The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.
Volume of CVEs assigned to CWE-424 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-58136CRITICAL Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 202 | Apr 10, 2025 | 9.8 | 97 | YES | YES |
CVE-2025-48827CRITICAL vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by | May 27, 2025 | 9.8 | 87 | NO | YES |
CVE-2025-48828HIGH Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting template code in an alternative | May 27, 2025 | 8.1 | 79 | NO | YES |
CVE-2026-54423HIGH In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI | Jul 10, 2026 | 8.2 | 37 | NO | NO |
CVE-2026-0237HIGH An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allow | May 13, 2026 | 7.8 | 29 | NO | NO |
CVE-2023-5165HIGH Docker Desktop before 4.23.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions via the debug shell which remains accessible for a short time win | Sep 25, 2023 | 8.8 | 28 | NO | NO |
CVE-2023-52952HIGH A vulnerability has been identified in HiMed Cockpit 12 pro (J31032-K2017-H259) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 14 pro+ (J31032-K2017-H435) (All versions >= V11. | Oct 8, 2024 | 8.5 | 27 | NO | NO |
CVE-2026-0268MEDIUM A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel.
This does not impact Prisma Acc | Jun 10, 2026 | 4.4 | 25 | NO | NO |
CVE-2023-20272HIGH A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to upload malicious files to the web root of t | Nov 21, 2023 | 8.8 | 24 | NO | NO |
CVE-2019-18996HIGH Path settings in HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier accept DLLs outside of the program directory, potentially allowing an attacker wi | Dec 18, 2019 | 7.8 | 24 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.