CWE-840 · 100 записей
Business Logic Errors
CVE этого класса
100 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2022-32207Эксплойта нет | When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a renhaxx · curl · CWE-840 | Критическая9,8 | — | 7,7 % | 7 июл. 2022 г. |
39Наблюдать | CVE-2021-4171Эксплойта нет | Business Logic Errors in janeczku/calibre-webjaneczku · calibre-web · CWE-840 | Критическая9,8 | — | 1,4 % | 17 янв. 2022 г. |
39Наблюдать | CVE-2022-4719Эксплойта нет | Business Logic Errors in ikus060/rdiffwebikus-soft · rdiffweb · CWE-840 | Критическая9,8 | — | 1,0 % | 27 дек. 2022 г. |
39Наблюдать | CVE-2022-3363Эксплойта нет | Business Logic Errors in ikus060/rdiffwebikus-soft · rdiffweb · CWE-840 | Критическая9,8 | — | 0,8 % | 26 окт. 2022 г. |
35Наблюдать | CVE-2022-0935Эксплойта нет | Host Header injection in password Reset in livehelperchat/livehelperchatlivehelperchat · live helper chat · CWE-840 | Высокая8,8 | — | 1,3 % | 7 апр. 2022 г. |
35Наблюдать | CVE-2019-3787Эксплойта нет | UAA defaults email address to an insecure domainpivotal software · cloud foundry uaa-release · CWE-840 | Высокая8,8 | — | 1,1 % | 19 июн. 2019 г. |
35Наблюдать | CVE-2025-2938Эксплойта нет | Business Logic Errors in GitLabgitlab · gitlab · CWE-840 | Высокая8,8 | — | 0,3 % | 26 июн. 2025 г. |
35Наблюдать | CVE-2023-6514Эксплойта нет | The Bluetooth module of some Huawei Smart Screen products has an identity authentication bypass vulnerability.huawei · ajmd-370s firmware · CWE-840 | Высокая8,8 | — | 0,3 % | 6 дек. 2023 г. |
33Наблюдать | CVE-2021-22926Эксплойта нет | libcurl-using applications can ask for a specific client certificate to be used in a transfer.haxx · curl · CWE-840 | Высокая7,5 | — | 9,8 % | 5 авг. 2021 г. |
32Наблюдать | CVE-2026-1322Эксплойта нет | Business Logic Errors in GitLabgitlab · gitlab · CWE-840 | Высокая8,1 | — | 0,3 % | 14 мая 2026 г. |
31Наблюдать | CVE-2022-27782Эксплойта нет | libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.haxx · curl · CWE-840 | Высокая7,5 | — | 2,9 % | 2 июн. 2022 г. |
31Наблюдать | CVE-2026-58558Эксплойта нет | Permission control vulnerability in the file system.huawei · harmony os · CWE-840 | Высокая7,8 | — | 0,1 % | 15 июл. 2026 г. |
30Наблюдать | CVE-2022-0524Эксплойта нет | Business Logic Errors in publify/publifypublify project · publify · CWE-840 | Высокая7,5 | — | 1,6 % | 8 февр. 2022 г. |
30Наблюдать | CVE-2024-2267Эксплойта нет | keerti1924 Online-Book-Store-Website shop.php logic errorkeerti1924 · online bookstore website · CWE-840 | Высокая7,5 | — | 0,5 % | 7 мар. 2024 г. |
30Наблюдать | CVE-2025-1908Эксплойта нет | Business Logic Errors in GitLabgitlab · gitlab · CWE-840 | Высокая7,7 | — | 0,4 % | 24 апр. 2025 г. |
30Наблюдать | CVE-2024-45424Эксплойта нет | Zoom Workplace Apps - Business Logic Errorzoom · meeting software development kit · CWE-840 | Высокая7,5 | — | 0,4 % | 25 февр. 2025 г. |
30Наблюдать | CVE-2024-51523Эксплойта нет | Information management vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confidenhuawei · harmonyos · CWE-840 | Высокая7,5 | — | 0,2 % | 5 нояб. 2024 г. |
30Наблюдать | CVE-2024-54098Эксплойта нет | Service logic error vulnerability in the system service module Impact: Successful exploitation of this vulnerability may affect service intehuawei · emui · CWE-840 | Высокая7,5 | — | 0,2 % | 12 дек. 2024 г. |
30Наблюдать | CVE-2024-56449Эксплойта нет | Privilege escalation vulnerability in the Account module Impact: Successful exploitation of this vulnerability may affect service confidentihuawei · emui · CWE-840 | Высокая7,5 | — | 0,2 % | 8 янв. 2025 г. |
29Наблюдать | CVE-2022-1155Эксплойта нет | Old sessions are not blocked by the login enable function. in snipe/snipe-itsnipeitapp · snipe-it · CWE-840 | Высокая7,4 | — | 1,0 % | 30 мар. 2022 г. |
28Наблюдать | CVE-2023-6017Эксплойта нет | H2O S3 Bucket Takeoverh2o · h2o · CWE-840 | Высокая7,1 | — | 0,9 % | 16 нояб. 2023 г. |
28Наблюдать | CVE-2024-1456Эксплойта нет | S3 Bucket Takeover in h2oai/h2o-3h2o · h2o · CWE-840 | Высокая7,1 | — | 0,2 % | 15 апр. 2024 г. |
28Наблюдать | CVE-2025-54606Эксплойта нет | Status verification vulnerability in the lock screen module.huawei · harmonyos · CWE-840 | Высокая7,1 | — | 0,1 % | 5 авг. 2025 г. |
27Наблюдать | CVE-2021-22922Эксплойта нет | When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML haxx · curl · CWE-840 | Средняя6,5 | — | 4,3 % | 5 авг. 2021 г. |
27Наблюдать | CVE-2021-36012Эксплойта нет | Magento Commerce Gift Card Business Logic Erroradobe · adobe commerce · CWE-840 | Средняя6,5 | — | 2,0 % | 1 сент. 2021 г. |
- CVE-2022-3220741В плане
When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a ren
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %haxx · curl7 июл. 2022 г.
- CVE-2021-417139Наблюдать
Business Logic Errors in janeczku/calibre-web
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %janeczku · calibre-web17 янв. 2022 г.
- CVE-2022-471939Наблюдать
Business Logic Errors in ikus060/rdiffweb
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ikus-soft · rdiffweb27 дек. 2022 г.
- CVE-2022-336339Наблюдать
Business Logic Errors in ikus060/rdiffweb
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ikus-soft · rdiffweb26 окт. 2022 г.
- CVE-2022-093535Наблюдать
Host Header injection in password Reset in livehelperchat/livehelperchat
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %livehelperchat · live helper chat7 апр. 2022 г.
- CVE-2019-378735Наблюдать
UAA defaults email address to an insecure domain
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %pivotal software · cloud foundry uaa-release19 июн. 2019 г.
- CVE-2025-293835Наблюдать
Business Logic Errors in GitLab
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %gitlab · gitlab26 июн. 2025 г.
- CVE-2023-651435Наблюдать
The Bluetooth module of some Huawei Smart Screen products has an identity authentication bypass vulnerability.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %huawei · ajmd-370s firmware6 дек. 2023 г.
- CVE-2021-2292633Наблюдать
libcurl-using applications can ask for a specific client certificate to be used in a transfer.
ВысокаяCVSS 7,5Эксплойта нетEPSS 10 %haxx · curl5 авг. 2021 г.
- CVE-2026-132232Наблюдать
Business Logic Errors in GitLab
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %gitlab · gitlab14 мая 2026 г.
- CVE-2022-2778231Наблюдать
libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %haxx · curl2 июн. 2022 г.
- CVE-2026-5855831Наблюдать
Permission control vulnerability in the file system.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %huawei · harmony os15 июл. 2026 г.
- CVE-2022-052430Наблюдать
Business Logic Errors in publify/publify
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %publify project · publify8 февр. 2022 г.
- CVE-2024-226730Наблюдать
keerti1924 Online-Book-Store-Website shop.php logic error
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %keerti1924 · online bookstore website7 мар. 2024 г.
- CVE-2025-190830Наблюдать
Business Logic Errors in GitLab
ВысокаяCVSS 7,7Эксплойта нетEPSS 0 %gitlab · gitlab24 апр. 2025 г.
- CVE-2024-4542430Наблюдать
Zoom Workplace Apps - Business Logic Error
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %zoom · meeting software development kit25 февр. 2025 г.
- CVE-2024-5152330Наблюдать
Information management vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confiden
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %huawei · harmonyos5 нояб. 2024 г.
- CVE-2024-5409830Наблюдать
Service logic error vulnerability in the system service module Impact: Successful exploitation of this vulnerability may affect service inte
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %huawei · emui12 дек. 2024 г.
- CVE-2024-5644930Наблюдать
Privilege escalation vulnerability in the Account module Impact: Successful exploitation of this vulnerability may affect service confidenti
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %huawei · emui8 янв. 2025 г.
- CVE-2022-115529Наблюдать
Old sessions are not blocked by the login enable function. in snipe/snipe-it
ВысокаяCVSS 7,4Эксплойта нетEPSS 1 %snipeitapp · snipe-it30 мар. 2022 г.
- CVE-2023-601728Наблюдать
H2O S3 Bucket Takeover
ВысокаяCVSS 7,1Эксплойта нетEPSS 1 %h2o · h2o16 нояб. 2023 г.
- CVE-2024-145628Наблюдать
S3 Bucket Takeover in h2oai/h2o-3
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %h2o · h2o15 апр. 2024 г.
- CVE-2025-5460628Наблюдать
Status verification vulnerability in the lock screen module.
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %huawei · harmonyos5 авг. 2025 г.
- CVE-2021-2292227Наблюдать
When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML
СредняяCVSS 6,5Эксплойта нетEPSS 4 %haxx · curl5 авг. 2021 г.
- CVE-2021-3601227Наблюдать
Magento Commerce Gift Card Business Logic Error
СредняяCVSS 6,5Эксплойта нетEPSS 2 %adobe · adobe commerce1 сент. 2021 г.