CWE-670— Always-Incorrect Control Flow Implementation
The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.— MITRE CWE catalog
162 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-670page 1 of 4
- CVE-2024-32896CRITICALCVSS 7.8EG 9.0⚠ KEV2024-06-13
there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
- CVE-2026-96760CRITICALCVSS 9.8EG 9.82026-09-28
Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for…
- CVE-2025-43359CRITICALCVSS 9.8EG 9.82025-09-15
A logic issue was addressed with improved state management. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. A UDP server socket…
- CVE-2022-25745CRITICALCVSS 9.8EG 9.82023-04-13
Memory corruption in modem due to improper input validation while handling the incoming CoAP message
- CVE-2020-1914CRITICALCVSS 9.8EG 9.82020-10-08
A logic vulnerability when handling the SaveGeneratorLong instruction in Facebook Hermes prior to commit b2021df620824627f5a8c96615edbd1eb7fdddfc allows attackers to potentially read out of bounds or theoretically execute arbitrary code vi…
- CVE-2020-17466CRITICALCVSS 9.8EG 9.82020-08-11
Turcom TRCwifiZone through 2020-08-10 allows authentication bypass by visiting manage/control.php and ignoring 302 Redirect responses.
- CVE-2019-17192CRITICALCVSS 9.8EG 9.82019-10-05
The WebRTC component in the Signal Private Messenger application through 4.47.7 for Android processes videoconferencing RTP packets before a callee chooses to answer a call, which might make it easier for remote attackers to cause a denial…
- CVE-2025-24800CRITICALCVSS 9.3EG 9.32025-01-28
Hyperbridge is a hyper-scalable coprocessor for verifiable, cross-chain interoperability. A critical vulnerability was discovered in the ismp-grandpa crate, that allowed a malicious prover easily convince the verifier of the finality of ar…
- CVE-2026-16392CRITICALCVSS 9.1EG 9.12026-07-21
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
- CVE-2026-55276CRITICALCVSS 9.1EG 9.12026-06-29
Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged. This issue affects Apache Tomcat: from 11.0.…
- CVE-2025-29312CRITICALCVSS 9.1EG 9.12025-03-24
An issue in onos v2.7.0 allows attackers to trigger unexpected behavior within a device connected to a legacy switch via changing the link type from indirect to direct.
- CVE-2024-32971CRITICALCVSS 9.0EG 9.02024-05-02
Apollo Router is a configurable, graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. The affected versions of Apollo Router contain a bug that in limited circumstances, could lead to unexpected operati…
- CVE-2023-31211HIGHCVSS 8.8EG 8.82024-01-12
Insufficient authentication flow in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows attacker to use locked credentials
- CVE-2023-20558HIGHCVSS 8.8EG 8.82023-04-02
Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to an escalation of privileges.
- CVE-2018-16766HIGHCVSS 8.8EG 8.82018-09-10
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because Errors::unreachable() is reached.
- CVE-2021-41153HIGHCVSS 8.7EG 8.72021-10-18
The evm crate is a pure Rust implementation of Ethereum Virtual Machine. In `evm` crate `< 0.31.0`, `JUMPI` opcode's condition is checked after the destination validity check. However, according to Geth and OpenEthereum, the condition chec…
- CVE-2024-20480HIGHCVSS 8.6EG 8.62024-09-25
A vulnerability in the DHCP Snooping feature of Cisco IOS XE Software on Software-Defined Access (SD-Access) fabric edge nodes could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting i…
- CVE-2022-2993HIGHCVSS 8.6EG 8.62022-12-09
There is an error in the condition of the last if-statement in the function smp_check_keys. It was rejecting current keys if all requirements were unmet.
- CVE-2025-49091HIGHCVSS 8.2EG 8.22025-06-11
KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme handlers such as a ssh:// or telnet:// or rlogin:// URL. This can be executed regardless of whether the ssh, telnet, or…
- CVE-2024-52811HIGHCVSS 8.2EG 8.22024-11-25
The ngtcp2 project is an effort to implement IETF QUIC protocol in C. In affected versions acks are not validated before being written to the qlog leading to a buffer overflow. In `ngtcp2_conn::conn_recv_pkt` for an ACK, there was new logi…
- CVE-2023-1668HIGHCVSS 8.2EG 8.22023-04-10
A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a…
- CVE-2022-36278HIGHCVSS 8.2EG 8.22023-02-16
Insufficient control flow management in the Intel(R) Battery Life Diagnostic Tool software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-29255HIGHCVSS 8.2EG 8.22022-06-09
Vyper is a Pythonic Smart Contract Language for the ethereum virtual machine. In versions prior to 0.3.4 when a calling an external contract with no return value, the contract address (including side effects) could be evaluated twice. This…
- CVE-2023-0400HIGHCVSS 5.9EG 8.22023-02-02
The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local user to bypass DLP controls when uploading sensitive data from a mapped drive into a web email client. Loading from a loca…
- CVE-2026-40960HIGHCVSS 8.1EG 8.12026-04-16
Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as secure.trusted_mods or secure.http_mods, then a crafted mod can intercept the request for the insecure environment or HT…
- CVE-2026-40200HIGHCVSS 8.1EG 8.12026-04-10
An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven mil…
- CVE-2026-35414HIGHCVSS 8.1EG 8.12026-04-02
OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.
- CVE-2024-8811HIGHCVSS 7.8EG 7.82024-11-22
WinZip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of WinZip. User interaction is required to exploit this vulnerability in t…
- CVE-2024-47745HIGHCVSS 7.8EG 7.82024-10-21
In the Linux kernel, the following vulnerability has been resolved: mm: call the security_mmap_file() LSM hook in remap_file_pages() The remap_file_pages syscall handler calls do_mmap() directly, which doesn't contain the LSM security ch…
- CVE-2023-20915HIGHCVSS 7.8EG 7.82023-01-26
In addOrReplacePhoneAccount of PhoneAccountRegistrar.java, there is a possible way to enable a phone account without user interaction due to a logic error in the code. This could lead to local escalation of privilege with no additional exe…
- CVE-2020-25603HIGHCVSS 7.8EG 7.82020-09-23
An issue was discovered in Xen through 4.14.x. There are missing memory barriers when accessing/allocating an event channel. Event channels control structures can be accessed lockless as long as the port is considered to be valid. Such a s…
- CVE-2017-0604HIGHCVSS 7.8EG 7.82017-05-12
An elevation of privilege vulnerability in the kernel Qualcomm power driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a …
- CVE-2022-27808HIGHCVSS 6.3EG 7.82023-02-16
Insufficient control flow management in some Intel(R) Ethernet Controller Administrative Tools drivers for Windows before version 1.5.0.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-30246HIGHCVSS 7.6EG 7.62024-03-29
Tuleap is an Open Source Suite to improve management of software developments and collaboration. A malicious user could exploit this issue on purpose to delete information on the instance or possibly gain access to restricted artifacts. It…
- CVE-2026-48844HIGHCVSS 7.5EG 7.52026-05-25
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)
- CVE-2026-38361HIGHCVSS 7.5EG 7.52026-05-08
Multiple unauthenticated denial-of-service (DoS) issues in fohrloop dash-uploader v0.1.0 through v0.7.0a2. The chunked-upload handler (dash_uploader/httprequesthandler.py, dash_uploader/upload.py) trusts unsanitized, attacker-controlled up…
- CVE-2026-40719HIGHCVSS 7.5EG 7.52026-04-15
Deadwood in MaraDNS 3.5.0036 allows attackers to exhaust connection slots via a zone whose authoritative nameserver address cannot be resolved.
- CVE-2026-34946HIGHCVSS 7.5EG 7.52026-04-09
Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler contains a vulnerability where the compilation of the table.fill instruction can result in a host panic. This means that a v…
- CVE-2025-58136HIGHCVSS 7.5EG 7.52026-04-02
A bug in POST request handling causes a crash under a certain condition. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12. Users are recommended to upgrade to version 10.1.2 or 9.2.13, which…
- CVE-2026-33011HIGHCVSS 7.5EG 7.52026-03-20
Nest is a framework for building scalable Node.js server-side applications. In versions 11.1.15 and below, a NestJS application using @nestjs/platform-fastify GET middleware can be bypassed because Fastify automatically redirects HEAD requ…
- CVE-2026-1874HIGHCVSS 7.5EG 7.52026-03-03
Always-Incorrect Control Flow Implementation vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP versions 1.106 and prior and Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-EI…
- CVE-2026-26267HIGHCVSS 7.5EG 7.52026-02-19
soroban-sdk is a Rust SDK for Soroban contracts. Prior to versions 22.0.10, 23.5.2, and 25.1.1, the `#[contractimpl]` macro contains a bug in how it wires up function calls. `#[contractimpl]` generates code that uses `MyContract::value()` …
- CVE-2025-21607HIGHCVSS 7.5EG 7.52025-01-14
Vyper is a Pythonic Smart Contract Language for the EVM. When the Vyper Compiler uses the precompiles EcRecover (0x1) and Identity (0x4), the success flag of the call is not checked. As a consequence an attacker can provide a specific amou…
- CVE-2024-53270HIGHCVSS 7.5EG 7.52024-12-18
Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions `sendOverloadError` is going to assume the active request exists when `envoy.load_shed_points.http1_server_abort_dispatch` is configured. If `active_r…
- CVE-2024-45807HIGHCVSS 7.5EG 7.52024-09-20
Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy's 1.31 is using `oghttp` as the default HTTP/2 codec, and there are potential bugs around stream management in the codec. To resolve this Envoy will switch off the `…
- CVE-2024-45311HIGHCVSS 7.5EG 7.52024-09-02
Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. As of quinn-proto 0.11, it is possible for a server to `accept()`, `retry()`, `refuse()`, or `ignore()` an `Incoming` connection. However, calling `…
- CVE-2024-37153HIGHCVSS 7.5EG 7.52024-06-06
Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. There is an issue with how to liquid stake using Safe which itself is a contract. The bug only appears when there is a local state change together with an ICS20 transfe…
- CVE-2023-49798HIGHCVSS 7.5EG 7.52023-12-09
OpenZeppelin Contracts is a library for smart contract development. A merge issue when porting the 5.0.1 patch to the 4.9 branch caused a line duplication. In the version of `Multicall.sol` released in `@openzeppelin/[email protected]` and `…
- CVE-2023-23623HIGHCVSS 7.5EG 7.52023-09-06
Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. A Content-Security-Policy that disables eval, specifically setting a `script-src` directive and _not_ providing `unsafe-eval` …
- CVE-2023-41058HIGHCVSS 7.5EG 7.52023-09-04
Parse Server is an open source backend server. In affected versions the Parse Cloud trigger `beforeFind` is not invoked in certain conditions of `Parse.Query`. This can pose a vulnerability for deployments where the `beforeFind` trigger is…
Map vulnerabilities like CWE-670 to your infrastructure
EchelonGraph correlates every CVE — across CWE-670 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →