A feature, API, or function does not perform according to its specification.
Volume of CVEs assigned to CWE-440 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
41 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-41035CRITICAL In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods. | Oct 25, 2021 | 9.8 | 32 | NO | NO |
CVE-2026-8806HIGH Expected Behavior Violation vulnerability in Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP all versions allows a remote attacker to cause a denial- | Jun 19, 2026 | 8.7 | 30 | NO | NO |
CVE-2019-6569CRITICAL The monitor barrier of the affected products insufficiently blocks data from being forwarded over the mirror port into the mirrored network. An attacker could use this behavior to | Mar 26, 2019 | 9.1 | 29 | NO | NO |
CVE-2024-32971CRITICAL Apollo Router is a configurable, graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. The affected versions of Apollo Router contain a bug that | May 2, 2024 | 9.0 | 27 | NO | NO |
CVE-2019-5108MEDIUM An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by triggering AP to send IAPP location | Dec 23, 2019 | 6.5 | 27 | NO | NO |
CVE-2026-42534MEDIUM NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purpose and degrade resolution performance. Retransmits of the s | May 20, 2026 | 5.3 | 26 | NO | NO |
CVE-2025-8850HIGH In danny-avila/librechat version 0.7.9, there is an insecure API design issue in the 2-Factor Authentication (2FA) flow. The system allows users to disable 2FA without requiring a | Oct 30, 2025 | 8.8 | 25 | NO | NO |
CVE-2022-3281HIGH WAGO Series PFC100/PFC200, Series Touch Panel 600, Compact Controller CC100 and Edge Controller in multiple versions are prone to a loss of MAC-Address-Filtering after reboot. This | Oct 17, 2022 | 7.5 | 25 | NO | NO |
CVE-2018-12550HIGH When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use an ACL file, and that ACL file is empty, or contains only comments or blank lines, then Mosquitto will | Mar 27, 2019 | 8.1 | 25 | NO | NO |
CVE-2026-42752MEDIUM Unauthenticated Bypass Vulnerability in Stripe Payments <= 2.0.98 versions. | Jun 15, 2026 | 6.5 | 24 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.