CWE-41: CWE-41

11
Total CVEs
0
Critical
4
High
5.7
Avg CVSS

Yearly Trend

2025
10
2024
1

Top Affected Vendors

1 Microsoft 7
2 Fortinet 1
3 Apple 1
4 Lunary 1
5 Flask Cors Project 1

All CWE-41 CVEs (11)

CVE-2025-24470
8.6

CVE-2025-24470 is an Improper Resolution of Path Equivalence vulnerability in FortiPortal that allows remote unauthenticated attackers to retrieve sou...

Feb 11, 2025
CVE-2025-43298
7.8

A path parsing vulnerability in macOS allows malicious applications to bypass directory validation and gain root privileges. This affects macOS system...

Sep 15, 2025
CVE-2024-30073
7.8

This vulnerability allows attackers to bypass Windows Security Zone mapping protections, potentially tricking users into executing malicious content f...

Sep 10, 2024
CVE-2024-8765
7.3

This vulnerability allows unauthenticated attackers to bypass authentication in lunary-ai/lunary by including '/auth/' in API endpoint paths. Attacker...

Mar 20, 2025
CVE-2024-6839
5.3

CVE-2024-6839 is an improper regex path matching vulnerability in flask-cors 4.0.1 that causes longer regex patterns to be prioritized over more speci...

Mar 20, 2025
CVE-2025-54107
4.3

This vulnerability allows attackers to bypass Windows security zone restrictions by exploiting improper path equivalence resolution in the MapUrlToZon...

Sep 9, 2025
CVE-2025-21332
4.3

This CVE describes a security feature bypass vulnerability in the MapUrlToZone function, which is used by Windows to determine the security zone of UR...

Jan 14, 2025
CVE-2025-21329
4.3

This vulnerability allows attackers to bypass security zone restrictions in Windows when processing certain URLs, potentially enabling them to execute...

Jan 14, 2025
CVE-2025-21268
4.3

This vulnerability allows attackers to bypass the MapUrlToZone security feature in Microsoft Windows, potentially tricking the system into treating ma...

Jan 14, 2025
CVE-2025-21219
4.3

This vulnerability allows attackers to bypass security zone restrictions in Windows when processing certain URLs. It affects Windows systems that use ...

Jan 14, 2025
CVE-2025-21189
4.3

This vulnerability allows attackers to bypass Internet Explorer's security zone restrictions, potentially tricking users into running malicious conten...

Jan 14, 2025

About CWE-41 (CWE-41)

Our database tracks 11 CVEs classified as CWE-41, with 0 rated critical and 4 rated high severity. The average CVSS score for CWE-41 vulnerabilities is 5.7.

External reference: View CWE-41 on MITRE CWE →

Monitor CWE-41 Vulnerabilities

Get alerted when new CWE-41 CVEs affect your infrastructure.

Start Monitoring Free