The code does not function according to its published specifications, potentially leading to incorrect usage.
Volume of CVEs assigned to CWE-684 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-40685CRITICAL In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incor | Apr 30, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-44597CRITICAL Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011. | May 7, 2026 | 9.1 | 34 | NO | NO |
CVE-2026-40684HIGH In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a | Apr 30, 2026 | 7.5 | 31 | NO | NO |
CVE-2026-34478HIGH Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CR | Apr 10, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-42255MEDIUM Technitium DNS Server before 15.0 allows DNS traffic amplification via cyclic name server delegation. | Apr 26, 2026 | 6.5 | 28 | NO | NO |
CVE-2025-66384HIGH app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, related to tmp_name. | Nov 28, 2025 | 8.2 | 27 | NO | NO |
CVE-2024-50357CRITICAL FutureNet NXR series routers provided by Century Systems Co., Ltd. have REST-APIs, which are configured as disabled in the initial (factory default) configuration. But, REST-APIs a | Nov 29, 2024 | 9.8 | 27 | NO | NO |
CVE-2025-58325MEDIUM An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0 through 7.0.15, 6.4 all versions may al | Oct 14, 2025 | 6.7 | 26 | NO | NO |
CVE-2024-6425CRITICAL Incorrect Provision of Specified Functionality vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can register user accounts without being authenticat | Jul 1, 2024 | 9.1 | 26 | NO | NO |
CVE-2023-5363HIGH Issue summary: A bug has been identified in the processing of key and
initialisation vector (IV) lengths. This can lead to potential truncation
or overruns during the initialisati | Oct 25, 2023 | 7.5 | 26 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.