CWE-393 · 7 records
Return of Wrong Status Code
CVEs in this class
7 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2024-49117Proof of concept | Windows Hyper-V Remote Code Execution Vulnerabilitymicrosoft · windows 11 22h2 · CWE-393 | High8.8 | — | 1.0% | Dec 11, 2024 |
33Monitor | CVE-2026-55958No exploit | Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessagewolfssl · wolfssl · CWE-393 | High8.3 | — | 0.4% | Jun 25, 2026 |
32Monitor | CVE-2025-5987No exploit | Libssh: invalid return code for chacha20 poly1305 with openssl backendlibssh · libssh · CWE-393 | High8.1 | — | 1.6% | Jul 7, 2025 |
31Monitor | CVE-2026-53092No exploit | bpf: Fix linked reg delta tracking when src_reg == dst_reglinux · linux kernel · CWE-393 | High7.8 | — | 0.1% | Jun 24, 2026 |
30Monitor | CVE-2025-32414No exploit | In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an ixmlsoft · libxml2 · CWE-393 | High7.5 | — | 0.4% | Apr 7, 2025 |
26Monitor | CVE-2025-24531No exploit | In OpenSC pam_pkcs11 before 0.6.13, pam_sm_authenticate() wrongly returns PAM_IGNORE in many error situations (such as an error triggered byopensc project · pam_pkcs11 · CWE-393 | Medium6.7 | — | 0.2% | Jan 16, 2026 |
21Monitor | CVE-2020-5401No exploit | Cloud Foundry GoRouter is vulnerable to cache poisoningcloudfoundry · routing release · CWE-393 | Medium5.3 | — | 1.0% | Feb 27, 2020 |
- CVE-2024-4911735Monitor
Windows Hyper-V Remote Code Execution Vulnerability
HighCVSS 8.8Proof of conceptEPSS 1%microsoft · windows 11 22h2Dec 11, 2024
- CVE-2026-5595833Monitor
Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessage
HighCVSS 8.3No exploitEPSS 0%wolfssl · wolfsslJun 25, 2026
- CVE-2025-598732Monitor
Libssh: invalid return code for chacha20 poly1305 with openssl backend
HighCVSS 8.1No exploitEPSS 2%libssh · libsshJul 7, 2025
- CVE-2026-5309231Monitor
bpf: Fix linked reg delta tracking when src_reg == dst_reg
HighCVSS 7.8No exploitEPSS 0%linux · linux kernelJun 24, 2026
- CVE-2025-3241430Monitor
In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an i
HighCVSS 7.5No exploitEPSS 0%xmlsoft · libxml2Apr 7, 2025
- CVE-2025-2453126Monitor
In OpenSC pam_pkcs11 before 0.6.13, pam_sm_authenticate() wrongly returns PAM_IGNORE in many error situations (such as an error triggered by
MediumCVSS 6.7No exploitEPSS 0%opensc project · pam_pkcs11Jan 16, 2026
- CVE-2020-540121Monitor
Cloud Foundry GoRouter is vulnerable to cache poisoning
MediumCVSS 5.3No exploitEPSS 1%cloudfoundry · routing releaseFeb 27, 2020