow booting an arbitrary image via a crafted /usr/bin/gunzip file.arris · vip1113 · CWE-424 | Orta6,7 | — | %0,2 | 2 Haz 2025 |
25İzleyin | CVE-2026-82754İstismar yok | ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controlsash-project · ash_authentication_oauth2_server · CWE-424 | Orta6,3 | — | %0,7 | 7 Eyl 2026 |
- CVE-2024-5813695Hemen
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited i
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %88yiiframework · yii9 Nis 2025
- CVE-2025-4882762Bu hafta
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running
KritikCVSS 9,8SilahlaştırılmışEPSS %76vbulletin · vbulletin27 May 2025
- CVE-2025-4882849Planlayın
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine.
YüksekCVSS 8,1SilahlaştırılmışEPSS %58vbulletin · vbulletin27 May 2025
- CVE-2023-5295237İzleyin
A vulnerability has been identified in HiMed Cockpit 12 pro (J31032-K2017-H259) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 14 pro+ (
KritikCVSS 9,3İstismar yokEPSS %0siemens · himed cockpit 12 pro8 Eki 2024
- CVE-2023-2027235İzleyin
A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to upl
YüksekCVSS 8,8İstismar yokEPSS %1cisco · identity services engine21 Kas 2023
- CVE-2023-516535İzleyin
Docker Desktop before 4.23.0 allows Enhanced Container Isolation bypass via debug shell
YüksekCVSS 8,8İstismar yokEPSS %0docker · docker desktop25 Eyl 2023
- CVE-2026-8258632İzleyin
AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
YüksekCVSS 8,2İstismar yokEPSS %1ash-project · ash_lua7 Eyl 2026
- CVE-2026-5442332İzleyin
In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use t
YüksekCVSS 8,2İstismar yokEPSS %0openstack · ironic10 Tem 2026
- CVE-2026-8614532İzleyin
PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching works
YüksekCVSS 8,2İstismar yokEPSS %0pcre · pcre25 Eyl 2026
- CVE-2026-3700832İzleyin
CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE
YüksekCVSS 8,1İstismar yokEPSS %0crewai · crewai13 Eyl 2026
- CVE-2019-1899631İzleyin
ABB PB610 HMIStudio accepts malicious DLL file in an application
YüksekCVSS 7,8İstismar yokEPSS %0abb · pb610 panel builder 60018 Ara 2019
- CVE-2024-345931İzleyin
KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened
YüksekCVSS 7,8İstismar yokEPSS %0kioware · kioware14 May 2024
- CVE-2023-4617631İzleyin
IBM MQ privilege escalation
YüksekCVSS 7,8İstismar yokEPSS %0ibm · mq appliance2 Kas 2023
- CVE-2019-1899730İzleyin
PB610 HMISimulator provides interface with access to arbitrary files
YüksekCVSS 7,5İstismar yokEPSS %2abb · pb610 panel builder 60018 Ara 2019
- CVE-2026-023729İzleyin
Prisma Browser: Improperly Restricted Automation Bridge Allows Security Bypass
YüksekCVSS 7,3İstismar yokEPSS %0paloaltonetworks · prisma browser13 May 2026
- CVE-2024-346028İzleyin
In KioWare for Windows (versions all through 8.34) it is possible to exit this software and use other already opened applications utilizing
YüksekCVSS 7,0İstismar yokEPSS %0kioware · kioware14 May 2024
- CVE-2023-062928İzleyin
Docker Desktop before 4.17.0 allows an unprivileged user to bypass Enhanced Container Isolation restrictions via the raw Docker socket and launch privileged con
YüksekCVSS 7,1İstismar yokEPSS %0docker · docker desktop13 Mar 2023
- CVE-2025-625028İzleyin
Privilege Management for Windows - Elevation of Privilege
YüksekCVSS 7,1İstismar yokEPSS %0beyondtrust · privilege management for windows28 Tem 2025
- CVE-2026-6675627İzleyin
Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false
OrtaCVSS 6,9İstismar yokEPSS %1apache · tika30 Tem 2026
- CVE-2022-174227İzleyin
2.2.4 IMPROPER PROTECTION OF ALTERNATE PATH CWE-424
OrtaCVSS 6,8İstismar yokEPSS %0dominionvoting · imagecast x24 Haz 2022
- CVE-2026-427027İzleyin
AWS API MCP File Access Restriction Bypass
OrtaCVSS 6,8İstismar yokEPSS %0amazon · aws api mcp server16 Mar 2026
- CVE-2024-831126İzleyin
Improper Protection of Alternate Path in GitLab
OrtaCVSS 6,5İstismar yokEPSS %1gitlab · gitlab12 Eyl 2024
- CVE-2026-5842826İzleyin
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
OrtaCVSS 6,5İstismar yokEPSS %0gitea · gitea open source git server13 Ağu 2026
- CVE-2025-4916326İzleyin
Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow booting an arbitrary image via a crafted /usr/bin/gunzip file.
OrtaCVSS 6,7İstismar yokEPSS %0arris · vip11132 Haz 2025
- CVE-2026-8275425İzleyin
ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls
OrtaCVSS 6,3İstismar yokEPSS %1ash-project · ash_authentication_oauth2_server7 Eyl 2026