VulnSea

CWE-420

CVEs classified under CWE-420, newest first.

6 CVEsRSS

CVE-2026-61909Low· 3.5
1w ago

An issue was discovered in Cyrus IMAP before 3.12.4

An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contact…

Sunlitcyrus · imapEPSS 0.20%via NVD
CVE-2026-77639Medium· 5.3
1mo ago

Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely

Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-…

Sunlittorproject · torEPSS 0.23%via NVD
CVE-2025-67303High· 7.5PoC
3mo ago

ComfyUI-Manager has an Unprotected Alternate Channel (CWE-420)

ComfyUI-Manager has an Unprotected Alternate Channel (CWE-420)

Midnightcomfyui-manager · comfyui-managerEPSS 1.4%via GHSA
CVE-2026-40435Medium· 5.3
4mo ago

When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow connections from blocked addresses.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow connections from blocked addresses.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

SunlitEPSS 0.23%via NVD
CVE-2023-28840High· 7.5
3y ago

Moby is an open source container framework developed by Docker Inc

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as m…

Twilightmobyproject · mobyEPSS 2.6%via NVD
CVE-2023-28842Medium· 6.8
3y ago

moby: Encrypted overlay network with a single endpoint is unauthenticated (CVE-2023-28842)

A vulnerability was found in Moby due to an unprotected alternate channel within encrypted overlay networks, which could allow a remote attacker to bypass security restrictions. By sending a specially crafted request, an attacker could inj…

SunlitRed Hat · multicluster engine for Kubernetes 2.4 for RHEL 8EPSS 1.4%via CSAF
CWE-420 vulnerabilities (CVEs) · VulnSea