CWE-840
100 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-840page 1 of 2
- CVE-2022-4719CRITICALCVSS 9.8EG 9.82022-12-27
Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.5.
- CVE-2022-3363CRITICALCVSS 9.8EG 9.82022-10-26
Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.0a7.
- CVE-2022-32207CRITICALCVSS 9.8EG 9.82022-07-07
When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accident…
- CVE-2021-4171CRITICALCVSS 9.8EG 9.82022-01-17
calibre-web is vulnerable to Business Logic Errors
- CVE-2024-39671CRITICALCVSS 9.3EG 9.32024-07-25
Access control vulnerability in the security verification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2023-6514HIGHCVSS 8.8EG 8.82023-12-06
The Bluetooth module of some Huawei Smart Screen products has an identity authentication bypass vulnerability. Successful exploitation of this vulnerability may allow attackers to access restricted functions. Successful exploitation of…
- CVE-2022-0935HIGHCVSS 8.8EG 8.82022-04-07
Host Header injection in password Reset in GitHub repository livehelperchat/livehelperchat prior to 3.97.
- CVE-2023-6017HIGHCVSS 7.1EG 8.72023-11-16
H2O included a reference to an S3 bucket that no longer existed allowing an attacker to take over the S3 bucket URL.
- CVE-2024-54098HIGHCVSS 8.5EG 8.52024-12-12
Service logic error vulnerability in the system service module Impact: Successful exploitation of this vulnerability may affect service integrity.
- CVE-2019-3787HIGHCVSS 8.3EG 8.32019-06-19
Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending “unknown.org” to a user's email address when one is not provided and the user name does not contain an @ character. This domain is held by a private company, which le…
- CVE-2026-58558HIGHCVSS 7.8EG 7.82026-07-15
Permission control vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2025-1908HIGHCVSS 7.7EG 7.72025-04-24
An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potentially leading to full account take-over, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 b…
- CVE-2022-27782HIGHCVSS 7.5EG 7.52022-06-02
libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if …
- CVE-2022-0524HIGHCVSS 7.5EG 7.52022-02-08
Business Logic Errors in GitHub repository publify/publify prior to 9.2.7.
- CVE-2021-22926HIGHCVSS 7.5EG 7.52021-08-05
libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CURLOPT_SSLCERT` option (`--cert` with the command line tool).When libcurl is built to use the macOS native TLS library S…
- CVE-2022-1155HIGHCVSS 7.4EG 7.42022-03-30
Old sessions are not blocked by the login enable function. in GitHub repository snipe/snipe-it prior to 5.3.10.
- CVE-2025-54611HIGHCVSS 7.3EG 7.32025-08-06
EXTRA_REFERRER resource read vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2025-54606HIGHCVSS 7.3EG 7.32025-08-06
Status verification vulnerability in the lock screen module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
- CVE-2024-58043HIGHCVSS 7.3EG 7.32025-03-04
Permission bypass vulnerability in the window module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2021-4111HIGHCVSS 4.3EG 7.32021-12-15
yetiforcecrm is vulnerable to Business Logic Errors
- CVE-2024-51523HIGHCVSS 7.1EG 7.12024-11-05
Information management vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-1456HIGHCVSS 7.1EG 7.12024-04-16
An S3 bucket takeover vulnerability was identified in the h2oai/h2o-3 repository. The issue involves the S3 bucket 'http://s3.amazonaws.com/h2o-training', which was found to be vulnerable to unauthorized takeover.
- CVE-2026-1322MEDIUMCVSS 6.8EG 6.82026-05-14
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with a read_api scoped OAuth application to create …
- CVE-2024-32999MEDIUMCVSS 6.8EG 6.82024-05-14
Cracking vulnerability in the OS security module Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2024-56449MEDIUMCVSS 6.6EG 6.62025-01-08
Privilege escalation vulnerability in the Account module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-42034MEDIUMCVSS 6.6EG 6.62024-08-08
LaunchAnywhere vulnerability in the account module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2026-8738MEDIUMCVSS 6.5EG 6.52026-05-17
A security vulnerability has been detected in Sanluan PublicCMS 5.202506.d. Impacted is the function TradeOrderController.pay/TradePaymentController.pay/AccountGatewayComponent.pay of the file publiccms-trade/src/main/java/com/publiccms/co…
- CVE-2025-14559MEDIUMCVSS 6.5EG 6.52026-01-21
A flaw was found in the keycloak-services component of Keycloak. This vulnerability allows the issuance of access and refresh tokens for disabled users, leading to unauthorized use of previously revoked privileges, via a business logic vul…
- CVE-2025-6601MEDIUMCVSS 6.5EG 6.52025-10-27
GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions could have allowed authenticated users to gain unauthorized project access by exploiting the a…
- CVE-2023-6566MEDIUMCVSS 6.5EG 6.52023-12-07
Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.
- CVE-2023-3229MEDIUMCVSS 6.5EG 6.52023-06-14
Business Logic Errors in GitHub repository fossbilling/fossbilling prior to 0.5.0.
- CVE-2022-0514MEDIUMCVSS 6.5EG 6.52022-03-21
Business Logic Errors in GitHub repository crater-invoice/crater prior to 6.0.5.
- CVE-2021-36012MEDIUMCVSS 6.5EG 6.52021-09-01
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a business logic error in the placeOrder graphql mutation. An authenticated attacker can leverage this vulnerability to altar the…
- CVE-2021-22922MEDIUMCVSS 6.5EG 6.52021-08-05
When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file.The metalink XML file points out to the client how to get the same contentfrom a set of differ…
- CVE-2019-3789MEDIUMCVSS 6.5EG 6.52019-04-24
Cloud Foundry Routing Release, all versions prior to 0.188.0, contains a vulnerability that can hijack the traffic to route services hosted outside the platform. A user with space developer permissions can create a private domain that shad…
- CVE-2024-4046MEDIUMCVSS 6.4EG 6.42024-05-14
Cracking vulnerability in the OS security module Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2024-6577MEDIUMCVSS 6.3EG 6.32025-03-20
In the latest version of pytorch/serve, the script 'upload_results_to_s3.sh' references the S3 bucket 'benchmarkai-metrics-prod' without ensuring its ownership or confirming its accessibility. This could lead to potential security vulnerab…
- CVE-2025-2321MEDIUMCVSS 6.3EG 6.32025-03-15
A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5 and classified as critical. Affected by this issue is some unknown functionality of the file /api/mjkj-chat/cgform-api/addData/. The manipulation of the argument chat…
- CVE-2024-58046MEDIUMCVSS 6.2EG 6.22025-03-04
Permission management vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2026-41973MEDIUMCVSS 5.9EG 5.92026-06-09
Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-41968MEDIUMCVSS 5.9EG 5.92026-05-15
Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-41967MEDIUMCVSS 5.9EG 5.92026-05-15
Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-41961MEDIUMCVSS 5.9EG 5.92026-05-15
Permission control vulnerability in contacts. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2022-32208MEDIUMCVSS 5.9EG 5.92022-07-07
When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.
- CVE-2019-15608MEDIUMCVSS 5.9EG 5.92020-03-15
The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. This may lead to a cache pollution attack.
- CVE-2025-58289MEDIUMCVSS 5.5EG 5.92025-10-11
Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability.
- CVE-2023-3228MEDIUMCVSS 5.7EG 5.72023-06-14
Business Logic Errors in GitHub repository fossbilling/fossbilling prior to 0.5.0.
- CVE-2026-41966MEDIUMCVSS 5.6EG 5.62026-05-15
Permission control vulnerability in the smart sensing service. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2026-41965MEDIUMCVSS 5.6EG 5.62026-05-15
Use-After-Free (UAF) vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-41971MEDIUMCVSS 5.5EG 5.52026-05-15
Permission control vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Map vulnerabilities like CWE-840 to your infrastructure
EchelonGraph correlates every CVE — across CWE-840 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →