CWE-840 · 99 records
Business Logic Errors
CVEs in this class
99 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2022-32207No exploit | When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a renhaxx · curl · CWE-840 | Critical9.8 | — | 7.7% | Jul 7, 2022 |
39Monitor | CVE-2021-4171No exploit | Business Logic Errors in janeczku/calibre-webjaneczku · calibre-web · CWE-840 | Critical9.8 | — | 1.4% | Jan 17, 2022 |
39Monitor | CVE-2022-4719No exploit | Business Logic Errors in ikus060/rdiffwebikus-soft · rdiffweb · CWE-840 | Critical9.8 | — | 1.0% | Dec 27, 2022 |
39Monitor | CVE-2022-3363No exploit | Business Logic Errors in ikus060/rdiffwebikus-soft · rdiffweb · CWE-840 | Critical9.8 | — | 0.8% | Oct 26, 2022 |
35Monitor | CVE-2022-0935No exploit | Host Header injection in password Reset in livehelperchat/livehelperchatlivehelperchat · live helper chat · CWE-840 | High8.8 | — | 1.3% | Apr 7, 2022 |
35Monitor | CVE-2019-3787No exploit | UAA defaults email address to an insecure domainpivotal software · cloud foundry uaa-release · CWE-840 | High8.8 | — | 1.1% | Jun 19, 2019 |
35Monitor | CVE-2025-2938No exploit | Business Logic Errors in GitLabgitlab · gitlab · CWE-840 | High8.8 | — | 0.3% | Jun 26, 2025 |
35Monitor | CVE-2023-6514No exploit | The Bluetooth module of some Huawei Smart Screen products has an identity authentication bypass vulnerability.huawei · ajmd-370s firmware · CWE-840 | High8.8 | — | 0.3% | Dec 6, 2023 |
33Monitor | CVE-2021-22926No exploit | libcurl-using applications can ask for a specific client certificate to be used in a transfer.haxx · curl · CWE-840 | High7.5 | — | 9.8% | Aug 5, 2021 |
32Monitor | CVE-2026-1322No exploit | Business Logic Errors in GitLabgitlab · gitlab · CWE-840 | High8.1 | — | 0.3% | May 14, 2026 |
31Monitor | CVE-2022-27782No exploit | libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.haxx · curl · CWE-840 | High7.5 | — | 2.9% | Jun 2, 2022 |
31Monitor | CVE-2026-58558No exploit | Permission control vulnerability in the file system.huawei · harmony os · CWE-840 | High7.8 | — | 0.1% | Jul 15, 2026 |
30Monitor | CVE-2022-0524No exploit | Business Logic Errors in publify/publifypublify project · publify · CWE-840 | High7.5 | — | 1.6% | Feb 8, 2022 |
30Monitor | CVE-2024-2267No exploit | keerti1924 Online-Book-Store-Website shop.php logic errorkeerti1924 · online bookstore website · CWE-840 | High7.5 | — | 0.5% | Mar 7, 2024 |
30Monitor | CVE-2025-1908No exploit | Business Logic Errors in GitLabgitlab · gitlab · CWE-840 | High7.7 | — | 0.4% | Apr 24, 2025 |
30Monitor | CVE-2024-45424No exploit | Zoom Workplace Apps - Business Logic Errorzoom · meeting software development kit · CWE-840 | High7.5 | — | 0.4% | Feb 25, 2025 |
30Monitor | CVE-2024-51523No exploit | Information management vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confidenhuawei · harmonyos · CWE-840 | High7.5 | — | 0.2% | Nov 5, 2024 |
30Monitor | CVE-2024-54098No exploit | Service logic error vulnerability in the system service module Impact: Successful exploitation of this vulnerability may affect service intehuawei · emui · CWE-840 | High7.5 | — | 0.2% | Dec 12, 2024 |
30Monitor | CVE-2024-56449No exploit | Privilege escalation vulnerability in the Account module Impact: Successful exploitation of this vulnerability may affect service confidentihuawei · emui · CWE-840 | High7.5 | — | 0.2% | Jan 8, 2025 |
29Monitor | CVE-2022-1155No exploit | Old sessions are not blocked by the login enable function. in snipe/snipe-itsnipeitapp · snipe-it · CWE-840 | High7.4 | — | 1.0% | Mar 30, 2022 |
28Monitor | CVE-2023-6017No exploit | H2O S3 Bucket Takeoverh2o · h2o · CWE-840 | High7.1 | — | 0.9% | Nov 16, 2023 |
28Monitor | CVE-2024-1456No exploit | S3 Bucket Takeover in h2oai/h2o-3h2o · h2o · CWE-840 | High7.1 | — | 0.2% | Apr 15, 2024 |
28Monitor | CVE-2025-54606No exploit | Status verification vulnerability in the lock screen module.huawei · harmonyos · CWE-840 | High7.1 | — | 0.1% | Aug 5, 2025 |
27Monitor | CVE-2021-22922No exploit | When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML haxx · curl · CWE-840 | Medium6.5 | — | 4.3% | Aug 5, 2021 |
27Monitor | CVE-2021-36012No exploit | Magento Commerce Gift Card Business Logic Erroradobe · adobe commerce · CWE-840 | Medium6.5 | — | 2.0% | Sep 1, 2021 |
- CVE-2022-3220741Plan
When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a ren
CriticalCVSS 9.8No exploitEPSS 8%haxx · curlJul 7, 2022
- CVE-2021-417139Monitor
Business Logic Errors in janeczku/calibre-web
CriticalCVSS 9.8No exploitEPSS 1%janeczku · calibre-webJan 17, 2022
- CVE-2022-471939Monitor
Business Logic Errors in ikus060/rdiffweb
CriticalCVSS 9.8No exploitEPSS 1%ikus-soft · rdiffwebDec 27, 2022
- CVE-2022-336339Monitor
Business Logic Errors in ikus060/rdiffweb
CriticalCVSS 9.8No exploitEPSS 1%ikus-soft · rdiffwebOct 26, 2022
- CVE-2022-093535Monitor
Host Header injection in password Reset in livehelperchat/livehelperchat
HighCVSS 8.8No exploitEPSS 1%livehelperchat · live helper chatApr 7, 2022
- CVE-2019-378735Monitor
UAA defaults email address to an insecure domain
HighCVSS 8.8No exploitEPSS 1%pivotal software · cloud foundry uaa-releaseJun 19, 2019
- CVE-2025-293835Monitor
Business Logic Errors in GitLab
HighCVSS 8.8No exploitEPSS 0%gitlab · gitlabJun 26, 2025
- CVE-2023-651435Monitor
The Bluetooth module of some Huawei Smart Screen products has an identity authentication bypass vulnerability.
HighCVSS 8.8No exploitEPSS 0%huawei · ajmd-370s firmwareDec 6, 2023
- CVE-2021-2292633Monitor
libcurl-using applications can ask for a specific client certificate to be used in a transfer.
HighCVSS 7.5No exploitEPSS 10%haxx · curlAug 5, 2021
- CVE-2026-132232Monitor
Business Logic Errors in GitLab
HighCVSS 8.1No exploitEPSS 0%gitlab · gitlabMay 14, 2026
- CVE-2022-2778231Monitor
libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.
HighCVSS 7.5No exploitEPSS 3%haxx · curlJun 2, 2022
- CVE-2026-5855831Monitor
Permission control vulnerability in the file system.
HighCVSS 7.8No exploitEPSS 0%huawei · harmony osJul 15, 2026
- CVE-2022-052430Monitor
Business Logic Errors in publify/publify
HighCVSS 7.5No exploitEPSS 2%publify project · publifyFeb 8, 2022
- CVE-2024-226730Monitor
keerti1924 Online-Book-Store-Website shop.php logic error
HighCVSS 7.5No exploitEPSS 1%keerti1924 · online bookstore websiteMar 7, 2024
- CVE-2025-190830Monitor
Business Logic Errors in GitLab
HighCVSS 7.7No exploitEPSS 0%gitlab · gitlabApr 24, 2025
- CVE-2024-4542430Monitor
Zoom Workplace Apps - Business Logic Error
HighCVSS 7.5No exploitEPSS 0%zoom · meeting software development kitFeb 25, 2025
- CVE-2024-5152330Monitor
Information management vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confiden
HighCVSS 7.5No exploitEPSS 0%huawei · harmonyosNov 5, 2024
- CVE-2024-5409830Monitor
Service logic error vulnerability in the system service module Impact: Successful exploitation of this vulnerability may affect service inte
HighCVSS 7.5No exploitEPSS 0%huawei · emuiDec 12, 2024
- CVE-2024-5644930Monitor
Privilege escalation vulnerability in the Account module Impact: Successful exploitation of this vulnerability may affect service confidenti
HighCVSS 7.5No exploitEPSS 0%huawei · emuiJan 8, 2025
- CVE-2022-115529Monitor
Old sessions are not blocked by the login enable function. in snipe/snipe-it
HighCVSS 7.4No exploitEPSS 1%snipeitapp · snipe-itMar 30, 2022
- CVE-2023-601728Monitor
H2O S3 Bucket Takeover
HighCVSS 7.1No exploitEPSS 1%h2o · h2oNov 16, 2023
- CVE-2024-145628Monitor
S3 Bucket Takeover in h2oai/h2o-3
HighCVSS 7.1No exploitEPSS 0%h2o · h2oApr 15, 2024
- CVE-2025-5460628Monitor
Status verification vulnerability in the lock screen module.
HighCVSS 7.1No exploitEPSS 0%huawei · harmonyosAug 5, 2025
- CVE-2021-2292227Monitor
When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML
MediumCVSS 6.5No exploitEPSS 4%haxx · curlAug 5, 2021
- CVE-2021-3601227Monitor
Magento Commerce Gift Card Business Logic Error
MediumCVSS 6.5No exploitEPSS 2%adobe · adobe commerceSep 1, 2021