Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-420

Unprotected Alternate Channel

The product protects a primary channel, but it does not use the same level of protection for an alternate channel.

37
Assigned CVEs
257th
Commonality Rank
7.1
Avg CVSS
5.4%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-420 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 27, 2020
5 years ago
Most Recent CVE
May 13, 2026
72 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

37 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-20198CRITICAL
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and
Oct 16, 202310.099YESYES
CVE-2025-54309CRITICAL
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access
Jul 18, 20259.897YESYES
CVE-2025-13315CRITICAL
Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file
Nov 19, 20259.874NOYES
CVE-2024-10081CRITICAL
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the API URL ends with Auth
Nov 6, 202410.061NOYES
CVE-2025-67303HIGH
An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data. This was due to the application storing it
Jan 5, 20267.539NOYES
CVE-2026-40217HIGH
LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.
Apr 10, 20268.836NONO
CVE-2025-54351CRITICAL
In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).
Aug 3, 202510.035NONO
CVE-2025-53967HIGH
Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a crafted HTTP POST request with shell metachar
Oct 8, 20258.034NONO
CVE-2025-52921CRITICAL
In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution on the server, by uploading a crafted fil
Jun 23, 20259.930NONO
CVE-2023-31241CRITICAL
Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.
May 22, 202310.030NONO
View all 37 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
16%
10%
4.0-4.9
11%
19%
5.0-5.9
8%
16%
6.0-6.9
14%
26%
7.0-7.9
24%
11%
8.0-8.9
19%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
2 CVEs
5.4% of CVEs· 98th percentile
Metasploit
2 CVEs
5.4% of CVEs· 97th percentile
Nuclei
5 CVEs
13.5% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products