CWE-837 · 18 записей
Improper Enforcement of a Single, Unique Action
CVE этого класса
18 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2026-105850Эксплойта нет | Payload: Order confirmation validation issue in Payload Ecommercepayloadcms · payload · CWE-837 | Высокая8,8 | — | 0,3 % | 2 дня назад |
30Наблюдать | CVE-2023-6759Эксплойта нет | Thecosy IceCMS Love resource improper enforcement of a single, unique actionthecosy · icecms · CWE-837 | Высокая7,5 | — | 1,0 % | 13 дек. 2023 г. |
30Наблюдать | CVE-2026-44601Эксплойта нет | Tor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because of a double close of a circuit, aka TROtorproject · tor · CWE-837 | Высокая7,5 | — | 0,6 % | 7 мая 2026 г. |
28Наблюдать | CVE-2025-54315Эксплойта нет | The Matrix specification before 1.16 (i.e., with a room version before 12) lacks create event uniqueness.matrix · matrix specification · CWE-837 | Высокая7,1 | — | 0,3 % | 2 окт. 2025 г. |
26Наблюдать | CVE-2024-4629Эксплойта нет | Keycloak: potential bypass of brute force protectionredhat · keycloak · CWE-837 | Средняя6,5 | — | 0,8 % | 3 сент. 2024 г. |
26Наблюдать | CVE-2024-11301Эксплойта нет | Improper Enforcement of Unique Constraint in lunary-ai/lunarylunary · lunary · CWE-837 | Средняя6,5 | — | 0,6 % | 20 мар. 2025 г. |
26Наблюдать | CVE-2025-58135Эксплойта нет | Zoom Workplace Clients for Windows - Improper Action Enforcementzoom · meeting software development kit · CWE-837 | Средняя6,5 | — | 0,3 % | 9 сент. 2025 г. |
26Наблюдать | GHSA-8wm9-24qg-m5qjЭксплойта нет | Duplicate Advisory: Keycloak has a brute force login protection bypassMaven · org.keycloak:keycloak-services · CWE-837 | Средняя6,5 | — | — | 3 сент. 2024 г. |
25Наблюдать | CVE-2024-11717Эксплойта нет | Tokens in CTFd used for account activation and password resetting can be used interchangeably for these operations.ctfd · ctfd · CWE-837 | Средняя6,3 | — | 0,7 % | 2 янв. 2025 г. |
24Наблюдать | CVE-2024-11716Эксплойта нет | While assignment of a user to a team (bracket) in CTFd should be possible only once, at the registration, a flaw in logic implementation alctfd · ctfd · CWE-837 | Средняя5,3 | — | 11,7 % | 2 янв. 2025 г. |
23Наблюдать | CVE-2025-62782Эксплойта нет | InventoryGUI vulnerable to item duplication via Bundle items when using GuiStorageElementphoenix616 · inventorygui · CWE-837 | Средняя5,9 | — | 0,3 % | 27 окт. 2025 г. |
21Наблюдать | CVE-2023-6438Эксплойта нет | Thecosy IceCMS Like improper enforcement of a single, unique actionthecosy · icecms · CWE-837 | Средняя5,3 | — | 0,7 % | 30 нояб. 2023 г. |
21Наблюдать | CVE-2026-45734Эксплойта нет | MyBB: Default CAPTCHA missing invalidationmybb · mybb · CWE-837 | Средняя5,3 | — | 0,6 % | 18 авг. 2026 г. |
21Наблюдать | CVE-2025-62784Эксплойта нет | InventoryGui allows item duplication in GUIs which use GuiStorageElementphoenix616 · inventorygui · CWE-837 | Средняя5,3 | — | 0,2 % | 27 окт. 2025 г. |
17Наблюдать | CVE-2025-62783Эксплойта нет | InventoryGui affected by item duplication in GUIs which use GuiStorageElementphoenix616 · inventorygui · CWE-837 | Средняя4,3 | — | 0,3 % | 27 окт. 2025 г. |
14Наблюдать | CVE-2023-6467Эксплойта нет | Thecosy IceCMS Comment Like improper enforcement of a single, unique actionthecosy · icecms · CWE-837 | Низкая3,7 | — | 0,6 % | 2 дек. 2023 г. |
14Наблюдать | CVE-2023-5313Эксплойта нет | phpkobo Ajax Poll Script ajax-poll.php improper enforcement of a single, unique actionphpkobo · ajax poll script · CWE-837 | Низкая3,7 | — | 0,6 % | 30 сент. 2023 г. |
9Наблюдать | CVE-2026-86198Эксплойта нет | PocketMine-MP before 5.44.2 Denial of Service via ResourcePackClientResponsePacketpmmp · pocketmine-mp · CWE-837 | Низкая2,3 | — | 0,4 % | 9 сент. 2026 г. |
- CVE-2026-10585035Наблюдать
Payload: Order confirmation validation issue in Payload Ecommerce
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %payloadcms · payload2 дня назад
- CVE-2023-675930Наблюдать
Thecosy IceCMS Love resource improper enforcement of a single, unique action
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %thecosy · icecms13 дек. 2023 г.
- CVE-2026-4460130Наблюдать
Tor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because of a double close of a circuit, aka TRO
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %torproject · tor7 мая 2026 г.
- CVE-2025-5431528Наблюдать
The Matrix specification before 1.16 (i.e., with a room version before 12) lacks create event uniqueness.
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %matrix · matrix specification2 окт. 2025 г.
- CVE-2024-462926Наблюдать
Keycloak: potential bypass of brute force protection
СредняяCVSS 6,5Эксплойта нетEPSS 1 %redhat · keycloak3 сент. 2024 г.
- CVE-2024-1130126Наблюдать
Improper Enforcement of Unique Constraint in lunary-ai/lunary
СредняяCVSS 6,5Эксплойта нетEPSS 1 %lunary · lunary20 мар. 2025 г.
- CVE-2025-5813526Наблюдать
Zoom Workplace Clients for Windows - Improper Action Enforcement
СредняяCVSS 6,5Эксплойта нетEPSS 0 %zoom · meeting software development kit9 сент. 2025 г.
- GHSA-8wm9-24qg-m5qj26Наблюдать
Duplicate Advisory: Keycloak has a brute force login protection bypass
СредняяCVSS 6,5Эксплойта нетMaven · org.keycloak:keycloak-services3 сент. 2024 г.
- CVE-2024-1171725Наблюдать
Tokens in CTFd used for account activation and password resetting can be used interchangeably for these operations.
СредняяCVSS 6,3Эксплойта нетEPSS 1 %ctfd · ctfd2 янв. 2025 г.
- CVE-2024-1171624Наблюдать
While assignment of a user to a team (bracket) in CTFd should be possible only once, at the registration, a flaw in logic implementation al
СредняяCVSS 5,3Эксплойта нетEPSS 12 %ctfd · ctfd2 янв. 2025 г.
- CVE-2025-6278223Наблюдать
InventoryGUI vulnerable to item duplication via Bundle items when using GuiStorageElement
СредняяCVSS 5,9Эксплойта нетEPSS 0 %phoenix616 · inventorygui27 окт. 2025 г.
- CVE-2023-643821Наблюдать
Thecosy IceCMS Like improper enforcement of a single, unique action
СредняяCVSS 5,3Эксплойта нетEPSS 1 %thecosy · icecms30 нояб. 2023 г.
- CVE-2026-4573421Наблюдать
MyBB: Default CAPTCHA missing invalidation
СредняяCVSS 5,3Эксплойта нетEPSS 1 %mybb · mybb18 авг. 2026 г.
- CVE-2025-6278421Наблюдать
InventoryGui allows item duplication in GUIs which use GuiStorageElement
СредняяCVSS 5,3Эксплойта нетEPSS 0 %phoenix616 · inventorygui27 окт. 2025 г.
- CVE-2025-6278317Наблюдать
InventoryGui affected by item duplication in GUIs which use GuiStorageElement
СредняяCVSS 4,3Эксплойта нетEPSS 0 %phoenix616 · inventorygui27 окт. 2025 г.
- CVE-2023-646714Наблюдать
Thecosy IceCMS Comment Like improper enforcement of a single, unique action
НизкаяCVSS 3,7Эксплойта нетEPSS 1 %thecosy · icecms2 дек. 2023 г.
- CVE-2023-531314Наблюдать
phpkobo Ajax Poll Script ajax-poll.php improper enforcement of a single, unique action
НизкаяCVSS 3,7Эксплойта нетEPSS 1 %phpkobo · ajax poll script30 сент. 2023 г.
- CVE-2026-861989Наблюдать
PocketMine-MP before 5.44.2 Denial of Service via ResourcePackClientResponsePacket
НизкаяCVSS 2,3Эксплойта нетEPSS 0 %pmmp · pocketmine-mp9 сент. 2026 г.