İçeriğe atla
Noroxi

CWE-424 · 38 kayıt

Improper Protection of Alternate Path

Bu sınıftaki CVE’ler

38 kayıt

  • Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited i

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %88

    yiiframework · yii9 Nis 2025

  • CVE-2025-48827
    62Bu hafta

    vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running

    KritikCVSS 9,8SilahlaştırılmışEPSS %76

    vbulletin · vbulletin27 May 2025

  • CVE-2025-48828
    49Planlayın

    Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine.

    YüksekCVSS 8,1SilahlaştırılmışEPSS %58

    vbulletin · vbulletin27 May 2025

  • CVE-2023-52952
    37İzleyin

    A vulnerability has been identified in HiMed Cockpit 12 pro (J31032-K2017-H259) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 14 pro+ (

    KritikCVSS 9,3İstismar yokEPSS %0

    siemens · himed cockpit 12 pro8 Eki 2024

  • CVE-2023-20272
    35İzleyin

    A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to upl

    YüksekCVSS 8,8İstismar yokEPSS %1

    cisco · identity services engine21 Kas 2023

  • CVE-2023-5165
    35İzleyin

    Docker Desktop before 4.23.0 allows Enhanced Container Isolation bypass via debug shell

    YüksekCVSS 8,8İstismar yokEPSS %0

    docker · docker desktop25 Eyl 2023

  • CVE-2026-82586
    32İzleyin

    AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes

    YüksekCVSS 8,2İstismar yokEPSS %1

    ash-project · ash_lua7 Eyl 2026

  • CVE-2026-54423
    32İzleyin

    In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use t

    YüksekCVSS 8,2İstismar yokEPSS %0

    openstack · ironic10 Tem 2026

  • CVE-2026-86145
    32İzleyin

    PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching works

    YüksekCVSS 8,2İstismar yokEPSS %0

    pcre · pcre25 Eyl 2026

  • CVE-2026-37008
    32İzleyin

    CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE

    YüksekCVSS 8,1İstismar yokEPSS %0

    crewai · crewai13 Eyl 2026

  • CVE-2019-18996
    31İzleyin

    ABB PB610 HMIStudio accepts malicious DLL file in an application

    YüksekCVSS 7,8İstismar yokEPSS %0

    abb · pb610 panel builder 60018 Ara 2019

  • CVE-2024-3459
    31İzleyin

    KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened

    YüksekCVSS 7,8İstismar yokEPSS %0

    kioware · kioware14 May 2024

  • CVE-2023-46176
    31İzleyin

    IBM MQ privilege escalation

    YüksekCVSS 7,8İstismar yokEPSS %0

    ibm · mq appliance2 Kas 2023

  • CVE-2019-18997
    30İzleyin

    PB610 HMISimulator provides interface with access to arbitrary files

    YüksekCVSS 7,5İstismar yokEPSS %2

    abb · pb610 panel builder 60018 Ara 2019

  • CVE-2026-0237
    29İzleyin

    Prisma Browser: Improperly Restricted Automation Bridge Allows Security Bypass

    YüksekCVSS 7,3İstismar yokEPSS %0

    paloaltonetworks · prisma browser13 May 2026

  • CVE-2024-3460
    28İzleyin

    In KioWare for Windows (versions all through 8.34) it is possible to exit this software and use other already opened applications utilizing

    YüksekCVSS 7,0İstismar yokEPSS %0

    kioware · kioware14 May 2024

  • CVE-2023-0629
    28İzleyin

    Docker Desktop before 4.17.0 allows an unprivileged user to bypass Enhanced Container Isolation restrictions via the raw Docker socket and launch privileged con

    YüksekCVSS 7,1İstismar yokEPSS %0

    docker · docker desktop13 Mar 2023

  • CVE-2025-6250
    28İzleyin

    Privilege Management for Windows - Elevation of Privilege

    YüksekCVSS 7,1İstismar yokEPSS %0

    beyondtrust · privilege management for windows28 Tem 2025

  • CVE-2026-66756
    27İzleyin

    Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false

    OrtaCVSS 6,9İstismar yokEPSS %1

    apache · tika30 Tem 2026

  • CVE-2022-1742
    27İzleyin

    2.2.4 IMPROPER PROTECTION OF ALTERNATE PATH CWE-424

    OrtaCVSS 6,8İstismar yokEPSS %0

    dominionvoting · imagecast x24 Haz 2022

  • CVE-2026-4270
    27İzleyin

    AWS API MCP File Access Restriction Bypass

    OrtaCVSS 6,8İstismar yokEPSS %0

    amazon · aws api mcp server16 Mar 2026

  • CVE-2024-8311
    26İzleyin

    Improper Protection of Alternate Path in GitLab

    OrtaCVSS 6,5İstismar yokEPSS %1

    gitlab · gitlab12 Eyl 2024

  • CVE-2026-58428
    26İzleyin

    Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

    OrtaCVSS 6,5İstismar yokEPSS %0

    gitea · gitea open source git server13 Ağu 2026

  • CVE-2025-49163
    26İzleyin

    Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow booting an arbitrary image via a crafted /usr/bin/gunzip file.

    OrtaCVSS 6,7İstismar yokEPSS %0

    arris · vip11132 Haz 2025

  • CVE-2026-82754
    25İzleyin

    ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls

    OrtaCVSS 6,3İstismar yokEPSS %1

    ash-project · ash_authentication_oauth2_server7 Eyl 2026

Tüm zafiyet sınıfları