CWE-420
CVEs classified under CWE-420, newest first.
6 CVEsRSS
CVE-2026-61909Low· 3.5An issue was discovered in Cyrus IMAP before 3.12.4
An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contact…
CVE-2026-77639Medium· 5.3Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely
Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-…
CVE-2025-67303High· 7.5PoCComfyUI-Manager has an Unprotected Alternate Channel (CWE-420)
ComfyUI-Manager has an Unprotected Alternate Channel (CWE-420)
CVE-2026-40435Medium· 5.3When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow connections from blocked addresses. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow connections from blocked addresses. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2023-28840High· 7.5Moby is an open source container framework developed by Docker Inc
Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as m…
CVE-2023-28842Medium· 6.8moby: Encrypted overlay network with a single endpoint is unauthenticated (CVE-2023-28842)
A vulnerability was found in Moby due to an unprotected alternate channel within encrypted overlay networks, which could allow a remote attacker to bypass security restrictions. By sending a specially crafted request, an attacker could inj…