CWE-420: Unprotected Alternate Channel
The product protects a primary channel, but it does not use the same level of protection for an alternate channel.
36 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-10081 — CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
- CVE-2025-13315 — Unauthenticated log access in Twonky Server
- CVE-2025-52921 — In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achi
- CVE-2025-54351 — In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).
- CVE-2025-8557 — An internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attack
- CVE-2025-62001 — BullWall Ransomware Containment hard-coded folder exclusions
- CVE-2025-1095 — IBM Personal Communications command execution
- CVE-2025-53967 — Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system
- CVE-2026-40217 — LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/t
- CVE-2025-41727 — Beckhoff: Performing privileged operations and gaining administrator access
- CVE-2025-59033 — The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries
- CVE-2026-40435 — BIG-IP httpd access control vulnerability
- CVE-2026-43505 — An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Be
- CVE-2025-66432 — In Oxide control plane 15 through 17 before 17.1, API tokens can be renewed past their expiration date.
- CVE-2025-62820 — Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within t
- CVE-2024-4444 — LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Bypass to User Registration
- CVE-2026-77639 — Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-stre
- CVE-2026-25916 — Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.
- CVE-2025-56558 — The Dyson MQTT server (2022 and possibly later) allows publications and subscriptions by a client that has the correct v
- CVE-2025-52968 — xdg-open in xdg-utils through 1.2.1 can send requests containing SameSite=Strict cookies, which can facilitate CSRF. (Fo
Recently published
- CVE-2026-77639 — Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-stre
- CVE-2026-40435 — BIG-IP httpd access control vulnerability
- CVE-2026-43505 — An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Be
- CVE-2026-40217 — LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/t
- CVE-2026-35388 — OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
- CVE-2026-25916 — Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.
- CVE-2025-41727 — Beckhoff: Performing privileged operations and gaining administrator access
- CVE-2025-62001 — BullWall Ransomware Containment hard-coded folder exclusions
- CVE-2025-66432 — In Oxide control plane 15 through 17 before 17.1, API tokens can be renewed past their expiration date.
- CVE-2025-13315 — Unauthenticated log access in Twonky Server
- CVE-2025-56558 — The Dyson MQTT server (2022 and possibly later) allows publications and subscriptions by a client that has the correct v
- CVE-2025-62820 — Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within t
- CVE-2025-53967 — Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system
- CVE-2025-8557 — An internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attack
- CVE-2025-59033 — The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries
- CVE-2025-54351 — In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).
- CVE-2025-52968 — xdg-open in xdg-utils through 1.2.1 can send requests containing SameSite=Strict cookies, which can facilitate CSRF. (Fo
- CVE-2025-52921 — In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achi
- CVE-2025-1095 — IBM Personal Communications command execution
- CVE-2024-10081 — CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.