Skip to content
Noroxi

CWE-253 · 24 records

Incorrect Check of Function Return Value

CVEs in this class

24 records

  • It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly.

    CriticalCVSS 9.8No exploitEPSS 3%

    keycloak · keycloak-nodejs-auth-utilsMay 12, 2017

  • CVE-2023-4501
    39Monitor

    Authentication bypass in OpenText (Micro Focus) Enterprise Server

    CriticalCVSS 9.8No exploitEPSS 1%

    microfocus · cobol serverSep 12, 2023

  • Denial of Service in Helper Process management

    HighCVSS 7.5No exploitEPSS 10%

    squid-cache · squidDec 4, 2023

  • Corosync: corosync: denial of service and information disclosure via crafted udp packet

    HighCVSS 8.2No exploitEPSS 1%

    corosync · corosyncApr 1, 2026

  • Windows Hyper-V Denial of Service Vulnerability

    HighCVSS 7.5No exploitEPSS 2%

    microsoft · windows server 2012Oct 8, 2024

  • bpf: Fix ld_{abs,ind} failure path analysis in subprogs

    HighCVSS 7.8No exploitEPSS 0%

    linux · linux kernelJun 24, 2026

  • Arbitrary file read in Citrix ADC and Citrix Gateway 

    HighCVSS 7.5No exploitEPSS 1%

    citrix · application delivery controllerJul 10, 2023

  • CVE-2024-1622
    30Monitor

    Routinator terminates when RTR connection is reset too quickly after opening

    HighCVSS 7.5No exploitEPSS 1%

    nlnetlabs · routinatorFeb 26, 2024

  • Envoy RELEASE_ASSERT using auto_sni with :authority header > 255 bytes

    HighCVSS 7.5No exploitEPSS 1%

    envoyproxy · envoyApr 18, 2024

  • Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value in the second factor

    HighCVSS 7.5No exploitEPSS 0%

    yubico · webauthn-server-coreMay 13, 2026

  • Asterisk can crash from a specifically malformed Authorization header in an incoming SIP request

    HighCVSS 7.5No exploitEPSS 0%

    sangoma · asteriskAug 28, 2025

  • Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification

    HighCVSS 7.5No exploitEPSS 0%

    libssh · libsshJul 21, 2026

  • Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability

    HighCVSS 7.2No exploitEPSS 1%

    adminer · adminerAug 20, 2026

  • CVE-2026-5818
    28Monitor

    MCU Firmware Update Authentication Bypass on Caliptra Core

    HighCVSS 7.2No exploitEPSS 0%

    caliptra · core runtime firmwareJun 23, 2026

  • Apache HTTP Server: 'RewriteCond expr' always evaluates to true in 2.4.64

    MediumCVSS 6.3No exploitEPSS 1%

    apache · http serverJul 23, 2025

  • CVE-2026-0648
    25Monitor

    The vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in threadx/utility/rtos_compatibility_layers

    MediumCVSS 6.3No exploitEPSS 0%

    eclipse · threadxJan 27, 2026

  • CVE-2020-6107
    22Monitor

    An exploitable information disclosure vulnerability exists in the dev_read functionality of F2fs-Tools F2fs.Fsck 1.13.

    MediumCVSS 5.5No exploitEPSS 2%

    f2fs-tools project · f2fs-toolsOct 15, 2020

  • uutils coreutils chmod False Success Exit Code in Recursive Mode

    MediumCVSS 5.5No exploitEPSS 0%

    uutils · coreutilsApr 22, 2026

  • uutils coreutils chown and chgrp False Success Exit Code in Recursive Mode

    MediumCVSS 5.5No exploitEPSS 0%

    uutils · coreutilsApr 22, 2026

  • Duplicate Advisory: uutils coreutils has an Incorrect Check of Function Return Value

    MediumCVSS 5.5No exploit

    crates.io · coreutilsApr 22, 2026

  • Duplicate Advisory: uutils coreutils incorrectly handles exit codes when processing multiple files

    MediumCVSS 5.5No exploit

    crates.io · coreutilsApr 22, 2026

  • Potential Captcha Validate Bypass in flask-session-captcha

    MediumCVSS 5.3No exploitEPSS 1%

    flask-session-captcha project · flask-session-captchaApr 25, 2022

  • ink! vulnerable to incorrect decoding of storage value when using `DelegateCall`

    MediumCVSS 5.3No exploitEPSS 1%

    parity · ink\!Jun 14, 2023

  • mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.

    LowCVSS 3.7No exploitEPSS 0%

    mutt · muttMay 4, 2026

All vulnerability classes