Skip to content
Noroxi

CWE-840 · 99 records

Business Logic Errors

CVEs in this class

99 records

  • When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a ren

    CriticalCVSS 9.8No exploitEPSS 8%

    haxx · curlJul 7, 2022

  • CVE-2021-4171
    39Monitor

    Business Logic Errors in janeczku/calibre-web

    CriticalCVSS 9.8No exploitEPSS 1%

    janeczku · calibre-webJan 17, 2022

  • CVE-2022-4719
    39Monitor

    Business Logic Errors in ikus060/rdiffweb

    CriticalCVSS 9.8No exploitEPSS 1%

    ikus-soft · rdiffwebDec 27, 2022

  • CVE-2022-3363
    39Monitor

    Business Logic Errors in ikus060/rdiffweb

    CriticalCVSS 9.8No exploitEPSS 1%

    ikus-soft · rdiffwebOct 26, 2022

  • CVE-2022-0935
    35Monitor

    Host Header injection in password Reset in livehelperchat/livehelperchat

    HighCVSS 8.8No exploitEPSS 1%

    livehelperchat · live helper chatApr 7, 2022

  • CVE-2019-3787
    35Monitor

    UAA defaults email address to an insecure domain

    HighCVSS 8.8No exploitEPSS 1%

    pivotal software · cloud foundry uaa-releaseJun 19, 2019

  • CVE-2025-2938
    35Monitor

    Business Logic Errors in GitLab

    HighCVSS 8.8No exploitEPSS 0%

    gitlab · gitlabJun 26, 2025

  • CVE-2023-6514
    35Monitor

    The Bluetooth module of some Huawei Smart Screen products has an identity authentication bypass vulnerability.

    HighCVSS 8.8No exploitEPSS 0%

    huawei · ajmd-370s firmwareDec 6, 2023

  • libcurl-using applications can ask for a specific client certificate to be used in a transfer.

    HighCVSS 7.5No exploitEPSS 10%

    haxx · curlAug 5, 2021

  • CVE-2026-1322
    32Monitor

    Business Logic Errors in GitLab

    HighCVSS 8.1No exploitEPSS 0%

    gitlab · gitlabMay 14, 2026

  • libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.

    HighCVSS 7.5No exploitEPSS 3%

    haxx · curlJun 2, 2022

  • Permission control vulnerability in the file system.

    HighCVSS 7.8No exploitEPSS 0%

    huawei · harmony osJul 15, 2026

  • CVE-2022-0524
    30Monitor

    Business Logic Errors in publify/publify

    HighCVSS 7.5No exploitEPSS 2%

    publify project · publifyFeb 8, 2022

  • CVE-2024-2267
    30Monitor

    keerti1924 Online-Book-Store-Website shop.php logic error

    HighCVSS 7.5No exploitEPSS 1%

    keerti1924 · online bookstore websiteMar 7, 2024

  • CVE-2025-1908
    30Monitor

    Business Logic Errors in GitLab

    HighCVSS 7.7No exploitEPSS 0%

    gitlab · gitlabApr 24, 2025

  • Zoom Workplace Apps - Business Logic Error

    HighCVSS 7.5No exploitEPSS 0%

    zoom · meeting software development kitFeb 25, 2025

  • Information management vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confiden

    HighCVSS 7.5No exploitEPSS 0%

    huawei · harmonyosNov 5, 2024

  • Service logic error vulnerability in the system service module Impact: Successful exploitation of this vulnerability may affect service inte

    HighCVSS 7.5No exploitEPSS 0%

    huawei · emuiDec 12, 2024

  • Privilege escalation vulnerability in the Account module Impact: Successful exploitation of this vulnerability may affect service confidenti

    HighCVSS 7.5No exploitEPSS 0%

    huawei · emuiJan 8, 2025

  • CVE-2022-1155
    29Monitor

    Old sessions are not blocked by the login enable function. in snipe/snipe-it

    HighCVSS 7.4No exploitEPSS 1%

    snipeitapp · snipe-itMar 30, 2022

  • CVE-2023-6017
    28Monitor

    H2O S3 Bucket Takeover

    HighCVSS 7.1No exploitEPSS 1%

    h2o · h2oNov 16, 2023

  • CVE-2024-1456
    28Monitor

    S3 Bucket Takeover in h2oai/h2o-3

    HighCVSS 7.1No exploitEPSS 0%

    h2o · h2oApr 15, 2024

  • Status verification vulnerability in the lock screen module.

    HighCVSS 7.1No exploitEPSS 0%

    huawei · harmonyosAug 5, 2025

  • When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML

    MediumCVSS 6.5No exploitEPSS 4%

    haxx · curlAug 5, 2021

  • Magento Commerce Gift Card Business Logic Error

    MediumCVSS 6.5No exploitEPSS 2%

    adobe · adobe commerceSep 1, 2021

All vulnerability classes