Threats Tagged 'cwe-420'
View all threats tagged with 'cwe-420'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-420'
Click on any threat for detailed analysis and mitigation recommendations
Kiteworks Core did not apply its gateway-level API security controls to every request authenticated through the platform's central authentication service. An authenticated user could reach REST API functionality over a request path on which those controls, including enforcement of signed-out and revoked sessions, were not applied. Join the discussion | CVE Database V5 | 09/30/2026, 20:12:39 UTC Added: 09/30/2026, 20:34:25 UTC |
An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contacts by including the target hrefs in a calendar-multiget or addressbook-multiget REPORT. Join the discussion | CVE Database V5 | 09/09/2026, 00:00:00 UTC Added: 09/10/2026, 11:04:41 UTC |
A vulnerability in Tor versions before 0.4.9.9 allows an attacker to bypass the compression bomb detection by concatenating multiple gzip or zlib sub-streams, each below the detection threshold. This flaw can lead to denial of service by causing resource exhaustion. The issue is tracked as CVE-2026-77639 and is classified under CWE-420 (Unprotected Alternate Channel). Join the discussion | CVE Database V5 | 08/20/2026, 22:00:00 UTC Added: 08/20/2026, 21:07:38 UTC |
When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow connections from blocked addresses. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Join the discussion | CVE Database V5 | 05/13/2026, 14:12:27 UTC Added: 05/13/2026, 15:21:44 UTC |
LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI. Join the discussion | CVE Database V5 | 04/10/2026, 13:43:23 UTC Added: 04/10/2026, 14:20:51 UTC |
CVE-2026-35388 is a low-severity vulnerability in OpenSSH versions before 10.3 where connection multiplexing confirmation is omitted for proxy-mode multiplexing sessions. This issue relates to CWE-420, an unprotected alternate channel, potentially allowing limited unauthorized interaction. The vulnerability does not impact confidentiality or availability but may cause limited integrity issues. There are no known exploits in the wild, and no official patch or vendor advisory is currently provided. Join the discussion | CVE Database V5 | 04/02/2026, 16:57:31 UTC Added: 04/02/2026, 17:08:18 UTC |
CVE-2026-25916 is a medium severity vulnerability in Roundcube Webmail versions before 1.5.13 and 1.6 before 1.6.13. When the 'Block remote images' feature is enabled, the application fails to block SVG feImage elements, allowing remote image content to be loaded. This unprotected alternate channel can be exploited to bypass privacy protections intended to prevent remote content loading, potentially leaking user information. The vulnerability does not impact integrity or availability and requires user interaction to trigger. No known exploits are currently reported in the wild. Join the discussion | CVE Database V5 | 02/09/2026, 08:14:10 UTC Added: 02/09/2026, 08:31:15 UTC |
0 A local low privileged attacker can bypass the authentication of the Device Manager user interface, allowing them to perform privileged operations and gain administrator access. Join the discussion | CVE Database V5 | 01/27/2026, 11:36:54 UTC Added: 01/27/2026, 11:50:56 UTC |
0 BullWall Ransomware Containment supports configurable file and directory exclusions such as '$RECYCLE.BIN' to balance monitoring scope and performance. Certain exclusion patterns could allow an authenticated attacker to rename directories in a way that avoids monitoring. Fixed in 4.6.1.14 and 5.0.0.42, which remove hardcoded exclusion behavior and exposes exclusion handling as configurable settings. Join the discussion | CVE Database V5 | 12/18/2025, 20:32:21 UTC Added: 12/18/2025, 20:41:29 UTC |
In Oxide control plane 15 through 17 before 17.1, API tokens can be renewed past their expiration date. Join the discussion | CVE Database V5 | 11/30/2025, 00:00:00 UTC Added: 11/30/2025, 04:45:14 UTC |
Showing 1 to 10 of 21 results