CWE-696 · 44 записей
Incorrect Behavior Order
CVE этого класса
45 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
37Наблюдать | CVE-2026-44108Эксплойта нет | Firewall bypass during shutdownphoenix contact · charx sec-3150 · CWE-696 | Критическая9,3 | — | 0,8 % | 30 июл. 2026 г. |
36Наблюдать | GHSA-j496-crgh-34mxЭксплойта нет | ibc-go: Potential Reentrancy using Timeout Callbacks in ibc-hooksGo · github.com/cosmos/ibc-go/v4 · CWE-696 | Критическая9,1 | — | — | 5 апр. 2024 г. |
34Наблюдать | CVE-2026-45033Proof of concept | GitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitorgithub · copilot-cli · CWE-696 | Высокая8,5 | — | 0,4 % | 13 мая 2026 г. |
32Наблюдать | CVE-2026-14169Эксплойта нет | ads-tec Industrial IT: Account lockout via non-atomic user creationads-tec industrial it · dvg-irf1401 · CWE-696 | Высокая8,1 | — | 0,5 % | 28 июл. 2026 г. |
32Наблюдать | CVE-2026-35386Эксплойта нет | In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line.openbsd · openssh · CWE-696 | Высокая8,1 | — | 0,4 % | 2 апр. 2026 г. |
30Наблюдать | CVE-2021-31379Эксплойта нет | Junos OS: MX Series: MPC 7/8/9/10/11 cards with MAP-E: PFE halts when an attacker sends malformed IPv4 or IPv6 traffic inside the MAP-E tunnel.juniper · junos · CWE-696 | Высокая7,5 | — | 1,3 % | 19 окт. 2021 г. |
30Наблюдать | CVE-2025-31485Эксплойта нет | GraphQL grant on a property might be cached with different objectsapi-platform · core · CWE-696 | Высокая7,5 | — | 0,6 % | 3 апр. 2025 г. |
30Наблюдать | CVE-2025-48965Эксплойта нет | Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_named_data can trigger conflicting data with val.p of NULL barm · mbed tls · CWE-696 | Высокая7,5 | — | 0,5 % | 20 июл. 2025 г. |
30Наблюдать | CVE-2026-41254Эксплойта нет | Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplicalittlecms · little cms · CWE-696 | Высокая7,5 | — | 0,4 % | 18 апр. 2026 г. |
29Наблюдать | CVE-2023-33224Эксплойта нет | SolarWinds Platform Incorrect Behavior Order Vulnerabilitysolarwinds · solarwinds platform · CWE-696 | Высокая7,2 | — | 2,8 % | 26 июл. 2023 г. |
29Наблюдать | CVE-2024-24853Эксплойта нет | Incorrect behavior order in transition between executive monitor and SMI transfer monitor (STM) in some Intel(R) Processor may allow a priviCWE-696 | Высокая7,3 | — | 0,2 % | 14 авг. 2024 г. |
29Наблюдать | GHSA-p6j4-wvmc-vx2hЭксплойта нет | Duplicate Advisory: OpenClaw: Tlon cite expansion happens before channel and DM authorization is completenpm · openclaw · CWE-696 | Высокая7,3 | — | — | 10 апр. 2026 г. |
28Наблюдать | CVE-2026-35636Эксплойта нет | OpenClaw 2026.3.11 < 2026.3.25 - Session Isolation Bypass via sessionId Resolutionopenclaw · openclaw · CWE-696 | Высокая7,1 | — | 0,5 % | 9 апр. 2026 г. |
28Наблюдать | CVE-2026-73446Эксплойта нет | Security Advisory 0160arista networks · eos · CWE-696 | Высокая7,0 | — | 0,3 % | 15 сент. 2026 г. |
27Наблюдать | CVE-2026-35640Эксплойта нет | OpenClaw < 2026.3.25 - Denial of Service via Unauthenticated Webhook Request Parsingopenclaw · openclaw · CWE-696 | Средняя6,9 | — | 0,8 % | 9 апр. 2026 г. |
27Наблюдать | CVE-2026-35627Эксплойта нет | OpenClaw < 2026.3.22 - Unauthenticated Cryptographic Work in Nostr Inbound DM Handlingopenclaw · openclaw · CWE-696 | Средняя6,9 | — | 0,7 % | 9 апр. 2026 г. |
27Наблюдать | CVE-2026-35652Эксплойта нет | OpenClaw < 2026.3.22 - Unauthorized Action Execution via Callback Dispatchopenclaw · openclaw · CWE-696 | Средняя6,9 | — | 0,6 % | 10 апр. 2026 г. |
27Наблюдать | CVE-2026-67217Эксплойта нет | cJSON JSON Patch Non-Atomic Application Destroys Data Before Validationdavegamble · cjson · CWE-696 | Средняя6,9 | — | 0,4 % | 29 июл. 2026 г. |
27Наблюдать | CVE-2026-35637Эксплойта нет | OpenClaw < 2026.3.22 - Premature Cite Expansion Before Authorization in Channel and DMopenclaw · openclaw · CWE-696 | Средняя6,9 | — | 0,4 % | 9 апр. 2026 г. |
27Наблюдать | CVE-2025-55114Эксплойта нет | BMC Control-M/Agent improper IP address filtering orderbmc · control-m/agent · CWE-696 | Средняя6,9 | — | 0,4 % | 16 сент. 2025 г. |
27Наблюдать | CVE-2025-9904Эксплойта нет | Unallocated memory access vulnerability in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / Genercanon inc. · generic plus pcl6 printer driver · CWE-696 | Средняя6,9 | — | 0,4 % | 28 сент. 2025 г. |
27Наблюдать | CVE-2024-30389Эксплойта нет | Junos OS: EX4300 Series: Firewall filter not blocking egress trafficjuniper · junos · CWE-696 | Средняя6,9 | — | 0,4 % | 12 апр. 2024 г. |
27Наблюдать | CVE-2024-30410Эксплойта нет | Junos OS: EX4300 Series: Loopback filter not blocking traffic despite having discard term.juniper · junos · CWE-696 | Средняя6,9 | — | 0,4 % | 12 апр. 2024 г. |
26Наблюдать | CVE-2026-44919Эксплойта нет | In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///openstack · ironic · CWE-696 | Средняя6,5 | — | 0,6 % | 13 мая 2026 г. |
26Наблюдать | CVE-2025-0150Эксплойта нет | Zoom Workplace Apps for iOS - Incorrect Behavior Orderzoom · meeting software development kit · CWE-696 | Средняя6,5 | — | 0,5 % | 11 мар. 2025 г. |
- CVE-2026-4410837Наблюдать
Firewall bypass during shutdown
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %phoenix contact · charx sec-315030 июл. 2026 г.
- GHSA-j496-crgh-34mx36Наблюдать
ibc-go: Potential Reentrancy using Timeout Callbacks in ibc-hooks
КритическаяCVSS 9,1Эксплойта нетGo · github.com/cosmos/ibc-go/v45 апр. 2024 г.
- CVE-2026-4503334Наблюдать
GitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitor
ВысокаяCVSS 8,5Proof of conceptEPSS 0 %github · copilot-cli13 мая 2026 г.
- CVE-2026-1416932Наблюдать
ads-tec Industrial IT: Account lockout via non-atomic user creation
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %ads-tec industrial it · dvg-irf140128 июл. 2026 г.
- CVE-2026-3538632Наблюдать
In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line.
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %openbsd · openssh2 апр. 2026 г.
- CVE-2021-3137930Наблюдать
Junos OS: MX Series: MPC 7/8/9/10/11 cards with MAP-E: PFE halts when an attacker sends malformed IPv4 or IPv6 traffic inside the MAP-E tunnel.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %juniper · junos19 окт. 2021 г.
- CVE-2025-3148530Наблюдать
GraphQL grant on a property might be cached with different objects
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %api-platform · core3 апр. 2025 г.
- CVE-2025-4896530Наблюдать
Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_named_data can trigger conflicting data with val.p of NULL b
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %arm · mbed tls20 июл. 2025 г.
- CVE-2026-4125430Наблюдать
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplica
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %littlecms · little cms18 апр. 2026 г.
- CVE-2023-3322429Наблюдать
SolarWinds Platform Incorrect Behavior Order Vulnerability
ВысокаяCVSS 7,2Эксплойта нетEPSS 3 %solarwinds · solarwinds platform26 июл. 2023 г.
- CVE-2024-2485329Наблюдать
Incorrect behavior order in transition between executive monitor and SMI transfer monitor (STM) in some Intel(R) Processor may allow a privi
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %14 авг. 2024 г.
- GHSA-p6j4-wvmc-vx2h29Наблюдать
Duplicate Advisory: OpenClaw: Tlon cite expansion happens before channel and DM authorization is complete
ВысокаяCVSS 7,3Эксплойта нетnpm · openclaw10 апр. 2026 г.
- CVE-2026-3563628Наблюдать
OpenClaw 2026.3.11 < 2026.3.25 - Session Isolation Bypass via sessionId Resolution
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %openclaw · openclaw9 апр. 2026 г.
- CVE-2026-7344628Наблюдать
Security Advisory 0160
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %arista networks · eos15 сент. 2026 г.
- CVE-2026-3564027Наблюдать
OpenClaw < 2026.3.25 - Denial of Service via Unauthenticated Webhook Request Parsing
СредняяCVSS 6,9Эксплойта нетEPSS 1 %openclaw · openclaw9 апр. 2026 г.
- CVE-2026-3562727Наблюдать
OpenClaw < 2026.3.22 - Unauthenticated Cryptographic Work in Nostr Inbound DM Handling
СредняяCVSS 6,9Эксплойта нетEPSS 1 %openclaw · openclaw9 апр. 2026 г.
- CVE-2026-3565227Наблюдать
OpenClaw < 2026.3.22 - Unauthorized Action Execution via Callback Dispatch
СредняяCVSS 6,9Эксплойта нетEPSS 1 %openclaw · openclaw10 апр. 2026 г.
- CVE-2026-6721727Наблюдать
cJSON JSON Patch Non-Atomic Application Destroys Data Before Validation
СредняяCVSS 6,9Эксплойта нетEPSS 0 %davegamble · cjson29 июл. 2026 г.
- CVE-2026-3563727Наблюдать
OpenClaw < 2026.3.22 - Premature Cite Expansion Before Authorization in Channel and DM
СредняяCVSS 6,9Эксплойта нетEPSS 0 %openclaw · openclaw9 апр. 2026 г.
- CVE-2025-5511427Наблюдать
BMC Control-M/Agent improper IP address filtering order
СредняяCVSS 6,9Эксплойта нетEPSS 0 %bmc · control-m/agent16 сент. 2025 г.
- CVE-2025-990427Наблюдать
Unallocated memory access vulnerability in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / Gener
СредняяCVSS 6,9Эксплойта нетEPSS 0 %canon inc. · generic plus pcl6 printer driver28 сент. 2025 г.
- CVE-2024-3038927Наблюдать
Junos OS: EX4300 Series: Firewall filter not blocking egress traffic
СредняяCVSS 6,9Эксплойта нетEPSS 0 %juniper · junos12 апр. 2024 г.
- CVE-2024-3041027Наблюдать
Junos OS: EX4300 Series: Loopback filter not blocking traffic despite having discard term.
СредняяCVSS 6,9Эксплойта нетEPSS 0 %juniper · junos12 апр. 2024 г.
- CVE-2026-4491926Наблюдать
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///
СредняяCVSS 6,5Эксплойта нетEPSS 1 %openstack · ironic13 мая 2026 г.
- CVE-2025-015026Наблюдать
Zoom Workplace Apps for iOS - Incorrect Behavior Order
СредняяCVSS 6,5Эксплойта нетEPSS 0 %zoom · meeting software development kit11 мар. 2025 г.