CWE-841 · 58 kayıt
Improper Enforcement of Behavioral Workflow
Bu sınıftaki CVE’ler
58 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
57Planlayın | CVE-2026-67279Silahlaştırılmış | SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOSmikrotik · routeros · CWE-841 | Orta6,9 | KEV | %1,0 | 5 Eyl 2026 |
39İzleyin | CVE-2023-4181İstismar yok | SourceCodester Free Hospital Management System for Small Practices Redirect behavioral workflowmayurik · free hospital management system for small practices · CWE-841 | Kritik9,8 | — | %1,1 | 6 Ağu 2023 |
39İzleyin | CVE-2026-3130İstismar yok | Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete perdevolutions · devolutions server · CWE-841 | Kritik9,8 | — | %0,5 | 3 Mar 2026 |
36İzleyin | CVE-2022-2105İstismar yok | Secheron SEPCOS Control and Protection Relaysecheron · sepcos control and protection relay firmware · CWE-841 | Kritik9,1 | — | %1,1 | 24 Haz 2022 |
35İzleyin | CVE-2026-65126İstismar yok | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper enforcement of a behavioral workfnvidia · infra controller · CWE-841 | Yüksek8,8 | — | %0,3 | 22 Eyl 2026 |
35İzleyin | CVE-2026-95369İstismar yok | Inappropriate implementation in XML in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code google · chrome · CWE-841 | Yüksek8,8 | — | — | Bugün |
34İzleyin | CVE-2026-43974İstismar yok | gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing server-driven protocol hijack and OOMninenines · gun · CWE-841 | Yüksek8,7 | — | %0,6 | 8 Haz 2026 |
34İzleyin | CVE-2026-55763İstismar yok | Klever-Go: Percentage-transfer royalty skips the source debit at exactly-100% splitsklever-io · klever-go · CWE-841 | Yüksek8,7 | — | %0,5 | 28 Ağu 2026 |
34İzleyin | CVE-2026-34582İstismar yok | Botan has a TLS 1.3 certificate authentication bypassbotan project · botan · CWE-841 | Yüksek8,7 | — | %0,4 | 7 Nis 2026 |
34İzleyin | CVE-2026-80195İstismar yok | Kimai before 2.63.0 Team Membership Removal via APIkimai · kimai · CWE-841 | Yüksek8,7 | — | %0,4 | 26 Ağu 2026 |
34İzleyin | CVE-2025-48479İstismar yok | FreeScout Has Business Logic Errorsfreescout · freescout · CWE-841 | Yüksek8,5 | — | %0,3 | 30 May 2025 |
32İzleyin | CVE-2026-41259İstismar yok | Mastodon: Insufficient verification of email addressesjoinmastodon · mastodon · CWE-841 | Yüksek8,2 | — | %0,4 | 23 Nis 2026 |
30İzleyin | CVE-2022-1667İstismar yok | Secheron SEPCOS Control and Protection Relaysecheron · sepcos control and protection relay firmware · CWE-841 | Yüksek7,5 | — | %1,3 | 24 Haz 2022 |
30İzleyin | CVE-2022-2102İstismar yok | Secheron SEPCOS Control and Protection Relaysecheron · sepcos control and protection relay firmware · CWE-841 | Yüksek7,5 | — | %0,9 | 24 Haz 2022 |
30İzleyin | CVE-2024-46307İstismar yok | A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products.sparkshop · sparkshop · CWE-841 | Yüksek7,5 | — | %0,5 | 9 Eki 2024 |
30İzleyin | CVE-2024-0410İstismar yok | Improper Enforcement of Behavioral Workflow in GitLabgitlab · gitlab · CWE-841 | Yüksek7,7 | — | %0,5 | 21 Şub 2024 |
30İzleyin | CVE-2026-30574İstismar yok | A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file.senior-walter · web-based pharmacy product management system · CWE-841 | Yüksek7,5 | — | %0,4 | 27 Mar 2026 |
30İzleyin | CVE-2026-79083İstismar yok | Improper enforcement of behavioral workflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised tgoogle · chrome · CWE-841 | Yüksek7,5 | — | %0,4 | 25 Ağu 2026 |
29İzleyin | CVE-2026-78135İstismar yok | libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine.strongswan · strongswan · CWE-841 | Yüksek7,3 | — | %0,4 | 10 Eyl 2026 |
28İzleyin | CVE-2025-48476İstismar yok | FreeScout Has Business Logic Errorsfreescout · freescout · CWE-841 | Yüksek7,1 | — | %0,5 | 30 May 2025 |
28İzleyin | CVE-2025-48477İstismar yok | FreeScout Has Business Logic Errorsfreescout · freescout · CWE-841 | Yüksek7,1 | — | %0,5 | 30 May 2025 |
28İzleyin | CVE-2025-48478İstismar yok | FreeScout Has Business Logic Errorsfreescout · freescout · CWE-841 | Yüksek7,0 | — | %0,4 | 30 May 2025 |
28İzleyin | CVE-2026-82406İstismar yok | Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplaceklever-io · klever-go · CWE-841 | Yüksek7,1 | — | %0,3 | 6 gün önce |
28İzleyin | CVE-2025-48480İstismar yok | FreeScout Has Business Logic Errorsfreescout · freescout · CWE-841 | Yüksek7,0 | — | %0,3 | 30 May 2025 |
28İzleyin | CVE-2025-52469İstismar yok | Chamilo: Friend Request Workflow Bypass - Unauthorized Friend Addition and ID Validation Bypasschamilo · chamilo lms · CWE-841 | Yüksek7,1 | — | %0,3 | 2 Mar 2026 |
- CVE-2026-6727957Planlayın
SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS
OrtaCVSS 6,9KEVSilahlaştırılmışEPSS %1mikrotik · routeros5 Eyl 2026
- CVE-2023-418139İzleyin
SourceCodester Free Hospital Management System for Small Practices Redirect behavioral workflow
KritikCVSS 9,8İstismar yokEPSS %1mayurik · free hospital management system for small practices6 Ağu 2023
- CVE-2026-313039İzleyin
Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete per
KritikCVSS 9,8İstismar yokEPSS %1devolutions · devolutions server3 Mar 2026
- CVE-2022-210536İzleyin
Secheron SEPCOS Control and Protection Relay
KritikCVSS 9,1İstismar yokEPSS %1secheron · sepcos control and protection relay firmware24 Haz 2022
- CVE-2026-6512635İzleyin
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper enforcement of a behavioral workf
YüksekCVSS 8,8İstismar yokEPSS %0nvidia · infra controller22 Eyl 2026
- CVE-2026-9536935İzleyin
Inappropriate implementation in XML in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code
YüksekCVSS 8,8İstismar yokgoogle · chromeBugün
- CVE-2026-4397434İzleyin
gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing server-driven protocol hijack and OOM
YüksekCVSS 8,7İstismar yokEPSS %1ninenines · gun8 Haz 2026
- CVE-2026-5576334İzleyin
Klever-Go: Percentage-transfer royalty skips the source debit at exactly-100% splits
YüksekCVSS 8,7İstismar yokEPSS %1klever-io · klever-go28 Ağu 2026
- CVE-2026-3458234İzleyin
Botan has a TLS 1.3 certificate authentication bypass
YüksekCVSS 8,7İstismar yokEPSS %0botan project · botan7 Nis 2026
- CVE-2026-8019534İzleyin
Kimai before 2.63.0 Team Membership Removal via API
YüksekCVSS 8,7İstismar yokEPSS %0kimai · kimai26 Ağu 2026
- CVE-2025-4847934İzleyin
FreeScout Has Business Logic Errors
YüksekCVSS 8,5İstismar yokEPSS %0freescout · freescout30 May 2025
- CVE-2026-4125932İzleyin
Mastodon: Insufficient verification of email addresses
YüksekCVSS 8,2İstismar yokEPSS %0joinmastodon · mastodon23 Nis 2026
- CVE-2022-166730İzleyin
Secheron SEPCOS Control and Protection Relay
YüksekCVSS 7,5İstismar yokEPSS %1secheron · sepcos control and protection relay firmware24 Haz 2022
- CVE-2022-210230İzleyin
Secheron SEPCOS Control and Protection Relay
YüksekCVSS 7,5İstismar yokEPSS %1secheron · sepcos control and protection relay firmware24 Haz 2022
- CVE-2024-4630730İzleyin
A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products.
YüksekCVSS 7,5İstismar yokEPSS %0sparkshop · sparkshop9 Eki 2024
- CVE-2024-041030İzleyin
Improper Enforcement of Behavioral Workflow in GitLab
YüksekCVSS 7,7İstismar yokEPSS %0gitlab · gitlab21 Şub 2024
- CVE-2026-3057430İzleyin
A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file.
YüksekCVSS 7,5İstismar yokEPSS %0senior-walter · web-based pharmacy product management system27 Mar 2026
- CVE-2026-7908330İzleyin
Improper enforcement of behavioral workflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised t
YüksekCVSS 7,5İstismar yokEPSS %0google · chrome25 Ağu 2026
- CVE-2026-7813529İzleyin
libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine.
YüksekCVSS 7,3İstismar yokEPSS %0strongswan · strongswan10 Eyl 2026
- CVE-2025-4847628İzleyin
FreeScout Has Business Logic Errors
YüksekCVSS 7,1İstismar yokEPSS %1freescout · freescout30 May 2025
- CVE-2025-4847728İzleyin
FreeScout Has Business Logic Errors
YüksekCVSS 7,1İstismar yokEPSS %0freescout · freescout30 May 2025
- CVE-2025-4847828İzleyin
FreeScout Has Business Logic Errors
YüksekCVSS 7,0İstismar yokEPSS %0freescout · freescout30 May 2025
- CVE-2026-8240628İzleyin
Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace
YüksekCVSS 7,1İstismar yokEPSS %0klever-io · klever-go6 gün önce
- CVE-2025-4848028İzleyin
FreeScout Has Business Logic Errors
YüksekCVSS 7,0İstismar yokEPSS %0freescout · freescout30 May 2025
- CVE-2025-5246928İzleyin
Chamilo: Friend Request Workflow Bypass - Unauthorized Friend Addition and ID Validation Bypass
YüksekCVSS 7,1İstismar yokEPSS %0chamilo · chamilo lms2 Mar 2026