CWE-420— Unprotected Alternate Channel
The product protects a primary channel, but it does not use the same level of protection for an alternate channel.— MITRE CWE catalog
40 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-420page 1 of 1
- CVE-2023-20198CRITICALCVSS 10.0EG 10.0⚠ KEV2023-10-16
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determi…
- CVE-2025-54309CRITICALCVSS 9.0EG 9.0⚠ KEV2025-07-18
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025.
- CVE-2024-10081CRITICALCVSS 10.0EG 10.02024-11-06
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the API URL ends with Authentication. This bypass allows superuser access to all API …
- CVE-2025-52921CRITICALCVSS 9.9EG 9.92025-06-23
In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution on the server, by uploading a crafted file and then renaming it to have a .php extension by using th…
- CVE-2025-13315CRITICALCVSS 9.8EG 9.82025-11-19
Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted passwor…
- CVE-2025-59033CRITICALCVSS 7.4EG 9.82025-09-08
The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only the to-be-signed (TBS) part of the code signer certificate are properly blocked, but entries that sp…
- CVE-2025-54351HIGHCVSS 8.9EG 8.92025-08-03
In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).
- CVE-2026-40217HIGHCVSS 8.8EG 8.82026-04-10
LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.
- CVE-2025-62001HIGHCVSS 8.8EG 8.82025-12-18
BullWall Ransomware Containment supports configurable file and directory exclusions such as '$RECYCLE.BIN' to balance monitoring scope and performance. Certain exclusion patterns could allow an authenticated attacker to rename directories …
- CVE-2025-8557HIGHCVSS 8.8EG 8.82025-09-11
An internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attacker with access to a device on the local Lenovo XClarity Orchestrator (LXCO) network segment may be able to manipulate t…
- CVE-2025-1095HIGHCVSS 8.8EG 8.82025-04-08
IBM Personal Communications v14 and v15 include a Windows service that is vulnerable to local privilege escalation (LPE). The vulnerability allows any interactively logged in users on the target computer to run commands with full privilege…
- CVE-2023-4570HIGHCVSS 8.8EG 8.82023-10-05
An improper access restriction in NI MeasurementLink Python services could allow an attacker on an adjacent network to reach services exposed on localhost. These services were previously thought to be unreachable outside of the node. Thi…
- CVE-2023-31241HIGHCVSS 8.6EG 8.62023-05-22
Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.
- CVE-2025-53967HIGHCVSS 8.0EG 8.02025-10-08
Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a crafted HTTP POST request with shell metacharacters in input that is used by a fetchWithRetry curl comma…
- CVE-2024-8038HIGHCVSS 7.9EG 7.92024-10-02
Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available without authentication locally to network namespace users. This enables denial of service attacks.
- CVE-2025-41727HIGHCVSS 7.8EG 7.82026-01-27
A local low privileged attacker can bypass the authentication of the Device Manager user interface, allowing them to perform privileged operations and gain administrator access.
- CVE-2025-67303HIGHCVSS 7.5EG 7.52026-01-05
An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data. This was due to the application storing its files in an insufficiently protected location that was ac…
- CVE-2023-7266HIGHCVSS 7.5EG 7.52024-12-28
Some Huawei home routers have a connection hijacking vulnerability. Successful exploitation of this vulnerability may cause DoS or information leakage.(Vulnerability ID:HWPSIRT-2023-76605) This vulnerability has been assigned a (CVE)ID:CVE…
- CVE-2023-28840HIGHCVSS 7.5EG 7.52023-04-04
Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as mob…
- CVE-2025-56558HIGHCVSS 3.0EG 7.52025-10-29
The Dyson MQTT server (2022 and possibly later) allows publications and subscriptions by a client that has the correct values of AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, and device serial number, even if a device (such …
- CVE-2024-6242HIGHCVSS 7.3EG 7.32024-08-01
A vulnerability exists in Rockwell Automation affected products that allows a threat actor to bypass the Trusted® Slot feature in a ControlLogix® controller. If exploited on any affected module in a 1756 chassis, a threat actor could pot…
- CVE-2023-28842MEDIUMCVSS 6.8EG 6.82023-04-04
Moby) is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as mo…
- CVE-2026-43505MEDIUMCVSS 6.5EG 6.52026-05-01
An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles access control in the activation scenario, relaying of unauthenticated traffic can occur.
- CVE-2023-52718MEDIUMCVSS 6.4EG 6.42024-12-28
A connection hijacking vulnerability exists in some Huawei home routers. Successful exploitation of this vulnerability may cause DoS or information leakage.(Vulnerability ID:HWPSIRT-2023-34408) This vulnerability has been assigned a (CVE)…
- CVE-2026-102134MEDIUMCVSS 5.4EG 5.42026-09-30
Kiteworks Core did not apply its gateway-level API security controls to every request authenticated through the platform's central authentication service. An authenticated user could reach REST API functionality over a request path on whic…
- CVE-2020-8558MEDIUMCVSS 5.4EG 5.42020-07-27
The Kubelet and kube-proxy components in versions 1.1.0-1.16.10, 1.17.0-1.17.6, and 1.18.0-1.18.3 were found to contain a security issue which allows adjacent hosts to reach TCP and UDP services bound to 127.0.0.1 running on the node or in…
- CVE-2026-77639MEDIUMCVSS 5.3EG 5.32026-08-20
Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2…
- CVE-2026-40435MEDIUMCVSS 5.3EG 5.32026-05-13
When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow connections from blocked addresses. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- CVE-2024-6099MEDIUMCVSS 5.3EG 5.32024-07-02
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthenticated bypass to user registration in versions up to, and including, 4.2.6.8.1. This is due to missing checks in the 'check_validate_fields' function in…
- CVE-2024-4444MEDIUMCVSS 5.3EG 5.32024-05-14
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 4.2.6.5. This is due to missing checks in the 'create_account' function in the checkout. This makes…
- CVE-2025-66432MEDIUMCVSS 5.0EG 5.02025-11-30
In Oxide control plane 15 through 17 before 17.1, API tokens can be renewed past their expiration date.
- CVE-2025-62820MEDIUMCVSS 4.9EG 4.92025-10-23
Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within the Nebula network.
- CVE-2023-0317MEDIUMCVSS 4.9EG 4.92023-04-19
Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensitive information.
- CVE-2022-25786MEDIUMCVSS 4.9EG 4.92022-05-04
Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensitive information. This issue affects: GateManager all versions prior to 9.7.
- CVE-2022-28693MEDIUMCVSS 4.7EG 4.72025-02-14
Unprotected alternative channel of return branch target prediction in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
- CVE-2026-61909MEDIUMCVSS 4.3EG 4.32026-09-09
An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contacts …
- CVE-2026-25916MEDIUMCVSS 4.3EG 4.32026-02-09
Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.
- CVE-2023-30946LOWCVSS 3.5EG 3.52023-06-29
A security defect was identified in Foundry Issues. If a user was added to an issue on a resource that they did not have access to and consequently could not see, they could query Foundry's Notification API and receive metadata about the i…
- CVE-2025-52968LOWCVSS 2.7EG 2.72025-06-23
xdg-open in xdg-utils through 1.2.1 can send requests containing SameSite=Strict cookies, which can facilitate CSRF. (For example, xdg-open could be modified to, by default, associate x-scheme-handler/https with the execution of a browser …
- CVE-2026-35388LOWCVSS 2.5EG 2.52026-04-02
OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
Map vulnerabilities like CWE-420 to your infrastructure
EchelonGraph correlates every CVE — across CWE-420 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →