İçeriğe atla
Noroxi

CWE-841 · 58 kayıt

Improper Enforcement of Behavioral Workflow

Bu sınıftaki CVE’ler

58 kayıt

  • CVE-2026-67279
    57Planlayın

    SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS

    OrtaCVSS 6,9KEVSilahlaştırılmışEPSS %1

    mikrotik · routeros5 Eyl 2026

  • CVE-2023-4181
    39İzleyin

    SourceCodester Free Hospital Management System for Small Practices Redirect behavioral workflow

    KritikCVSS 9,8İstismar yokEPSS %1

    mayurik · free hospital management system for small practices6 Ağu 2023

  • CVE-2026-3130
    39İzleyin

    Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete per

    KritikCVSS 9,8İstismar yokEPSS %1

    devolutions · devolutions server3 Mar 2026

  • CVE-2022-2105
    36İzleyin

    Secheron SEPCOS Control and Protection Relay

    KritikCVSS 9,1İstismar yokEPSS %1

    secheron · sepcos control and protection relay firmware24 Haz 2022

  • CVE-2026-65126
    35İzleyin

    NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper enforcement of a behavioral workf

    YüksekCVSS 8,8İstismar yokEPSS %0

    nvidia · infra controller22 Eyl 2026

  • CVE-2026-95369
    35İzleyin

    Inappropriate implementation in XML in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code

    YüksekCVSS 8,8İstismar yok

    google · chrome1 gün önce

  • CVE-2026-43974
    34İzleyin

    gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing server-driven protocol hijack and OOM

    YüksekCVSS 8,7İstismar yokEPSS %1

    ninenines · gun8 Haz 2026

  • CVE-2026-55763
    34İzleyin

    Klever-Go: Percentage-transfer royalty skips the source debit at exactly-100% splits

    YüksekCVSS 8,7İstismar yokEPSS %1

    klever-io · klever-go28 Ağu 2026

  • CVE-2026-34582
    34İzleyin

    Botan has a TLS 1.3 certificate authentication bypass

    YüksekCVSS 8,7İstismar yokEPSS %0

    botan project · botan7 Nis 2026

  • CVE-2026-80195
    34İzleyin

    Kimai before 2.63.0 Team Membership Removal via API

    YüksekCVSS 8,7İstismar yokEPSS %0

    kimai · kimai26 Ağu 2026

  • CVE-2025-48479
    34İzleyin

    FreeScout Has Business Logic Errors

    YüksekCVSS 8,5İstismar yokEPSS %0

    freescout · freescout30 May 2025

  • CVE-2026-41259
    32İzleyin

    Mastodon: Insufficient verification of email addresses

    YüksekCVSS 8,2İstismar yokEPSS %0

    joinmastodon · mastodon23 Nis 2026

  • CVE-2022-1667
    30İzleyin

    Secheron SEPCOS Control and Protection Relay

    YüksekCVSS 7,5İstismar yokEPSS %1

    secheron · sepcos control and protection relay firmware24 Haz 2022

  • CVE-2022-2102
    30İzleyin

    Secheron SEPCOS Control and Protection Relay

    YüksekCVSS 7,5İstismar yokEPSS %1

    secheron · sepcos control and protection relay firmware24 Haz 2022

  • CVE-2024-46307
    30İzleyin

    A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products.

    YüksekCVSS 7,5İstismar yokEPSS %0

    sparkshop · sparkshop9 Eki 2024

  • CVE-2024-0410
    30İzleyin

    Improper Enforcement of Behavioral Workflow in GitLab

    YüksekCVSS 7,7İstismar yokEPSS %0

    gitlab · gitlab21 Şub 2024

  • CVE-2026-30574
    30İzleyin

    A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file.

    YüksekCVSS 7,5İstismar yokEPSS %0

    senior-walter · web-based pharmacy product management system27 Mar 2026

  • CVE-2026-79083
    30İzleyin

    Improper enforcement of behavioral workflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised t

    YüksekCVSS 7,5İstismar yokEPSS %0

    google · chrome25 Ağu 2026

  • CVE-2026-78135
    29İzleyin

    libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine.

    YüksekCVSS 7,3İstismar yokEPSS %0

    strongswan · strongswan10 Eyl 2026

  • CVE-2025-48476
    28İzleyin

    FreeScout Has Business Logic Errors

    YüksekCVSS 7,1İstismar yokEPSS %1

    freescout · freescout30 May 2025

  • CVE-2025-48477
    28İzleyin

    FreeScout Has Business Logic Errors

    YüksekCVSS 7,1İstismar yokEPSS %0

    freescout · freescout30 May 2025

  • CVE-2025-48478
    28İzleyin

    FreeScout Has Business Logic Errors

    YüksekCVSS 7,0İstismar yokEPSS %0

    freescout · freescout30 May 2025

  • CVE-2026-82406
    28İzleyin

    Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace

    YüksekCVSS 7,1İstismar yokEPSS %0

    klever-io · klever-go23 Eyl 2026

  • CVE-2025-48480
    28İzleyin

    FreeScout Has Business Logic Errors

    YüksekCVSS 7,0İstismar yokEPSS %0

    freescout · freescout30 May 2025

  • CVE-2025-52469
    28İzleyin

    Chamilo: Friend Request Workflow Bypass - Unauthorized Friend Addition and ID Validation Bypass

    YüksekCVSS 7,1İstismar yokEPSS %0

    chamilo · chamilo lms2 Mar 2026

Tüm zafiyet sınıfları