İçeriğe atla
Noroxi

CWE-670 · 142 kayıt

Always-Incorrect Control Flow Implementation

Bu sınıftaki CVE’ler

142 kayıt

  • CVE-2024-32896
    62Bu hafta

    there is a possible way to bypass due to a logic error in the code.

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %3

    google · android13 Haz 2024

  • CVE-2019-17192
    40Planlayın

    The WebRTC component in the Signal Private Messenger application through 4.47.7 for Android processes videoconferencing RTP packets before a

    KritikCVSS 9,8İstismar yokEPSS %3

    signal · private messenger4 Eki 2019

  • CVE-2020-1914
    40Planlayın

    A logic vulnerability when handling the SaveGeneratorLong instruction in Facebook Hermes prior to commit b2021df620824627f5a8c96615edbd1eb7f

    KritikCVSS 9,8İstismar yokEPSS %3

    facebook · hermes8 Eki 2020

  • CVE-2020-17466
    39İzleyin

    Turcom TRCwifiZone through 2020-08-10 allows authentication bypass by visiting manage/control.php and ignoring 302 Redirect responses.

    KritikCVSS 9,8İstismar yokEPSS %1

    turcom · trcwifizone11 Ağu 2020

  • CVE-2022-21679
    39İzleyin

    Authorization Policy bypass in Istio

    KritikCVSS 9,8İstismar yokEPSS %1

    istio · istio19 Oca 2022

  • CVE-2021-41153
    39İzleyin

    Specification non-compliance in JUMPI

    KritikCVSS 9,8İstismar yokEPSS %1

    evm project · evm18 Eki 2021

  • CVE-2025-43359
    39İzleyin

    A logic issue was addressed with improved state management.

    KritikCVSS 9,8İstismar yokEPSS %1

    apple · ipados15 Eyl 2025

  • CVE-2023-23623
    39İzleyin

    Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled in Electron

    KritikCVSS 9,8İstismar yokEPSS %1

    electronjs · electron6 Eyl 2023

  • CVE-2022-2993
    39İzleyin

    bt: host: Wrong key validation check

    KritikCVSS 9,8İstismar yokEPSS %1

    zephyrproject · zephyr9 Ara 2022

  • CVE-2022-25745
    39İzleyin

    Always Incorrect Control Flow Implementation in MODEM

    KritikCVSS 9,8İstismar yokEPSS %0

    qualcomm · mdm9205 firmware13 Nis 2023

  • Cosmos EVM: incorrect state handling during nested EVM execution paths

    KritikCVSS 9,5İstismar yok

    Go · github.com/cosmos/evm11 Mar 2026

  • CVE-2020-9425
    36İzleyin

    An issue was discovered in includes/head.inc.php in rConfig before 3.9.4.

    YüksekCVSS 7,5Kavram kanıtıEPSS %19

    rconfig · rconfig20 Mar 2020

  • CVE-2026-55276
    36İzleyin

    Apache Tomcat: Logged effective web.xml is incomplete

    KritikCVSS 9,1İstismar yokEPSS %1

    apache · tomcat29 Haz 2026

  • CVE-2025-29312
    36İzleyin

    An issue in onos v2.7.0 allows attackers to trigger unexpected behavior within a device connected to a legacy switch via changing the link t

    KritikCVSS 9,1İstismar yokEPSS %0

    opennetworking · onos24 Mar 2025

  • CVE-2026-16392
    36İzleyin

    JIT miscompilation in the JavaScript Engine: JIT component

    KritikCVSS 9,1İstismar yokEPSS %0

    mozilla · firefox21 Tem 2026

  • CVE-2018-16766
    35İzleyin

    In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or poss

    YüksekCVSS 8,8İstismar yokEPSS %1

    webassembly virtual machine project · webassembly virtual machine10 Eyl 2018

  • CVE-2023-20558
    35İzleyin

    Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to

    YüksekCVSS 8,8İstismar yokEPSS %1

    amd · ryzen 7 5700g firmware2 Nis 2023

  • CVE-2026-33011
    34İzleyin

    Nest Fastify HEAD Request Middleware Bypass

    YüksekCVSS 8,7İstismar yokEPSS %0

    nestjs · nest20 Mar 2026

  • CVE-2026-1874
    34İzleyin

    Denial-of-Service (DoS) vulnerability in Ethernet function of MELSEC iQ-F Series EtherNet/IP module and Ethernet module

    YüksekCVSS 8,7İstismar yokEPSS %0

    mitsubishielectric · melsec iq-f fx5-eip firmware3 Mar 2026

  • CVE-2024-5659
    33İzleyin

    Rockwell Automation Multicast Request Causes major nonrecoverable fault on Select Controllers

    YüksekCVSS 8,3İstismar yokEPSS %0

    rockwellautomation · controllogix 5580 firmware14 Haz 2024

  • CVE-2023-1668
    32İzleyin

    A flaw was found in openvswitch (OVS).

    YüksekCVSS 8,2İstismar yokEPSS %1

    cloudbase · open vswitch10 Nis 2023

  • CVE-2024-38365
    32İzleyin

    btcd did not correctly re-implement Bitcoin Core's "FindAndDelete()" functionality

    YüksekCVSS 8,1İstismar yokEPSS %1

    btcd project · btcd11 Eki 2024

  • CVE-2024-52811
    32İzleyin

    Acks not validated before logged to qlog leads to buffer overflow in ngtcp2

    YüksekCVSS 8,2İstismar yokEPSS %1

    ngtcp2 · ngtcp225 Kas 2024

  • CVE-2025-49091
    32İzleyin

    KDE Konsole before 25.04.2 allows remote code execution in a certain scenario.

    YüksekCVSS 8,2Kavram kanıtıEPSS %1

    kde · konsole10 Haz 2025

  • CVE-2023-0400
    32İzleyin

    The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0.

    YüksekCVSS 8,2Kavram kanıtıEPSS %0

    trellix · data loss prevention2 Şub 2023

Tüm zafiyet sınıfları