LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/t
A local low privileged attacker can bypass the authentication of the Device Manager user interface, allowing them to per
An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration a
An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Be
When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow connections from blo
Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-stre
Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.
OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
Frequently Asked Questions
What is CWE-420?
CWE-420 (CWE-420) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-420?
There are 8 CVE records associated with CWE-420 in our database. Of these, 0 are critical severity, 3 are high severity, and 4 are medium severity.
How can I protect against CWE-420 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-420 using AI-powered security agents.
Detect CWE-420 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-420 vulnerabilities across your infrastructure.
Get Started