The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.
Volume of CVEs assigned to CWE-670 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
141 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-32896HIGH there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti | Jun 13, 2024 | 7.8 | 66 | YES | NO |
CVE-2026-38361HIGH Multiple unauthenticated denial-of-service (DoS) issues in fohrloop dash-uploader v0.1.0 through v0.7.0a2. The chunked-upload handler (dash_uploader/httprequesthandler.py, dash_upl | May 8, 2026 | 7.5 | 42 | NO | YES |
CVE-2020-9425HIGH An issue was discovered in includes/head.inc.php in rConfig before 3.9.4. An unauthenticated attacker can retrieve saved cleartext credentials via a GET request to settings.php. Be | Mar 20, 2020 | 7.5 | 42 | NO | YES |
CVE-2026-55276CRITICAL Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xm | Jun 29, 2026 | 9.1 | 41 | NO | NO |
CVE-2026-53404HIGH Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions w | Jun 29, 2026 | 7.3 | 36 | NO | NO |
CVE-2026-7656MEDIUM The IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr.c (handle_ra_input, handle_ns_input, handle_na_input) used an incorrect boolean expression that combined the RFC 4861 | Jun 29, 2026 | 6.8 | 34 | NO | NO |
CVE-2026-35414HIGH OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certai | Apr 2, 2026 | 8.1 | 33 | NO | NO |
CVE-2026-20171MEDIUM A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS | May 20, 2026 | 6.8 | 31 | NO | NO |
CVE-2022-21679CRITICAL Istio is an open platform to connect, manage, and secure microservices. In Istio 1.12.0 and 1.12.1 The authorization policy with hosts and notHosts might be accidentally bypassed f | Jan 19, 2022 | 9.8 | 31 | NO | NO |
CVE-2019-17192CRITICAL The WebRTC component in the Signal Private Messenger application through 4.47.7 for Android processes videoconferencing RTP packets before a callee chooses to answer a call, which | Oct 5, 2019 | 9.8 | 31 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.