The product does not properly return control flow to the proper location after it has completed a task or detected an unusual condition.
Volume of CVEs assigned to CWE-705 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-3262HIGH A vulnerability has been found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected is an unknown function of the component Administrative Interfa | Feb 26, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-3264HIGH A vulnerability was determined in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. Affected by this issue is some unknown functionality of the component Administr | Feb 26, 2026 | 8.8 | 27 | NO | NO |
CVE-2026-10271MEDIUM A flaw has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The affected element is an unknown function of the file admin/ of the compon | Jun 1, 2026 | 6.3 | 25 | NO | NO |
CVE-2025-53856HIGH When a virtual server, network address translation (NAT) object, or secure network address translation (SNAT) object uses the embedded Packet Velocity Acceleration (ePVA) feature, | Oct 15, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-9848HIGH A security vulnerability has been detected in ScriptAndTools Real Estate Management System 1.0. The affected element is an unknown function of the file /admin/userlist.php. Such ma | Sep 3, 2025 | 7.5 | 25 | NO | NO |
An attacker might be able to delay the processing of DoH3 queries by sending DoH3 GET queries with an invalid DATA frame. | Jun 25, 2026 | 3.7 | 23 | NO | NO |
CVE-2024-45433MEDIUM OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Incorrect Control Flow Scoping. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of p | Sep 12, 2025 | 6.5 | 23 | NO | NO |
Versions of the package @tootallnate/once before 3.0.1 are vulnerable to Incorrect Control Flow Scoping in promise resolving when AbortSignal option is used. The Promise remains in | Mar 3, 2026 | 3.3 | 17 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.