Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-424

Improper Protection of Alternate Path

The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.

33
Assigned CVEs
274th
Commonality Rank
6.6
Avg CVSS
3.0%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-424 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 18, 2019
6 years ago
Most Recent CVE
Jul 10, 2026
15 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

33 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-58136CRITICAL
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 202
Apr 10, 20259.897YESYES
CVE-2025-48827CRITICAL
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by
May 27, 20259.887NOYES
CVE-2025-48828HIGH
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting template code in an alternative
May 27, 20258.179NOYES
CVE-2026-54423HIGH
In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI
Jul 10, 20268.237NONO
CVE-2026-0237HIGH
An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allow
May 13, 20267.829NONO
CVE-2023-5165HIGH
Docker Desktop before 4.23.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions via the debug shell which remains accessible for a short time win
Sep 25, 20238.828NONO
CVE-2023-52952HIGH
A vulnerability has been identified in HiMed Cockpit 12 pro (J31032-K2017-H259) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 14 pro+ (J31032-K2017-H435) (All versions >= V11.
Oct 8, 20248.527NONO
CVE-2026-0268MEDIUM
A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This does not impact Prisma Acc
Jun 10, 20264.425NONO
CVE-2023-20272HIGH
A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to upload malicious files to the web root of t
Nov 21, 20238.824NONO
CVE-2019-18996HIGH
Path settings in HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier accept DLLs outside of the program directory, potentially allowing an attacker wi
Dec 18, 20197.824NONO
View all 33 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
18%
10%
4.0-4.9
18%
19%
5.0-5.9
15%
16%
6.0-6.9
21%
26%
7.0-7.9
18%
11%
8.0-8.9
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
1 CVE
3.0% of CVEs· 97th percentile
Metasploit
2 CVEs
6.1% of CVEs· 98th percentile
Nuclei
3 CVEs
9.1% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products