VYPR

CWE-420

Unprotected Alternate Channel

BaseDraft

Description

The product protects a primary channel, but it does not use the same level of protection for an alternate channel.

Hierarchy (View 1000)

CVEs mapped to this weakness (37)

page 2 of 2
  • CVE-2023-28840HigApr 4, 2023
    risk 0.42cvss 7.5epss 0.03

    Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as moby/moby, is commonly referred to as…

  • CVE-2020-8558MedJul 27, 2020
    risk 0.35cvss 5.4epss 0.04

    The Kubelet and kube-proxy components in versions 1.1.0-1.16.10, 1.17.0-1.17.6, and 1.18.0-1.18.3 were found to contain a security issue which allows adjacent hosts to reach TCP and UDP services bound to 127.0.0.1 running on the node or in the node's network namespace. Such a…

  • CVE-2026-40435MedMay 13, 2026
    risk 0.34cvss 5.3epss 0.00

    When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow connections from blocked addresses.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2025-66432MedNov 30, 2025
    risk 0.33cvss 5.0epss 0.00

    In Oxide control plane 15 through 17 before 17.1, API tokens can be renewed past their expiration date.

  • CVE-2023-0317MedApr 19, 2023
    risk 0.32cvss 4.9epss 0.01

    Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensitive information.

  • CVE-2022-25786MedMay 4, 2022
    risk 0.32cvss 4.9epss 0.01

    Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensitive information. This issue affects: GateManager all versions prior to 9.7.

  • CVE-2022-28693MedFeb 14, 2025
    risk 0.31cvss 4.7epss 0.00

    Unprotected alternative channel of return branch target prediction in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

  • CVE-2026-25916MedFeb 9, 2026
    risk 0.28cvss 4.3epss 0.01

    Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.

  • CVE-2024-4444MedMay 14, 2024
    risk 0.28cvss 5.3epss 0.01

    The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 4.2.6.5. This is due to missing checks in the 'create_account' function in the checkout. This makes it possible for unauthenticated…

  • CVE-2024-6099MedJul 2, 2024
    risk 0.27cvss 5.3epss 0.00

    The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthenticated bypass to user registration in versions up to, and including, 4.2.6.8.1. This is due to missing checks in the 'check_validate_fields' function in the checkout. This makes it possible…

  • CVE-2025-62820MedOct 23, 2025
    risk 0.25cvss 4.9epss 0.00

    Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within the Nebula network.

  • CVE-2023-30946LowJun 29, 2023
    risk 0.23cvss 3.5epss 0.00

    A security defect was identified in Foundry Issues. If a user was added to an issue on a resource that they did not have access to and consequently could not see, they could query Foundry's Notification API and receive metadata about the issue including the RID of the issue,…

  • CVE-2025-56558LowOct 29, 2025
    risk 0.20cvss 3.0epss 0.00

    The Dyson MQTT server (2022 and possibly later) allows publications and subscriptions by a client that has the correct values of AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, and device serial number, even if a device (such as a Pure Hot+Cool device) has been…

  • CVE-2025-52968LowJun 23, 2025
    risk 0.18cvss 2.7epss 0.00

    xdg-open in xdg-utils through 1.2.1 can send requests containing SameSite=Strict cookies, which can facilitate CSRF. (For example, xdg-open could be modified to, by default, associate x-scheme-handler/https with the execution of a browser with command-line options that arrange…

  • CVE-2026-35388LowApr 2, 2026
    risk 0.16cvss 2.5epss 0.00

    OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.

  • CVE-2025-67303HigJan 5, 2026
    risk 0.00cvss 7.5epss 0.01

    An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data. This was due to the application storing its files in an insufficiently protected location that was accessible via the web interface

  • CVE-2025-54351HigAug 3, 2025
    risk 0.00cvss 8.9epss 0.00

    In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).