CWE-841 · 58 записей
Improper Enforcement of Behavioral Workflow
CVE этого класса
58 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
57В плане | CVE-2026-67279Готовый эксплойт | SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOSmikrotik · routeros · CWE-841 | Средняя6,9 | KEV | 1,0 % | 5 сент. 2026 г. |
39Наблюдать | CVE-2023-4181Эксплойта нет | SourceCodester Free Hospital Management System for Small Practices Redirect behavioral workflowmayurik · free hospital management system for small practices · CWE-841 | Критическая9,8 | — | 1,1 % | 6 авг. 2023 г. |
39Наблюдать | CVE-2026-3130Эксплойта нет | Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete perdevolutions · devolutions server · CWE-841 | Критическая9,8 | — | 0,5 % | 3 мар. 2026 г. |
36Наблюдать | CVE-2022-2105Эксплойта нет | Secheron SEPCOS Control and Protection Relaysecheron · sepcos control and protection relay firmware · CWE-841 | Критическая9,1 | — | 1,1 % | 24 июн. 2022 г. |
35Наблюдать | CVE-2026-95369Эксплойта нет | Inappropriate implementation in XML in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code google · chrome · CWE-841 | Высокая8,8 | — | 0,4 % | 6 дней назад |
35Наблюдать | CVE-2026-65126Эксплойта нет | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper enforcement of a behavioral workfnvidia · infra controller · CWE-841 | Высокая8,8 | — | 0,3 % | 22 сент. 2026 г. |
34Наблюдать | CVE-2026-43974Эксплойта нет | gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing server-driven protocol hijack and OOMninenines · gun · CWE-841 | Высокая8,7 | — | 0,6 % | 8 июн. 2026 г. |
34Наблюдать | CVE-2026-55763Эксплойта нет | Klever-Go: Percentage-transfer royalty skips the source debit at exactly-100% splitsklever-io · klever-go · CWE-841 | Высокая8,7 | — | 0,5 % | 28 авг. 2026 г. |
34Наблюдать | CVE-2026-34582Эксплойта нет | Botan has a TLS 1.3 certificate authentication bypassbotan project · botan · CWE-841 | Высокая8,7 | — | 0,4 % | 7 апр. 2026 г. |
34Наблюдать | CVE-2026-80195Эксплойта нет | Kimai before 2.63.0 Team Membership Removal via APIkimai · kimai · CWE-841 | Высокая8,7 | — | 0,4 % | 26 авг. 2026 г. |
34Наблюдать | CVE-2025-48479Эксплойта нет | FreeScout Has Business Logic Errorsfreescout · freescout · CWE-841 | Высокая8,5 | — | 0,3 % | 30 мая 2025 г. |
32Наблюдать | CVE-2026-41259Эксплойта нет | Mastodon: Insufficient verification of email addressesjoinmastodon · mastodon · CWE-841 | Высокая8,2 | — | 0,4 % | 23 апр. 2026 г. |
30Наблюдать | CVE-2022-1667Эксплойта нет | Secheron SEPCOS Control and Protection Relaysecheron · sepcos control and protection relay firmware · CWE-841 | Высокая7,5 | — | 1,3 % | 24 июн. 2022 г. |
30Наблюдать | CVE-2022-2102Эксплойта нет | Secheron SEPCOS Control and Protection Relaysecheron · sepcos control and protection relay firmware · CWE-841 | Высокая7,5 | — | 0,9 % | 24 июн. 2022 г. |
30Наблюдать | CVE-2024-46307Эксплойта нет | A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products.sparkshop · sparkshop · CWE-841 | Высокая7,5 | — | 0,5 % | 9 окт. 2024 г. |
30Наблюдать | CVE-2024-0410Эксплойта нет | Improper Enforcement of Behavioral Workflow in GitLabgitlab · gitlab · CWE-841 | Высокая7,7 | — | 0,5 % | 21 февр. 2024 г. |
30Наблюдать | CVE-2026-30574Эксплойта нет | A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file.senior-walter · web-based pharmacy product management system · CWE-841 | Высокая7,5 | — | 0,4 % | 27 мар. 2026 г. |
30Наблюдать | CVE-2026-79083Эксплойта нет | Improper enforcement of behavioral workflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised tgoogle · chrome · CWE-841 | Высокая7,5 | — | 0,4 % | 25 авг. 2026 г. |
29Наблюдать | CVE-2026-78135Эксплойта нет | libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine.strongswan · strongswan · CWE-841 | Высокая7,3 | — | 0,4 % | 10 сент. 2026 г. |
28Наблюдать | CVE-2025-48476Эксплойта нет | FreeScout Has Business Logic Errorsfreescout · freescout · CWE-841 | Высокая7,1 | — | 0,5 % | 30 мая 2025 г. |
28Наблюдать | CVE-2025-48477Эксплойта нет | FreeScout Has Business Logic Errorsfreescout · freescout · CWE-841 | Высокая7,1 | — | 0,5 % | 30 мая 2025 г. |
28Наблюдать | CVE-2025-48478Эксплойта нет | FreeScout Has Business Logic Errorsfreescout · freescout · CWE-841 | Высокая7,0 | — | 0,4 % | 30 мая 2025 г. |
28Наблюдать | CVE-2026-82406Эксплойта нет | Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplaceklever-io · klever-go · CWE-841 | Высокая7,1 | — | 0,3 % | 23 сент. 2026 г. |
28Наблюдать | CVE-2025-48480Эксплойта нет | FreeScout Has Business Logic Errorsfreescout · freescout · CWE-841 | Высокая7,0 | — | 0,3 % | 30 мая 2025 г. |
28Наблюдать | CVE-2025-52469Эксплойта нет | Chamilo: Friend Request Workflow Bypass - Unauthorized Friend Addition and ID Validation Bypasschamilo · chamilo lms · CWE-841 | Высокая7,1 | — | 0,3 % | 2 мар. 2026 г. |
- CVE-2026-6727957В плане
SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS
СредняяCVSS 6,9KEVГотовый эксплойтEPSS 1 %mikrotik · routeros5 сент. 2026 г.
- CVE-2023-418139Наблюдать
SourceCodester Free Hospital Management System for Small Practices Redirect behavioral workflow
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mayurik · free hospital management system for small practices6 авг. 2023 г.
- CVE-2026-313039Наблюдать
Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete per
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %devolutions · devolutions server3 мар. 2026 г.
- CVE-2022-210536Наблюдать
Secheron SEPCOS Control and Protection Relay
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %secheron · sepcos control and protection relay firmware24 июн. 2022 г.
- CVE-2026-9536935Наблюдать
Inappropriate implementation in XML in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %google · chrome6 дней назад
- CVE-2026-6512635Наблюдать
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper enforcement of a behavioral workf
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %nvidia · infra controller22 сент. 2026 г.
- CVE-2026-4397434Наблюдать
gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing server-driven protocol hijack and OOM
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %ninenines · gun8 июн. 2026 г.
- CVE-2026-5576334Наблюдать
Klever-Go: Percentage-transfer royalty skips the source debit at exactly-100% splits
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %klever-io · klever-go28 авг. 2026 г.
- CVE-2026-3458234Наблюдать
Botan has a TLS 1.3 certificate authentication bypass
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %botan project · botan7 апр. 2026 г.
- CVE-2026-8019534Наблюдать
Kimai before 2.63.0 Team Membership Removal via API
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %kimai · kimai26 авг. 2026 г.
- CVE-2025-4847934Наблюдать
FreeScout Has Business Logic Errors
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %freescout · freescout30 мая 2025 г.
- CVE-2026-4125932Наблюдать
Mastodon: Insufficient verification of email addresses
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %joinmastodon · mastodon23 апр. 2026 г.
- CVE-2022-166730Наблюдать
Secheron SEPCOS Control and Protection Relay
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %secheron · sepcos control and protection relay firmware24 июн. 2022 г.
- CVE-2022-210230Наблюдать
Secheron SEPCOS Control and Protection Relay
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %secheron · sepcos control and protection relay firmware24 июн. 2022 г.
- CVE-2024-4630730Наблюдать
A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %sparkshop · sparkshop9 окт. 2024 г.
- CVE-2024-041030Наблюдать
Improper Enforcement of Behavioral Workflow in GitLab
ВысокаяCVSS 7,7Эксплойта нетEPSS 0 %gitlab · gitlab21 февр. 2024 г.
- CVE-2026-3057430Наблюдать
A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %senior-walter · web-based pharmacy product management system27 мар. 2026 г.
- CVE-2026-7908330Наблюдать
Improper enforcement of behavioral workflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised t
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %google · chrome25 авг. 2026 г.
- CVE-2026-7813529Наблюдать
libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine.
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %strongswan · strongswan10 сент. 2026 г.
- CVE-2025-4847628Наблюдать
FreeScout Has Business Logic Errors
ВысокаяCVSS 7,1Эксплойта нетEPSS 1 %freescout · freescout30 мая 2025 г.
- CVE-2025-4847728Наблюдать
FreeScout Has Business Logic Errors
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %freescout · freescout30 мая 2025 г.
- CVE-2025-4847828Наблюдать
FreeScout Has Business Logic Errors
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %freescout · freescout30 мая 2025 г.
- CVE-2026-8240628Наблюдать
Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %klever-io · klever-go23 сент. 2026 г.
- CVE-2025-4848028Наблюдать
FreeScout Has Business Logic Errors
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %freescout · freescout30 мая 2025 г.
- CVE-2025-5246928Наблюдать
Chamilo: Friend Request Workflow Bypass - Unauthorized Friend Addition and ID Validation Bypass
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %chamilo · chamilo lms2 мар. 2026 г.