CWE-670 · 142 kayıt
Always-Incorrect Control Flow Implementation
Bu sınıftaki CVE’ler
142 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
62Bu hafta | CVE-2024-32896Silahlaştırılmış | there is a possible way to bypass due to a logic error in the code.google · android · CWE-670 | Yüksek7,8 | KEV | %3,0 | 13 Haz 2024 |
40Planlayın | CVE-2019-17192İstismar yok | The WebRTC component in the Signal Private Messenger application through 4.47.7 for Android processes videoconferencing RTP packets before asignal · private messenger · CWE-670 | Kritik9,8 | — | %2,7 | 4 Eki 2019 |
40Planlayın | CVE-2020-1914İstismar yok | A logic vulnerability when handling the SaveGeneratorLong instruction in Facebook Hermes prior to commit b2021df620824627f5a8c96615edbd1eb7ffacebook · hermes · CWE-670 | Kritik9,8 | — | %2,5 | 8 Eki 2020 |
39İzleyin | CVE-2020-17466İstismar yok | Turcom TRCwifiZone through 2020-08-10 allows authentication bypass by visiting manage/control.php and ignoring 302 Redirect responses.turcom · trcwifizone · CWE-670 | Kritik9,8 | — | %1,5 | 11 Ağu 2020 |
39İzleyin | CVE-2022-21679İstismar yok | Authorization Policy bypass in Istioistio · istio · CWE-670 | Kritik9,8 | — | %1,1 | 19 Oca 2022 |
39İzleyin | CVE-2021-41153İstismar yok | Specification non-compliance in JUMPIevm project · evm · CWE-670 | Kritik9,8 | — | %1,0 | 18 Eki 2021 |
39İzleyin | CVE-2025-43359İstismar yok | A logic issue was addressed with improved state management.apple · ipados · CWE-670 | Kritik9,8 | — | %0,9 | 15 Eyl 2025 |
39İzleyin | CVE-2023-23623İstismar yok | Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled in Electronelectronjs · electron · CWE-670 | Kritik9,8 | — | %0,7 | 6 Eyl 2023 |
39İzleyin | CVE-2022-2993İstismar yok | bt: host: Wrong key validation checkzephyrproject · zephyr · CWE-670 | Kritik9,8 | — | %0,6 | 9 Ara 2022 |
39İzleyin | CVE-2022-25745İstismar yok | Always Incorrect Control Flow Implementation in MODEMqualcomm · mdm9205 firmware · CWE-670 | Kritik9,8 | — | %0,4 | 13 Nis 2023 |
38İzleyin | GHSA-54gx-3cgr-7mfmİstismar yok | Cosmos EVM: incorrect state handling during nested EVM execution pathsGo · github.com/cosmos/evm · CWE-670 | Kritik9,5 | — | — | 11 Mar 2026 |
36İzleyin | CVE-2020-9425Kavram kanıtı | An issue was discovered in includes/head.inc.php in rConfig before 3.9.4.rconfig · rconfig · CWE-670 | Yüksek7,5 | — | %19,0 | 20 Mar 2020 |
36İzleyin | CVE-2026-55276İstismar yok | Apache Tomcat: Logged effective web.xml is incompleteapache · tomcat · CWE-670 | Kritik9,1 | — | %0,6 | 29 Haz 2026 |
36İzleyin | CVE-2025-29312İstismar yok | An issue in onos v2.7.0 allows attackers to trigger unexpected behavior within a device connected to a legacy switch via changing the link topennetworking · onos · CWE-670 | Kritik9,1 | — | %0,5 | 24 Mar 2025 |
36İzleyin | CVE-2026-16392İstismar yok | JIT miscompilation in the JavaScript Engine: JIT componentmozilla · firefox · CWE-670 | Kritik9,1 | — | %0,4 | 21 Tem 2026 |
35İzleyin | CVE-2018-16766İstismar yok | In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or posswebassembly virtual machine project · webassembly virtual machine · CWE-670 | Yüksek8,8 | — | %1,3 | 10 Eyl 2018 |
35İzleyin | CVE-2023-20558İstismar yok | Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to amd · ryzen 7 5700g firmware · CWE-670 | Yüksek8,8 | — | %0,7 | 2 Nis 2023 |
34İzleyin | CVE-2026-33011İstismar yok | Nest Fastify HEAD Request Middleware Bypassnestjs · nest · CWE-670 | Yüksek8,7 | — | %0,5 | 20 Mar 2026 |
34İzleyin | CVE-2026-1874İstismar yok | Denial-of-Service (DoS) vulnerability in Ethernet function of MELSEC iQ-F Series EtherNet/IP module and Ethernet modulemitsubishielectric · melsec iq-f fx5-eip firmware · CWE-670 | Yüksek8,7 | — | %0,4 | 3 Mar 2026 |
33İzleyin | CVE-2024-5659İstismar yok | Rockwell Automation Multicast Request Causes major nonrecoverable fault on Select Controllersrockwellautomation · controllogix 5580 firmware · CWE-670 | Yüksek8,3 | — | %0,3 | 14 Haz 2024 |
32İzleyin | CVE-2023-1668İstismar yok | A flaw was found in openvswitch (OVS).cloudbase · open vswitch · CWE-670 | Yüksek8,2 | — | %1,2 | 10 Nis 2023 |
32İzleyin | CVE-2024-38365İstismar yok | btcd did not correctly re-implement Bitcoin Core's "FindAndDelete()" functionalitybtcd project · btcd · CWE-670 | Yüksek8,1 | — | %1,0 | 11 Eki 2024 |
32İzleyin | CVE-2024-52811İstismar yok | Acks not validated before logged to qlog leads to buffer overflow in ngtcp2ngtcp2 · ngtcp2 · CWE-670 | Yüksek8,2 | — | %0,8 | 25 Kas 2024 |
32İzleyin | CVE-2025-49091Kavram kanıtı | KDE Konsole before 25.04.2 allows remote code execution in a certain scenario.kde · konsole · CWE-670 | Yüksek8,2 | — | %0,7 | 10 Haz 2025 |
32İzleyin | CVE-2023-0400Kavram kanıtı | The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0.trellix · data loss prevention · CWE-670 | Yüksek8,2 | — | %0,4 | 2 Şub 2023 |
- CVE-2024-3289662Bu hafta
there is a possible way to bypass due to a logic error in the code.
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %3google · android13 Haz 2024
- CVE-2019-1719240Planlayın
The WebRTC component in the Signal Private Messenger application through 4.47.7 for Android processes videoconferencing RTP packets before a
KritikCVSS 9,8İstismar yokEPSS %3signal · private messenger4 Eki 2019
- CVE-2020-191440Planlayın
A logic vulnerability when handling the SaveGeneratorLong instruction in Facebook Hermes prior to commit b2021df620824627f5a8c96615edbd1eb7f
KritikCVSS 9,8İstismar yokEPSS %3facebook · hermes8 Eki 2020
- CVE-2020-1746639İzleyin
Turcom TRCwifiZone through 2020-08-10 allows authentication bypass by visiting manage/control.php and ignoring 302 Redirect responses.
KritikCVSS 9,8İstismar yokEPSS %1turcom · trcwifizone11 Ağu 2020
- CVE-2022-2167939İzleyin
Authorization Policy bypass in Istio
KritikCVSS 9,8İstismar yokEPSS %1istio · istio19 Oca 2022
- CVE-2021-4115339İzleyin
Specification non-compliance in JUMPI
KritikCVSS 9,8İstismar yokEPSS %1evm project · evm18 Eki 2021
- CVE-2025-4335939İzleyin
A logic issue was addressed with improved state management.
KritikCVSS 9,8İstismar yokEPSS %1apple · ipados15 Eyl 2025
- CVE-2023-2362339İzleyin
Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled in Electron
KritikCVSS 9,8İstismar yokEPSS %1electronjs · electron6 Eyl 2023
- CVE-2022-299339İzleyin
bt: host: Wrong key validation check
KritikCVSS 9,8İstismar yokEPSS %1zephyrproject · zephyr9 Ara 2022
- CVE-2022-2574539İzleyin
Always Incorrect Control Flow Implementation in MODEM
KritikCVSS 9,8İstismar yokEPSS %0qualcomm · mdm9205 firmware13 Nis 2023
- GHSA-54gx-3cgr-7mfm38İzleyin
Cosmos EVM: incorrect state handling during nested EVM execution paths
KritikCVSS 9,5İstismar yokGo · github.com/cosmos/evm11 Mar 2026
- CVE-2020-942536İzleyin
An issue was discovered in includes/head.inc.php in rConfig before 3.9.4.
YüksekCVSS 7,5Kavram kanıtıEPSS %19rconfig · rconfig20 Mar 2020
- CVE-2026-5527636İzleyin
Apache Tomcat: Logged effective web.xml is incomplete
KritikCVSS 9,1İstismar yokEPSS %1apache · tomcat29 Haz 2026
- CVE-2025-2931236İzleyin
An issue in onos v2.7.0 allows attackers to trigger unexpected behavior within a device connected to a legacy switch via changing the link t
KritikCVSS 9,1İstismar yokEPSS %0opennetworking · onos24 Mar 2025
- CVE-2026-1639236İzleyin
JIT miscompilation in the JavaScript Engine: JIT component
KritikCVSS 9,1İstismar yokEPSS %0mozilla · firefox21 Tem 2026
- CVE-2018-1676635İzleyin
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or poss
YüksekCVSS 8,8İstismar yokEPSS %1webassembly virtual machine project · webassembly virtual machine10 Eyl 2018
- CVE-2023-2055835İzleyin
Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to
YüksekCVSS 8,8İstismar yokEPSS %1amd · ryzen 7 5700g firmware2 Nis 2023
- CVE-2026-3301134İzleyin
Nest Fastify HEAD Request Middleware Bypass
YüksekCVSS 8,7İstismar yokEPSS %0nestjs · nest20 Mar 2026
- CVE-2026-187434İzleyin
Denial-of-Service (DoS) vulnerability in Ethernet function of MELSEC iQ-F Series EtherNet/IP module and Ethernet module
YüksekCVSS 8,7İstismar yokEPSS %0mitsubishielectric · melsec iq-f fx5-eip firmware3 Mar 2026
- CVE-2024-565933İzleyin
Rockwell Automation Multicast Request Causes major nonrecoverable fault on Select Controllers
YüksekCVSS 8,3İstismar yokEPSS %0rockwellautomation · controllogix 5580 firmware14 Haz 2024
- CVE-2023-166832İzleyin
A flaw was found in openvswitch (OVS).
YüksekCVSS 8,2İstismar yokEPSS %1cloudbase · open vswitch10 Nis 2023
- CVE-2024-3836532İzleyin
btcd did not correctly re-implement Bitcoin Core's "FindAndDelete()" functionality
YüksekCVSS 8,1İstismar yokEPSS %1btcd project · btcd11 Eki 2024
- CVE-2024-5281132İzleyin
Acks not validated before logged to qlog leads to buffer overflow in ngtcp2
YüksekCVSS 8,2İstismar yokEPSS %1ngtcp2 · ngtcp225 Kas 2024
- CVE-2025-4909132İzleyin
KDE Konsole before 25.04.2 allows remote code execution in a certain scenario.
YüksekCVSS 8,2Kavram kanıtıEPSS %1kde · konsole10 Haz 2025
- CVE-2023-040032İzleyin
The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0.
YüksekCVSS 8,2Kavram kanıtıEPSS %0trellix · data loss prevention2 Şub 2023