Перейти к содержимому
Noroxi

CWE-841 · 58 записей

Improper Enforcement of Behavioral Workflow

CVE этого класса

58 записей

  • CVE-2026-67279
    57В плане

    SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS

    СредняяCVSS 6,9KEVГотовый эксплойтEPSS 1 %

    mikrotik · routeros5 сент. 2026 г.

  • CVE-2023-4181
    39Наблюдать

    SourceCodester Free Hospital Management System for Small Practices Redirect behavioral workflow

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    mayurik · free hospital management system for small practices6 авг. 2023 г.

  • CVE-2026-3130
    39Наблюдать

    Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete per

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    devolutions · devolutions server3 мар. 2026 г.

  • CVE-2022-2105
    36Наблюдать

    Secheron SEPCOS Control and Protection Relay

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    secheron · sepcos control and protection relay firmware24 июн. 2022 г.

  • CVE-2026-95369
    35Наблюдать

    Inappropriate implementation in XML in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    google · chrome6 дней назад

  • CVE-2026-65126
    35Наблюдать

    NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper enforcement of a behavioral workf

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    nvidia · infra controller22 сент. 2026 г.

  • CVE-2026-43974
    34Наблюдать

    gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing server-driven protocol hijack and OOM

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    ninenines · gun8 июн. 2026 г.

  • CVE-2026-55763
    34Наблюдать

    Klever-Go: Percentage-transfer royalty skips the source debit at exactly-100% splits

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    klever-io · klever-go28 авг. 2026 г.

  • CVE-2026-34582
    34Наблюдать

    Botan has a TLS 1.3 certificate authentication bypass

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    botan project · botan7 апр. 2026 г.

  • CVE-2026-80195
    34Наблюдать

    Kimai before 2.63.0 Team Membership Removal via API

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    kimai · kimai26 авг. 2026 г.

  • CVE-2025-48479
    34Наблюдать

    FreeScout Has Business Logic Errors

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    freescout · freescout30 мая 2025 г.

  • CVE-2026-41259
    32Наблюдать

    Mastodon: Insufficient verification of email addresses

    ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %

    joinmastodon · mastodon23 апр. 2026 г.

  • CVE-2022-1667
    30Наблюдать

    Secheron SEPCOS Control and Protection Relay

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    secheron · sepcos control and protection relay firmware24 июн. 2022 г.

  • CVE-2022-2102
    30Наблюдать

    Secheron SEPCOS Control and Protection Relay

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    secheron · sepcos control and protection relay firmware24 июн. 2022 г.

  • CVE-2024-46307
    30Наблюдать

    A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    sparkshop · sparkshop9 окт. 2024 г.

  • CVE-2024-0410
    30Наблюдать

    Improper Enforcement of Behavioral Workflow in GitLab

    ВысокаяCVSS 7,7Эксплойта нетEPSS 0 %

    gitlab · gitlab21 февр. 2024 г.

  • CVE-2026-30574
    30Наблюдать

    A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    senior-walter · web-based pharmacy product management system27 мар. 2026 г.

  • CVE-2026-79083
    30Наблюдать

    Improper enforcement of behavioral workflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised t

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    google · chrome25 авг. 2026 г.

  • CVE-2026-78135
    29Наблюдать

    libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine.

    ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %

    strongswan · strongswan10 сент. 2026 г.

  • CVE-2025-48476
    28Наблюдать

    FreeScout Has Business Logic Errors

    ВысокаяCVSS 7,1Эксплойта нетEPSS 1 %

    freescout · freescout30 мая 2025 г.

  • CVE-2025-48477
    28Наблюдать

    FreeScout Has Business Logic Errors

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    freescout · freescout30 мая 2025 г.

  • CVE-2025-48478
    28Наблюдать

    FreeScout Has Business Logic Errors

    ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %

    freescout · freescout30 мая 2025 г.

  • CVE-2026-82406
    28Наблюдать

    Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    klever-io · klever-go23 сент. 2026 г.

  • CVE-2025-48480
    28Наблюдать

    FreeScout Has Business Logic Errors

    ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %

    freescout · freescout30 мая 2025 г.

  • CVE-2025-52469
    28Наблюдать

    Chamilo: Friend Request Workflow Bypass - Unauthorized Friend Addition and ID Validation Bypass

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    chamilo · chamilo lms2 мар. 2026 г.

Все классы уязвимостей