CWE-440 · 46 records
Expected Behavior Violation
CVEs in this class
46 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2019-6569No exploit | The monitor barrier of the affected products insufficiently blocks data from being forwarded over the mirror port into the mirrored network.siemens · scalance x-200 firmware · CWE-440 | Critical9.1 | — | 1.3% | Mar 26, 2019 |
36Monitor | CVE-2024-32971No exploit | Defect in query plan cache may cause incorrect operations to be executed in Apollo Routerapollographql · router · CWE-440 | Critical9.0 | — | 0.7% | May 2, 2024 |
35Monitor | CVE-2025-8850No exploit | Insecure API Design in danny-avila/librechatlibrechat · librechat · CWE-440 | High8.8 | — | 0.4% | Oct 30, 2025 |
34Monitor | CVE-2026-8806No exploit | Denial-of-service (DoS) vulnerability in MELSEC iQ-F Series FX5-ENET/IP Ethernet modulemitsubishi electric corporation · mitsubishi electric melsec iq-f series fx5-enet/ip ethernet module fx5-enet/ip · CWE-440 | High8.7 | — | 0.6% | Jun 18, 2026 |
32Monitor | CVE-2018-12550No exploit | When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use an ACL file, and that ACL file is empty, or contains only commeeclipse · mosquitto · CWE-440 | High8.1 | — | 1.4% | Mar 27, 2019 |
32Monitor | GHSA-fqf6-gxhh-2xhwNo exploit | uutils coreutils: cp/install/mv/ln --suffix alone does not enable backup mode (silent data loss vs GNU)crates.io · uucore · CWE-440 | High8.0 | — | — | Jul 7, 2026 |
31Monitor | CVE-2023-4807No exploit | POLY1305 MAC implementation corrupts XMM registers on Windowsopenssl · openssl · CWE-440 | High7.8 | — | 0.8% | Sep 8, 2023 |
30Monitor | CVE-2022-3281No exploit | WAGO: multiple products - Loss of MAC-Address-Filtering after rebootwago · 750-8100 firmware · CWE-440 | High7.5 | — | 0.7% | Oct 17, 2022 |
30Monitor | CVE-2023-32731No exploit | Information leak in gRPCgrpc · grpc · CWE-440 | High7.5 | — | 0.5% | Jun 9, 2023 |
29Monitor | CVE-2019-5108No exploit | An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3.linux · linux kernel · CWE-440 | Medium6.5 | — | 10.1% | Dec 23, 2019 |
28Monitor | CVE-2024-30246No exploit | Tuleap deleting or moving an artifact can delete values from unrelated artifactsenalean · tuleap · CWE-440 | High7.1 | — | 0.6% | Mar 29, 2024 |
28Monitor | CVE-2025-52953No exploit | Junos OS and Junos OS Evolved: An unauthenticated adjacent attacker sending a valid BGP UPDATE packet forces a BGP session resetjuniper · junos · CWE-440 | High7.1 | — | 0.3% | Jul 11, 2025 |
28Monitor | CVE-2026-65934No exploit | BT122 plaintext pause encryption request causes DOSsilabs.com · bt122 · CWE-440 | High7.1 | — | 0.1% | Aug 13, 2026 |
28Monitor | CVE-2026-16769No exploit | RS9116W/SiWx917 plaintext pause encryption request causes DOSsilabs.com · wisecnnect · CWE-440 | High7.1 | — | 0.1% | Sep 8, 2026 |
27Monitor | CVE-2023-6129No exploit | POLY1305 MAC implementation corrupts vector registers on PowerPCopenssl · openssl · CWE-440 | Medium6.5 | — | 2.3% | Jan 9, 2024 |
27Monitor | CVE-2026-42534No exploit | Jostle logic bypass degrades resolution performancenlnetlabs · unbound · CWE-440 | Medium6.9 | — | 0.7% | May 20, 2026 |
27Monitor | CVE-2026-3344No exploit | WatchGuard Firebox System Integrity Check Bypasswatchguard · fireware · CWE-440 | Medium6.9 | — | 0.4% | Mar 3, 2026 |
26Monitor | CVE-2023-2088No exploit | A flaw was found in OpenStack due to an inconsistency between Cinder and Nova.redhat · openstack · CWE-440 | Medium6.5 | — | 1.2% | May 12, 2023 |
26Monitor | CVE-2019-5061No exploit | An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAPP location updates fw1.fi · hostapd · CWE-440 | Medium6.5 | — | 0.9% | Dec 12, 2019 |
26Monitor | CVE-2019-5062No exploit | An exploitable denial-of-service vulnerability exists in the 802.11w security state handling for hostapd 2.6 connected clients with valid 80w1.fi · hostapd · CWE-440 | Medium6.5 | — | 0.5% | Dec 12, 2019 |
26Monitor | CVE-2025-6211No exploit | MD5 Hash Collision in run-llama/llama_indexllamaindex · llamaindex · CWE-440 | Medium6.5 | — | 0.3% | Jul 10, 2025 |
26Monitor | CVE-2026-42752No exploit | WordPress Stripe Payments plugin <= 2.0.98 - Bypass Vulnerability vulnerabilitymra13 / team tips and tricks hq · stripe payments · CWE-440 | Medium6.5 | — | 0.3% | Jun 15, 2026 |
26Monitor | CVE-2025-13940No exploit | WatchGuard Firebox Boot Time System Integrity Check Bypasswatchguard · fireware · CWE-440 | Medium6.7 | — | 0.1% | Dec 4, 2025 |
25Monitor | CVE-2024-7246No exploit | HPACK table poisoning in gRPC C++, Python & Rubygrpc · grpc · CWE-440 | Medium6.3 | — | 0.2% | Aug 6, 2024 |
23Monitor | CVE-2024-47762No exploit | Unexpected visibility of environment variable configurations in @backstage/plugin-app-backendbackstage · backstage · CWE-440 | Medium5.8 | — | 0.4% | Oct 3, 2024 |
- CVE-2019-656936Monitor
The monitor barrier of the affected products insufficiently blocks data from being forwarded over the mirror port into the mirrored network.
CriticalCVSS 9.1No exploitEPSS 1%siemens · scalance x-200 firmwareMar 26, 2019
- CVE-2024-3297136Monitor
Defect in query plan cache may cause incorrect operations to be executed in Apollo Router
CriticalCVSS 9.0No exploitEPSS 1%apollographql · routerMay 2, 2024
- CVE-2025-885035Monitor
Insecure API Design in danny-avila/librechat
HighCVSS 8.8No exploitEPSS 0%librechat · librechatOct 30, 2025
- CVE-2026-880634Monitor
Denial-of-service (DoS) vulnerability in MELSEC iQ-F Series FX5-ENET/IP Ethernet module
HighCVSS 8.7No exploitEPSS 1%mitsubishi electric corporation · mitsubishi electric melsec iq-f series fx5-enet/ip ethernet module fx5-enet/ipJun 18, 2026
- CVE-2018-1255032Monitor
When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use an ACL file, and that ACL file is empty, or contains only comme
HighCVSS 8.1No exploitEPSS 1%eclipse · mosquittoMar 27, 2019
- GHSA-fqf6-gxhh-2xhw32Monitor
uutils coreutils: cp/install/mv/ln --suffix alone does not enable backup mode (silent data loss vs GNU)
HighCVSS 8.0No exploitcrates.io · uucoreJul 7, 2026
- CVE-2023-480731Monitor
POLY1305 MAC implementation corrupts XMM registers on Windows
HighCVSS 7.8No exploitEPSS 1%openssl · opensslSep 8, 2023
- CVE-2022-328130Monitor
WAGO: multiple products - Loss of MAC-Address-Filtering after reboot
HighCVSS 7.5No exploitEPSS 1%wago · 750-8100 firmwareOct 17, 2022
- CVE-2023-3273130Monitor
Information leak in gRPC
HighCVSS 7.5No exploitEPSS 0%grpc · grpcJun 9, 2023
- CVE-2019-510829Monitor
An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3.
MediumCVSS 6.5No exploitEPSS 10%linux · linux kernelDec 23, 2019
- CVE-2024-3024628Monitor
Tuleap deleting or moving an artifact can delete values from unrelated artifacts
HighCVSS 7.1No exploitEPSS 1%enalean · tuleapMar 29, 2024
- CVE-2025-5295328Monitor
Junos OS and Junos OS Evolved: An unauthenticated adjacent attacker sending a valid BGP UPDATE packet forces a BGP session reset
HighCVSS 7.1No exploitEPSS 0%juniper · junosJul 11, 2025
- CVE-2026-6593428Monitor
BT122 plaintext pause encryption request causes DOS
HighCVSS 7.1No exploitEPSS 0%silabs.com · bt122Aug 13, 2026
- CVE-2026-1676928Monitor
RS9116W/SiWx917 plaintext pause encryption request causes DOS
HighCVSS 7.1No exploitEPSS 0%silabs.com · wisecnnectSep 8, 2026
- CVE-2023-612927Monitor
POLY1305 MAC implementation corrupts vector registers on PowerPC
MediumCVSS 6.5No exploitEPSS 2%openssl · opensslJan 9, 2024
- CVE-2026-4253427Monitor
Jostle logic bypass degrades resolution performance
MediumCVSS 6.9No exploitEPSS 1%nlnetlabs · unboundMay 20, 2026
- CVE-2026-334427Monitor
WatchGuard Firebox System Integrity Check Bypass
MediumCVSS 6.9No exploitEPSS 0%watchguard · firewareMar 3, 2026
- CVE-2023-208826Monitor
A flaw was found in OpenStack due to an inconsistency between Cinder and Nova.
MediumCVSS 6.5No exploitEPSS 1%redhat · openstackMay 12, 2023
- CVE-2019-506126Monitor
An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAPP location updates f
MediumCVSS 6.5No exploitEPSS 1%w1.fi · hostapdDec 12, 2019
- CVE-2019-506226Monitor
An exploitable denial-of-service vulnerability exists in the 802.11w security state handling for hostapd 2.6 connected clients with valid 80
MediumCVSS 6.5No exploitEPSS 1%w1.fi · hostapdDec 12, 2019
- CVE-2025-621126Monitor
MD5 Hash Collision in run-llama/llama_index
MediumCVSS 6.5No exploitEPSS 0%llamaindex · llamaindexJul 10, 2025
- CVE-2026-4275226Monitor
WordPress Stripe Payments plugin <= 2.0.98 - Bypass Vulnerability vulnerability
MediumCVSS 6.5No exploitEPSS 0%mra13 / team tips and tricks hq · stripe paymentsJun 15, 2026
- CVE-2025-1394026Monitor
WatchGuard Firebox Boot Time System Integrity Check Bypass
MediumCVSS 6.7No exploitEPSS 0%watchguard · firewareDec 4, 2025
- CVE-2024-724625Monitor
HPACK table poisoning in gRPC C++, Python & Ruby
MediumCVSS 6.3No exploitEPSS 0%grpc · grpcAug 6, 2024
- CVE-2024-4776223Monitor
Unexpected visibility of environment variable configurations in @backstage/plugin-app-backend
MediumCVSS 5.8No exploitEPSS 0%backstage · backstageOct 3, 2024