CWE-253 · 24 records
Incorrect Check of Function Return Value
CVEs in this class
24 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2017-7474No exploit | It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly.keycloak · keycloak-nodejs-auth-utils · CWE-253 | Critical9.8 | — | 2.5% | May 12, 2017 |
39Monitor | CVE-2023-4501No exploit | Authentication bypass in OpenText (Micro Focus) Enterprise Servermicrofocus · cobol server · CWE-253 | Critical9.8 | — | 0.8% | Sep 12, 2023 |
33Monitor | CVE-2023-49286No exploit | Denial of Service in Helper Process managementsquid-cache · squid · CWE-253 | High7.5 | — | 10.4% | Dec 4, 2023 |
32Monitor | CVE-2026-35091No exploit | Corosync: corosync: denial of service and information disclosure via crafted udp packetcorosync · corosync · CWE-253 | High8.2 | — | 1.1% | Apr 1, 2026 |
31Monitor | CVE-2024-43521No exploit | Windows Hyper-V Denial of Service Vulnerabilitymicrosoft · windows server 2012 · CWE-253 | High7.5 | — | 2.4% | Oct 8, 2024 |
31Monitor | CVE-2026-53090No exploit | bpf: Fix ld_{abs,ind} failure path analysis in subprogslinux · linux kernel · CWE-253 | High7.8 | — | 0.1% | Jun 24, 2026 |
30Monitor | CVE-2023-24487No exploit | Arbitrary file read in Citrix ADC and Citrix Gateway citrix · application delivery controller · CWE-253 | High7.5 | — | 1.1% | Jul 10, 2023 |
30Monitor | CVE-2024-1622No exploit | Routinator terminates when RTR connection is reset too quickly after openingnlnetlabs · routinator · CWE-253 | High7.5 | — | 1.0% | Feb 26, 2024 |
30Monitor | CVE-2024-32475No exploit | Envoy RELEASE_ASSERT using auto_sni with :authority header > 255 bytesenvoyproxy · envoy · CWE-253 | High7.5 | — | 0.7% | Apr 18, 2024 |
30Monitor | CVE-2026-46419No exploit | Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value in the second factor yubico · webauthn-server-core · CWE-253 | High7.5 | — | 0.4% | May 13, 2026 |
30Monitor | CVE-2025-57767No exploit | Asterisk can crash from a specifically malformed Authorization header in an incoming SIP requestsangoma · asterisk · CWE-253 | High7.5 | — | 0.4% | Aug 28, 2025 |
30Monitor | CVE-2026-59847No exploit | Libssh: libssh: integrity downgrade via openssl aes-gcm tag verificationlibssh · libssh · CWE-253 | High7.5 | — | 0.3% | Jul 21, 2026 |
28Monitor | CVE-2026-15686No exploit | Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerabilityadminer · adminer · CWE-253 | High7.2 | — | 0.7% | Aug 20, 2026 |
28Monitor | CVE-2026-5818No exploit | MCU Firmware Update Authentication Bypass on Caliptra Corecaliptra · core runtime firmware · CWE-253 | High7.2 | — | 0.2% | Jun 23, 2026 |
25Monitor | CVE-2025-54090No exploit | Apache HTTP Server: 'RewriteCond expr' always evaluates to true in 2.4.64apache · http server · CWE-253 | Medium6.3 | — | 0.8% | Jul 23, 2025 |
25Monitor | CVE-2026-0648No exploit | The vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in threadx/utility/rtos_compatibility_layerseclipse · threadx · CWE-253 | Medium6.3 | — | 0.1% | Jan 27, 2026 |
22Monitor | CVE-2020-6107No exploit | An exploitable information disclosure vulnerability exists in the dev_read functionality of F2fs-Tools F2fs.Fsck 1.13.f2fs-tools project · f2fs-tools · CWE-253 | Medium5.5 | — | 1.5% | Oct 15, 2020 |
22Monitor | CVE-2026-35339No exploit | uutils coreutils chmod False Success Exit Code in Recursive Modeuutils · coreutils · CWE-253 | Medium5.5 | — | 0.2% | Apr 22, 2026 |
22Monitor | CVE-2026-35340No exploit | uutils coreutils chown and chgrp False Success Exit Code in Recursive Modeuutils · coreutils · CWE-253 | Medium5.5 | — | 0.2% | Apr 22, 2026 |
22Monitor | GHSA-88ch-q68x-36v7No exploit | Duplicate Advisory: uutils coreutils has an Incorrect Check of Function Return Valuecrates.io · coreutils · CWE-253 | Medium5.5 | — | — | Apr 22, 2026 |
22Monitor | GHSA-vp6q-mv9j-j428No exploit | Duplicate Advisory: uutils coreutils incorrectly handles exit codes when processing multiple filescrates.io · coreutils · CWE-253 | Medium5.5 | — | — | Apr 22, 2026 |
21Monitor | CVE-2022-24880No exploit | Potential Captcha Validate Bypass in flask-session-captchaflask-session-captcha project · flask-session-captcha · CWE-253 | Medium5.3 | — | 1.2% | Apr 25, 2022 |
21Monitor | CVE-2023-34449No exploit | ink! vulnerable to incorrect decoding of storage value when using `DelegateCall`parity · ink\! · CWE-253 | Medium5.3 | — | 1.0% | Jun 14, 2023 |
14Monitor | CVE-2026-43863No exploit | mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.mutt · mutt · CWE-253 | Low3.7 | — | 0.3% | May 4, 2026 |
- CVE-2017-747440Plan
It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly.
CriticalCVSS 9.8No exploitEPSS 3%keycloak · keycloak-nodejs-auth-utilsMay 12, 2017
- CVE-2023-450139Monitor
Authentication bypass in OpenText (Micro Focus) Enterprise Server
CriticalCVSS 9.8No exploitEPSS 1%microfocus · cobol serverSep 12, 2023
- CVE-2023-4928633Monitor
Denial of Service in Helper Process management
HighCVSS 7.5No exploitEPSS 10%squid-cache · squidDec 4, 2023
- CVE-2026-3509132Monitor
Corosync: corosync: denial of service and information disclosure via crafted udp packet
HighCVSS 8.2No exploitEPSS 1%corosync · corosyncApr 1, 2026
- CVE-2024-4352131Monitor
Windows Hyper-V Denial of Service Vulnerability
HighCVSS 7.5No exploitEPSS 2%microsoft · windows server 2012Oct 8, 2024
- CVE-2026-5309031Monitor
bpf: Fix ld_{abs,ind} failure path analysis in subprogs
HighCVSS 7.8No exploitEPSS 0%linux · linux kernelJun 24, 2026
- CVE-2023-2448730Monitor
Arbitrary file read in Citrix ADC and Citrix Gateway
HighCVSS 7.5No exploitEPSS 1%citrix · application delivery controllerJul 10, 2023
- CVE-2024-162230Monitor
Routinator terminates when RTR connection is reset too quickly after opening
HighCVSS 7.5No exploitEPSS 1%nlnetlabs · routinatorFeb 26, 2024
- CVE-2024-3247530Monitor
Envoy RELEASE_ASSERT using auto_sni with :authority header > 255 bytes
HighCVSS 7.5No exploitEPSS 1%envoyproxy · envoyApr 18, 2024
- CVE-2026-4641930Monitor
Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value in the second factor
HighCVSS 7.5No exploitEPSS 0%yubico · webauthn-server-coreMay 13, 2026
- CVE-2025-5776730Monitor
Asterisk can crash from a specifically malformed Authorization header in an incoming SIP request
HighCVSS 7.5No exploitEPSS 0%sangoma · asteriskAug 28, 2025
- CVE-2026-5984730Monitor
Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification
HighCVSS 7.5No exploitEPSS 0%libssh · libsshJul 21, 2026
- CVE-2026-1568628Monitor
Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability
HighCVSS 7.2No exploitEPSS 1%adminer · adminerAug 20, 2026
- CVE-2026-581828Monitor
MCU Firmware Update Authentication Bypass on Caliptra Core
HighCVSS 7.2No exploitEPSS 0%caliptra · core runtime firmwareJun 23, 2026
- CVE-2025-5409025Monitor
Apache HTTP Server: 'RewriteCond expr' always evaluates to true in 2.4.64
MediumCVSS 6.3No exploitEPSS 1%apache · http serverJul 23, 2025
- CVE-2026-064825Monitor
The vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in threadx/utility/rtos_compatibility_layers
MediumCVSS 6.3No exploitEPSS 0%eclipse · threadxJan 27, 2026
- CVE-2020-610722Monitor
An exploitable information disclosure vulnerability exists in the dev_read functionality of F2fs-Tools F2fs.Fsck 1.13.
MediumCVSS 5.5No exploitEPSS 2%f2fs-tools project · f2fs-toolsOct 15, 2020
- CVE-2026-3533922Monitor
uutils coreutils chmod False Success Exit Code in Recursive Mode
MediumCVSS 5.5No exploitEPSS 0%uutils · coreutilsApr 22, 2026
- CVE-2026-3534022Monitor
uutils coreutils chown and chgrp False Success Exit Code in Recursive Mode
MediumCVSS 5.5No exploitEPSS 0%uutils · coreutilsApr 22, 2026
- GHSA-88ch-q68x-36v722Monitor
Duplicate Advisory: uutils coreutils has an Incorrect Check of Function Return Value
MediumCVSS 5.5No exploitcrates.io · coreutilsApr 22, 2026
- GHSA-vp6q-mv9j-j42822Monitor
Duplicate Advisory: uutils coreutils incorrectly handles exit codes when processing multiple files
MediumCVSS 5.5No exploitcrates.io · coreutilsApr 22, 2026
- CVE-2022-2488021Monitor
Potential Captcha Validate Bypass in flask-session-captcha
MediumCVSS 5.3No exploitEPSS 1%flask-session-captcha project · flask-session-captchaApr 25, 2022
- CVE-2023-3444921Monitor
ink! vulnerable to incorrect decoding of storage value when using `DelegateCall`
MediumCVSS 5.3No exploitEPSS 1%parity · ink\!Jun 14, 2023
- CVE-2026-4386314Monitor
mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.
LowCVSS 3.7No exploitEPSS 0%mutt · muttMay 4, 2026