Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.
Volume of CVEs assigned to CWE-436 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
123 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-63030CRITICAL WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (C | Jul 17, 2026 | 9.8 | 96 | YES | YES |
CVE-2025-25292CRITICAL ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 a | Mar 12, 2025 | 9.8 | 67 | NO | NO |
CVE-2025-48384HIGH Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading | Jul 8, 2025 | 8.0 | 66 | YES | NO |
CVE-2025-25291CRITICAL ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 a | Mar 12, 2025 | 9.8 | 53 | NO | YES |
CVE-2021-28474HIGH Microsoft SharePoint Server Remote Code Execution Vulnerability | May 11, 2021 | 8.8 | 53 | NO | NO |
CVE-2022-37436MEDIUM Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. I | Jan 17, 2023 | 5.3 | 50 | NO | NO |
CVE-2026-47767CRITICAL Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated | Jul 14, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-14198CRITICAL @fastify/middie versions 9.1.0 through 9.3.2 decode the encoded slash %2F inside path parameter values before matching middleware paths, while Fastify's underlying router preserves | Jul 1, 2026 | 9.1 | 39 | NO | NO |
CVE-2026-13676HIGH fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the | Jun 29, 2026 | 7.5 | 37 | NO | NO |
CVE-2026-41248CRITICAL Clerk JavaScript is the official JavaScript repository for Clerk authentication. createRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro can be bypassed by certain craft | Apr 24, 2026 | 9.1 | 37 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.