The product protects a primary channel, but it does not use the same level of protection for an alternate channel.
Volume of CVEs assigned to CWE-420 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-20198CRITICAL Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and | Oct 16, 2023 | 10.0 | 99 | YES | YES |
CVE-2025-54309CRITICAL CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access | Jul 18, 2025 | 9.8 | 97 | YES | YES |
CVE-2025-13315CRITICAL Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file | Nov 19, 2025 | 9.8 | 74 | NO | YES |
CVE-2024-10081CRITICAL CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
Authentication bypass occurs when the API URL ends with Auth | Nov 6, 2024 | 10.0 | 61 | NO | YES |
CVE-2025-67303HIGH An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data. This was due to the application storing it | Jan 5, 2026 | 7.5 | 39 | NO | YES |
CVE-2026-40217HIGH LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI. | Apr 10, 2026 | 8.8 | 36 | NO | NO |
CVE-2025-54351CRITICAL In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv). | Aug 3, 2025 | 10.0 | 35 | NO | NO |
CVE-2025-53967HIGH Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a crafted HTTP POST request with shell metachar | Oct 8, 2025 | 8.0 | 34 | NO | NO |
CVE-2025-52921CRITICAL In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution on the server, by uploading a crafted fil | Jun 23, 2025 | 9.9 | 30 | NO | NO |
CVE-2023-31241CRITICAL Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright. | May 22, 2023 | 10.0 | 30 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.