CWE-696 · 44 kayıt
Incorrect Behavior Order
Bu sınıftaki CVE’ler
45 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
37İzleyin | CVE-2026-44108İstismar yok | Firewall bypass during shutdownphoenix contact · charx sec-3150 · CWE-696 | Kritik9,3 | — | %0,8 | 30 Tem 2026 |
36İzleyin | GHSA-j496-crgh-34mxİstismar yok | ibc-go: Potential Reentrancy using Timeout Callbacks in ibc-hooksGo · github.com/cosmos/ibc-go/v4 · CWE-696 | Kritik9,1 | — | — | 5 Nis 2024 |
34İzleyin | CVE-2026-45033Kavram kanıtı | GitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitorgithub · copilot-cli · CWE-696 | Yüksek8,5 | — | %0,4 | 13 May 2026 |
32İzleyin | CVE-2026-14169İstismar yok | ads-tec Industrial IT: Account lockout via non-atomic user creationads-tec industrial it · dvg-irf1401 · CWE-696 | Yüksek8,1 | — | %0,5 | 28 Tem 2026 |
32İzleyin | CVE-2026-35386İstismar yok | In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line.openbsd · openssh · CWE-696 | Yüksek8,1 | — | %0,4 | 2 Nis 2026 |
30İzleyin | CVE-2021-31379İstismar yok | Junos OS: MX Series: MPC 7/8/9/10/11 cards with MAP-E: PFE halts when an attacker sends malformed IPv4 or IPv6 traffic inside the MAP-E tunnel.juniper · junos · CWE-696 | Yüksek7,5 | — | %1,3 | 19 Eki 2021 |
30İzleyin | CVE-2025-31485İstismar yok | GraphQL grant on a property might be cached with different objectsapi-platform · core · CWE-696 | Yüksek7,5 | — | %0,6 | 3 Nis 2025 |
30İzleyin | CVE-2025-48965İstismar yok | Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_named_data can trigger conflicting data with val.p of NULL barm · mbed tls · CWE-696 | Yüksek7,5 | — | %0,5 | 20 Tem 2025 |
30İzleyin | CVE-2026-41254İstismar yok | Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplicalittlecms · little cms · CWE-696 | Yüksek7,5 | — | %0,4 | 18 Nis 2026 |
29İzleyin | CVE-2023-33224İstismar yok | SolarWinds Platform Incorrect Behavior Order Vulnerabilitysolarwinds · solarwinds platform · CWE-696 | Yüksek7,2 | — | %2,8 | 26 Tem 2023 |
29İzleyin | CVE-2024-24853İstismar yok | Incorrect behavior order in transition between executive monitor and SMI transfer monitor (STM) in some Intel(R) Processor may allow a priviCWE-696 | Yüksek7,3 | — | %0,2 | 14 Ağu 2024 |
29İzleyin | GHSA-p6j4-wvmc-vx2hİstismar yok | Duplicate Advisory: OpenClaw: Tlon cite expansion happens before channel and DM authorization is completenpm · openclaw · CWE-696 | Yüksek7,3 | — | — | 10 Nis 2026 |
28İzleyin | CVE-2026-35636İstismar yok | OpenClaw 2026.3.11 < 2026.3.25 - Session Isolation Bypass via sessionId Resolutionopenclaw · openclaw · CWE-696 | Yüksek7,1 | — | %0,5 | 9 Nis 2026 |
28İzleyin | CVE-2026-73446İstismar yok | Security Advisory 0160arista networks · eos · CWE-696 | Yüksek7,0 | — | %0,3 | 15 Eyl 2026 |
27İzleyin | CVE-2026-35640İstismar yok | OpenClaw < 2026.3.25 - Denial of Service via Unauthenticated Webhook Request Parsingopenclaw · openclaw · CWE-696 | Orta6,9 | — | %0,8 | 9 Nis 2026 |
27İzleyin | CVE-2026-35627İstismar yok | OpenClaw < 2026.3.22 - Unauthenticated Cryptographic Work in Nostr Inbound DM Handlingopenclaw · openclaw · CWE-696 | Orta6,9 | — | %0,7 | 9 Nis 2026 |
27İzleyin | CVE-2026-35652İstismar yok | OpenClaw < 2026.3.22 - Unauthorized Action Execution via Callback Dispatchopenclaw · openclaw · CWE-696 | Orta6,9 | — | %0,6 | 10 Nis 2026 |
27İzleyin | CVE-2026-67217İstismar yok | cJSON JSON Patch Non-Atomic Application Destroys Data Before Validationdavegamble · cjson · CWE-696 | Orta6,9 | — | %0,4 | 29 Tem 2026 |
27İzleyin | CVE-2026-35637İstismar yok | OpenClaw < 2026.3.22 - Premature Cite Expansion Before Authorization in Channel and DMopenclaw · openclaw · CWE-696 | Orta6,9 | — | %0,4 | 9 Nis 2026 |
27İzleyin | CVE-2025-55114İstismar yok | BMC Control-M/Agent improper IP address filtering orderbmc · control-m/agent · CWE-696 | Orta6,9 | — | %0,4 | 16 Eyl 2025 |
27İzleyin | CVE-2025-9904İstismar yok | Unallocated memory access vulnerability in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / Genercanon inc. · generic plus pcl6 printer driver · CWE-696 | Orta6,9 | — | %0,4 | 28 Eyl 2025 |
27İzleyin | CVE-2024-30389İstismar yok | Junos OS: EX4300 Series: Firewall filter not blocking egress trafficjuniper · junos · CWE-696 | Orta6,9 | — | %0,4 | 12 Nis 2024 |
27İzleyin | CVE-2024-30410İstismar yok | Junos OS: EX4300 Series: Loopback filter not blocking traffic despite having discard term.juniper · junos · CWE-696 | Orta6,9 | — | %0,4 | 12 Nis 2024 |
26İzleyin | CVE-2026-44919İstismar yok | In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///openstack · ironic · CWE-696 | Orta6,5 | — | %0,6 | 13 May 2026 |
26İzleyin | CVE-2025-0150İstismar yok | Zoom Workplace Apps for iOS - Incorrect Behavior Orderzoom · meeting software development kit · CWE-696 | Orta6,5 | — | %0,5 | 11 Mar 2025 |
- CVE-2026-4410837İzleyin
Firewall bypass during shutdown
KritikCVSS 9,3İstismar yokEPSS %1phoenix contact · charx sec-315030 Tem 2026
- GHSA-j496-crgh-34mx36İzleyin
ibc-go: Potential Reentrancy using Timeout Callbacks in ibc-hooks
KritikCVSS 9,1İstismar yokGo · github.com/cosmos/ibc-go/v45 Nis 2024
- CVE-2026-4503334İzleyin
GitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitor
YüksekCVSS 8,5Kavram kanıtıEPSS %0github · copilot-cli13 May 2026
- CVE-2026-1416932İzleyin
ads-tec Industrial IT: Account lockout via non-atomic user creation
YüksekCVSS 8,1İstismar yokEPSS %1ads-tec industrial it · dvg-irf140128 Tem 2026
- CVE-2026-3538632İzleyin
In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line.
YüksekCVSS 8,1İstismar yokEPSS %0openbsd · openssh2 Nis 2026
- CVE-2021-3137930İzleyin
Junos OS: MX Series: MPC 7/8/9/10/11 cards with MAP-E: PFE halts when an attacker sends malformed IPv4 or IPv6 traffic inside the MAP-E tunnel.
YüksekCVSS 7,5İstismar yokEPSS %1juniper · junos19 Eki 2021
- CVE-2025-3148530İzleyin
GraphQL grant on a property might be cached with different objects
YüksekCVSS 7,5İstismar yokEPSS %1api-platform · core3 Nis 2025
- CVE-2025-4896530İzleyin
Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_named_data can trigger conflicting data with val.p of NULL b
YüksekCVSS 7,5İstismar yokEPSS %1arm · mbed tls20 Tem 2025
- CVE-2026-4125430İzleyin
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplica
YüksekCVSS 7,5İstismar yokEPSS %0littlecms · little cms18 Nis 2026
- CVE-2023-3322429İzleyin
SolarWinds Platform Incorrect Behavior Order Vulnerability
YüksekCVSS 7,2İstismar yokEPSS %3solarwinds · solarwinds platform26 Tem 2023
- CVE-2024-2485329İzleyin
Incorrect behavior order in transition between executive monitor and SMI transfer monitor (STM) in some Intel(R) Processor may allow a privi
YüksekCVSS 7,3İstismar yokEPSS %014 Ağu 2024
- GHSA-p6j4-wvmc-vx2h29İzleyin
Duplicate Advisory: OpenClaw: Tlon cite expansion happens before channel and DM authorization is complete
YüksekCVSS 7,3İstismar yoknpm · openclaw10 Nis 2026
- CVE-2026-3563628İzleyin
OpenClaw 2026.3.11 < 2026.3.25 - Session Isolation Bypass via sessionId Resolution
YüksekCVSS 7,1İstismar yokEPSS %0openclaw · openclaw9 Nis 2026
- CVE-2026-7344628İzleyin
Security Advisory 0160
YüksekCVSS 7,0İstismar yokEPSS %0arista networks · eos15 Eyl 2026
- CVE-2026-3564027İzleyin
OpenClaw < 2026.3.25 - Denial of Service via Unauthenticated Webhook Request Parsing
OrtaCVSS 6,9İstismar yokEPSS %1openclaw · openclaw9 Nis 2026
- CVE-2026-3562727İzleyin
OpenClaw < 2026.3.22 - Unauthenticated Cryptographic Work in Nostr Inbound DM Handling
OrtaCVSS 6,9İstismar yokEPSS %1openclaw · openclaw9 Nis 2026
- CVE-2026-3565227İzleyin
OpenClaw < 2026.3.22 - Unauthorized Action Execution via Callback Dispatch
OrtaCVSS 6,9İstismar yokEPSS %1openclaw · openclaw10 Nis 2026
- CVE-2026-6721727İzleyin
cJSON JSON Patch Non-Atomic Application Destroys Data Before Validation
OrtaCVSS 6,9İstismar yokEPSS %0davegamble · cjson29 Tem 2026
- CVE-2026-3563727İzleyin
OpenClaw < 2026.3.22 - Premature Cite Expansion Before Authorization in Channel and DM
OrtaCVSS 6,9İstismar yokEPSS %0openclaw · openclaw9 Nis 2026
- CVE-2025-5511427İzleyin
BMC Control-M/Agent improper IP address filtering order
OrtaCVSS 6,9İstismar yokEPSS %0bmc · control-m/agent16 Eyl 2025
- CVE-2025-990427İzleyin
Unallocated memory access vulnerability in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / Gener
OrtaCVSS 6,9İstismar yokEPSS %0canon inc. · generic plus pcl6 printer driver28 Eyl 2025
- CVE-2024-3038927İzleyin
Junos OS: EX4300 Series: Firewall filter not blocking egress traffic
OrtaCVSS 6,9İstismar yokEPSS %0juniper · junos12 Nis 2024
- CVE-2024-3041027İzleyin
Junos OS: EX4300 Series: Loopback filter not blocking traffic despite having discard term.
OrtaCVSS 6,9İstismar yokEPSS %0juniper · junos12 Nis 2024
- CVE-2026-4491926İzleyin
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///
OrtaCVSS 6,5İstismar yokEPSS %1openstack · ironic13 May 2026
- CVE-2025-015026İzleyin
Zoom Workplace Apps for iOS - Incorrect Behavior Order
OrtaCVSS 6,5İstismar yokEPSS %0zoom · meeting software development kit11 Mar 2025