CWE-670

Always-Incorrect Control Flow Implementation

Parent: CWE-691 - Insufficient Control Flow Management

The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.

130 vulnerabilities with CWE-670
CVE-2025-29312 CRITICAL
onos <2.7.0 - Info Disclosure
CVSS 9.1
CVE-2025-24800 CRITICAL
ismp-grandpa <15.0.1 - RCE
CVE-2025-21607 HIGH
Vyper - Code Injection
CVSS 7.5
CVE-2024-53271 HIGH
Envoy <1.31.5-1.32.3 - DoS
CVSS 7.1
CVE-2024-53270 HIGH
Envoy - Use After Free
CVSS 7.5
CVE-2024-53269 MEDIUM
Envoy <1.32.2-1.30.8 - DoS
CVSS 4.5
CVE-2024-53134 MEDIUM
Linux Kernel - Buffer Overflow
CVSS 5.5
CVE-2024-52811 HIGH
Ngtcp2 - Buffer Overflow
CVSS 8.2
CVE-2024-8811 HIGH
WinZip - Info Disclosure
CVSS 7.8
CVE-2024-30133 MEDIUM
HCL Traveler for Microsoft Outlook - Control Flow Vulnerability
CVSS 5.3
CVE-2024-47745 HIGH
Linux kernel - Privilege Escalation
CVSS 7.8
CVE-2024-38365 HIGH
btcd <0.24 - Consensus Failure
CVSS 7.4
CVE-2024-25622 LOW
h2o - Info Disclosure
CVSS 3.1
CVE-2024-47168 MEDIUM
Gradio - Info Disclosure
CVSS 4.3
CVE-2024-47763 MEDIUM
Wasmtime - Runtime Crash
CVSS 5.5
CVE-2024-20480 HIGH
Cisco IOS XE - DoS
CVSS 8.6
CVE-2024-45807 HIGH
Envoy <1.31 - DoS
CVSS 7.5
CVE-2024-45298 MEDIUM
Wiki.js - Auth Bypass
CVSS 4.3
CVE-2024-45311 HIGH
Quinn-proto <0.11 - Code Injection
CVSS 7.5
CVE-2024-45304 MEDIUM
Cairo-Contracts - Privilege Escalation
CVSS 5.3
CVE-2024-5659 MEDIUM
Rockwell Automation - DoS
CVSS 6.5
CVE-2024-32896 HIGH KEV
Logic Error - Privilege Escalation
CVSS 7.8
CVE-2024-37153 HIGH
Evmos - Info Disclosure
CVSS 7.5
CVE-2024-35195 MEDIUM
Requests <2.32.0 - Info Disclosure
CVSS 5.6
CVE-2024-35312 MEDIUM
Tor Arti <1.2.3 - Info Disclosure
CVSS 6.2
Details
Vulnerabilities 130