Skip to main content

CWE archive

CWE-424 CVEs

Programmatic archive

33 CVEs tagged with CWE-4244 Critical, 10 High, 18 Medium, 1 Low, 0 Unrated.

CVE-2026-54423

Published Jul 10, 2026

In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI…

CVSS 8.2 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-0237

Published May 13, 2026

An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allo…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-4913

Published Apr 14, 2026

Improper protection of an alternate path in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker to retain access when their account has been disabled.

CVSS 5.7 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-4270

Published Mar 16, 2026

Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >= 0.2.14 and < 1.3.9 on all platforms may allow the bypass of…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-68939

Published Dec 26, 2025

Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-4617

Published Nov 14, 2025

An insufficient policy enforcement vulnerability in Palo Alto Networks Prisma® Browser on Windows allows a locally authenticated non-admin user to bypass the screenshot control fe…

CVSS 1.1 · Low

CVE-2025-58079

Published Oct 16, 2025

Improper Protection of Alternate Path (CWE-424) in the AppSuite of desknet's NEO V4.0R1.0 to V9.0R2.0 allows an attacker to create malicious AppSuite applications.

CVSS 5.3 · Medium

CVE-2025-49163

Published Jun 3, 2025

Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow booting an arbitrary image via a crafted /usr/bin/gunzip file.

CVSS 6.7 · Medium

CVE-2025-49162

Published Jun 3, 2025

Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow file overwrite via TFTP because a remote filename with a space character allows an attacker to control the local fil…

CVSS 6.4 · Medium

CVE-2025-48828

Published May 27, 2025

Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting template code in an alternative…

CVSS 9.0 · Critical
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2025-48827

Published May 27, 2025

vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated b…

CVSS 10.0 · Critical
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2025-46655

Published Apr 26, 2025

CodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScript, but it can be bypassed in certain cases of different-or…

CVSS 4.9 · Medium

CVE-2025-46654

Published Apr 26, 2025

CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that references an uplo…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-58136

Published Apr 10, 2025

Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 20…

CVSS 9.0 · Critical
evidence mentions
6
Buzz score
56.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-0113

Published Feb 12, 2025

A problem with the network isolation mechanism of the Palo Alto Networks Cortex XDR Broker VM allows attackers unauthorized access to Docker containers from the host network used…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-8781

Published Nov 18, 2024

Execution with Unnecessary Privileges, : Improper Protection of Alternate Path vulnerability in TR7 Application Security Platform (ASP) allows Privilege Escalation, -Privilege Abu…

CVSS 8.7 · High

CVE-2023-52952

Published Oct 8, 2024

A vulnerability has been identified in HiMed Cockpit 12 pro (J31032-K2017-H259) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 14 pro+ (J31032-K2017-H435) (All versions >= V11…

CVSS 9.3 · Critical

CVE-2024-8311

Published Sep 12, 2024

An issue was discovered with pipeline execution policies in GitLab EE affecting all versions from 17.2 prior to 17.2.5, 17.3 prior to 17.3.2 which allows authenticated users to by…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3927

Published May 22, 2024

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Form Submission Admin Email Bypas…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3460

Published May 14, 2024

In KioWare for Windows (versions all through 8.34) it is possible to exit this software and use other already opened applications utilizing a short time window before the forced a…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3459

Published May 14, 2024

KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened in an external PDF viewer. By using bui…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-20272

Published Nov 21, 2023

A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to upload malicious files to the web root of…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46176

Published Nov 3, 2023

IBM MQ Appliance 9.3 CD could allow a local attacker to gain elevated privileges on the system, caused by improper validation of security keys. IBM X-Force ID: 269535.

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 33 CVEsPage 1 of 2