Auto-created placeholder
Volume of CVEs assigned to CWE-840 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
89 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3363CRITICAL Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.0a7. | Oct 26, 2022 | 9.8 | 32 | NO | NO |
CVE-2026-58558HIGH Permission control vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Jul 15, 2026 | 7.8 | 31 | NO | NO |
CVE-2021-4171CRITICAL calibre-web is vulnerable to Business Logic Errors | Jan 17, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-22926HIGH libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CURLOPT_SSLCERT` option (`--cert` with the command line tool). | Aug 5, 2021 | 7.5 | 29 | NO | NO |
CVE-2022-0935HIGH Host Header injection in password Reset in GitHub repository livehelperchat/livehelperchat prior to 3.97. | Apr 7, 2022 | 8.8 | 28 | NO | NO |
CVE-2026-1322HIGH GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticat | May 14, 2026 | 8.1 | 27 | NO | NO |
CVE-2022-4719CRITICAL Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.5. | Dec 27, 2022 | 9.8 | 27 | NO | NO |
CVE-2026-41973MEDIUM Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability. | Jun 9, 2026 | 5.9 | 26 | NO | NO |
CVE-2022-32207CRITICAL When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final t | Jul 7, 2022 | 9.8 | 26 | NO | NO |
CVE-2022-27782HIGH libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connection | Jun 2, 2022 | 7.5 | 26 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.