Skip to main content

Threats Tagged 'cwe-420'

View all threats tagged with 'cwe-420'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-420

Threats Tagged 'cwe-420'

Click on any threat for detailed analysis and mitigation recommendations

Kiteworks Core did not apply its gateway-level API security controls to every request authenticated through the platform's central authentication service. An authenticated user could reach REST API functionality over a request path on which those controls, including enforcement of signed-out and revoked sessions, were not applied.

Join the discussion

An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contacts by including the target hrefs in a calendar-multiget or addressbook-multiget REPORT.

Join the discussion

A vulnerability in Tor versions before 0.4.9.9 allows an attacker to bypass the compression bomb detection by concatenating multiple gzip or zlib sub-streams, each below the detection threshold. This flaw can lead to denial of service by causing resource exhaustion. The issue is tracked as CVE-2026-77639 and is classified under CWE-420 (Unprotected Alternate Channel).

Join the discussion

When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow connections from blocked addresses.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Join the discussion

LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.

Join the discussion

CVE-2026-35388 is a low-severity vulnerability in OpenSSH versions before 10.3 where connection multiplexing confirmation is omitted for proxy-mode multiplexing sessions. This issue relates to CWE-420, an unprotected alternate channel, potentially allowing limited unauthorized interaction. The vulnerability does not impact confidentiality or availability but may cause limited integrity issues. There are no known exploits in the wild, and no official patch or vendor advisory is currently provided.

Join the discussion

CVE-2026-25916 is a medium severity vulnerability in Roundcube Webmail versions before 1.5.13 and 1.6 before 1.6.13. When the 'Block remote images' feature is enabled, the application fails to block SVG feImage elements, allowing remote image content to be loaded. This unprotected alternate channel can be exploited to bypass privacy protections intended to prevent remote content loading, potentially leaking user information. The vulnerability does not impact integrity or availability and requires user interaction to trigger. No known exploits are currently reported in the wild.

Join the discussion

A local low privileged attacker can bypass the authentication of the Device Manager user interface, allowing them to perform privileged operations and gain administrator access.

Join the discussion

BullWall Ransomware Containment supports configurable file and directory exclusions such as '$RECYCLE.BIN' to balance monitoring scope and performance. Certain exclusion patterns could allow an authenticated attacker to rename directories in a way that avoids monitoring. Fixed in 4.6.1.14 and 5.0.0.42, which remove hardcoded exclusion behavior and exposes exclusion handling as configurable settings.

Join the discussion

In Oxide control plane 15 through 17 before 17.1, API tokens can be renewed past their expiration date.

Join the discussion

Showing 1 to 10 of 21 results

Filters:Tag: cwe-420
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses