CWE-684 · 27 records
Incorrect Provision of Specified Functionality
CVEs in this class
27 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-24845No exploit | A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC,siemens · ruggedcom ros · CWE-684 | Critical9.8 | — | 0.7% | Aug 8, 2023 |
39Monitor | CVE-2026-40685No exploit | In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in exim · exim · CWE-684 | Critical9.8 | — | 0.6% | Apr 30, 2026 |
39Monitor | CVE-2024-50357No exploit | FutureNet NXR series routers provided by Century Systems Co., Ltd.century systems co., ltd. · futurenet nxr-g110 series · CWE-684 | Critical9.8 | — | 0.6% | Nov 29, 2024 |
37Monitor | CVE-2026-52735No exploit | ZEBRA: Consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parserzcashfoundation · zebra · CWE-684 | Critical9.3 | — | 0.5% | Aug 18, 2026 |
36Monitor | CVE-2026-44597No exploit | Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.torproject · tor · CWE-684 | Critical9.1 | — | 0.6% | May 6, 2026 |
36Monitor | CVE-2024-6425No exploit | Incorrect Provision of Specified Functionality vulnerability in MESbookmesbook · mesbook · CWE-684 | Critical9.1 | — | 0.5% | Jul 1, 2024 |
32Monitor | CVE-2025-66384No exploit | app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, related to tmp_name.misp · misp · CWE-684 | High8.2 | — | 0.4% | Nov 28, 2025 |
31Monitor | CVE-2023-5363No exploit | Incorrect cipher key & IV length processingopenssl · openssl · CWE-684 | High7.5 | — | 3.3% | Oct 25, 2023 |
31Monitor | CVE-2025-47227Proof of concept | In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandlescriptcase · scriptcase · CWE-684 | High7.5 | — | 2.1% | Jul 4, 2025 |
30Monitor | CVE-2026-40684No exploit | In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is presexim · exim · CWE-684 | High7.5 | — | 0.6% | Apr 30, 2026 |
29Monitor | CVE-2024-20317No exploit | Cisco IOS XR Software Layer 2 Services Denial of Service Vulnerabilitycisco · ios xr · CWE-684 | High7.4 | — | 0.2% | Sep 11, 2024 |
26Monitor | CVE-2023-4258No exploit | bt: mesh: vulnerability in provisioning protocol implementation on provisionee sidezephyrproject · zephyr · CWE-684 | Medium6.5 | — | 0.6% | Sep 25, 2023 |
26Monitor | CVE-2024-6502No exploit | Incorrect Provision of Specified Functionality in GitLabgitlab · gitlab · CWE-684 | Medium6.5 | — | 0.4% | Aug 22, 2024 |
26Monitor | CVE-2026-42255No exploit | Technitium DNS Server before 15.0 allows DNS traffic amplification via cyclic name server delegation.technitium · dnsserver · CWE-684 | Medium6.5 | — | 0.4% | Apr 26, 2026 |
26Monitor | CVE-2025-58325No exploit | An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0fortinet · fortios · CWE-684 | Medium6.7 | — | 0.3% | Oct 14, 2025 |
24Monitor | CVE-2022-23728No exploit | Attacker can reset the device with AT Command in the process of rebooting the device.google · android · CWE-684 | Medium6.1 | — | 0.1% | Jan 21, 2022 |
23Monitor | CVE-2026-79126No exploit | Incorrect provision of specified functionality in Proxy in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker tgoogle · chrome · CWE-684 | Medium5.9 | — | 0.2% | Aug 25, 2026 |
22Monitor | CVE-2023-5158No exploit | Possible dos from guest to host invringh_kiov_advance in vhost driver at drivers/vhost/vringh.clinux · linux kernel · CWE-684 | Medium5.5 | — | 0.2% | Sep 25, 2023 |
21Monitor | CVE-2025-54567No exploit | hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.qemu · qemu · CWE-684 | Medium5.4 | — | 0.2% | Jul 24, 2025 |
17Monitor | CVE-2024-5005No exploit | Incorrect Provision of Specified Functionality in GitLabgitlab · gitlab · CWE-684 | Medium4.3 | — | 0.4% | Oct 11, 2024 |
17Monitor | CVE-2024-8974No exploit | Incorrect Provision of Specified Functionality in GitLabgitlab · gitlab · CWE-684 | Medium4.3 | — | 0.3% | Sep 26, 2024 |
14Monitor | CVE-2020-11054No exploit | Incorrect Provision of Specified Functionality in qutebrowserqutebrowser · qutebrowser · CWE-684 | Low3.5 | — | 1.5% | May 7, 2020 |
14Monitor | CVE-2025-54568No exploit | Akamai Rate Control alpha before 2025 allows attackers to send requests above the stipulated thresholds because the rate is measured separatakamai · rate control · CWE-684 | Low3.7 | — | 0.3% | Jul 25, 2025 |
13Monitor | CVE-2026-35379No exploit | uutils coreutils tr Local Logic Error and Data Integrity Issue in Character Class Handlinguutils · coreutils · CWE-684 | Low3.3 | — | 0.2% | Apr 22, 2026 |
13Monitor | CVE-2026-35381No exploit | uutils coreutils cut Local Logic Error and Data Integrity Issue in Output Filteringuutils · coreutils · CWE-684 | Low3.3 | — | 0.2% | Apr 22, 2026 |
- CVE-2023-2484539Monitor
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC,
CriticalCVSS 9.8No exploitEPSS 1%siemens · ruggedcom rosAug 8, 2023
- CVE-2026-4068539Monitor
In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in
CriticalCVSS 9.8No exploitEPSS 1%exim · eximApr 30, 2026
- CVE-2024-5035739Monitor
FutureNet NXR series routers provided by Century Systems Co., Ltd.
CriticalCVSS 9.8No exploitEPSS 1%century systems co., ltd. · futurenet nxr-g110 seriesNov 29, 2024
- CVE-2026-5273537Monitor
ZEBRA: Consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser
CriticalCVSS 9.3No exploitEPSS 1%zcashfoundation · zebraAug 18, 2026
- CVE-2026-4459736Monitor
Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.
CriticalCVSS 9.1No exploitEPSS 1%torproject · torMay 6, 2026
- CVE-2024-642536Monitor
Incorrect Provision of Specified Functionality vulnerability in MESbook
CriticalCVSS 9.1No exploitEPSS 1%mesbook · mesbookJul 1, 2024
- CVE-2025-6638432Monitor
app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, related to tmp_name.
HighCVSS 8.2No exploitEPSS 0%misp · mispNov 28, 2025
- CVE-2023-536331Monitor
Incorrect cipher key & IV length processing
HighCVSS 7.5No exploitEPSS 3%openssl · opensslOct 25, 2023
- CVE-2025-4722731Monitor
In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandle
HighCVSS 7.5Proof of conceptEPSS 2%scriptcase · scriptcaseJul 4, 2025
- CVE-2026-4068430Monitor
In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is pres
HighCVSS 7.5No exploitEPSS 1%exim · eximApr 30, 2026
- CVE-2024-2031729Monitor
Cisco IOS XR Software Layer 2 Services Denial of Service Vulnerability
HighCVSS 7.4No exploitEPSS 0%cisco · ios xrSep 11, 2024
- CVE-2023-425826Monitor
bt: mesh: vulnerability in provisioning protocol implementation on provisionee side
MediumCVSS 6.5No exploitEPSS 1%zephyrproject · zephyrSep 25, 2023
- CVE-2024-650226Monitor
Incorrect Provision of Specified Functionality in GitLab
MediumCVSS 6.5No exploitEPSS 0%gitlab · gitlabAug 22, 2024
- CVE-2026-4225526Monitor
Technitium DNS Server before 15.0 allows DNS traffic amplification via cyclic name server delegation.
MediumCVSS 6.5No exploitEPSS 0%technitium · dnsserverApr 26, 2026
- CVE-2025-5832526Monitor
An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0
MediumCVSS 6.7No exploitEPSS 0%fortinet · fortiosOct 14, 2025
- CVE-2022-2372824Monitor
Attacker can reset the device with AT Command in the process of rebooting the device.
MediumCVSS 6.1No exploitEPSS 0%google · androidJan 21, 2022
- CVE-2026-7912623Monitor
Incorrect provision of specified functionality in Proxy in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker t
MediumCVSS 5.9No exploitEPSS 0%google · chromeAug 25, 2026
- CVE-2023-515822Monitor
Possible dos from guest to host invringh_kiov_advance in vhost driver at drivers/vhost/vringh.c
MediumCVSS 5.5No exploitEPSS 0%linux · linux kernelSep 25, 2023
- CVE-2025-5456721Monitor
hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.
MediumCVSS 5.4No exploitEPSS 0%qemu · qemuJul 24, 2025
- CVE-2024-500517Monitor
Incorrect Provision of Specified Functionality in GitLab
MediumCVSS 4.3No exploitEPSS 0%gitlab · gitlabOct 11, 2024
- CVE-2024-897417Monitor
Incorrect Provision of Specified Functionality in GitLab
MediumCVSS 4.3No exploitEPSS 0%gitlab · gitlabSep 26, 2024
- CVE-2020-1105414Monitor
Incorrect Provision of Specified Functionality in qutebrowser
LowCVSS 3.5No exploitEPSS 2%qutebrowser · qutebrowserMay 7, 2020
- CVE-2025-5456814Monitor
Akamai Rate Control alpha before 2025 allows attackers to send requests above the stipulated thresholds because the rate is measured separat
LowCVSS 3.7No exploitEPSS 0%akamai · rate controlJul 25, 2025
- CVE-2026-3537913Monitor
uutils coreutils tr Local Logic Error and Data Integrity Issue in Character Class Handling
LowCVSS 3.3No exploitEPSS 0%uutils · coreutilsApr 22, 2026
- CVE-2026-3538113Monitor
uutils coreutils cut Local Logic Error and Data Integrity Issue in Output Filtering
LowCVSS 3.3No exploitEPSS 0%uutils · coreutilsApr 22, 2026