CWE-670
Always-Incorrect Control Flow Implementation
The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.
134 vulnerabilities with CWE-670
CVE-2025-38291
MEDIUM
Linux Kernel 6.13-6.15.2 - Denial of Service via WMI Command During Firmware Crash
CVSS 5.5
CVE-2025-49091
HIGH
KDE Konsole < 25.04.2 - Remote Code Execution via URL Scheme Handler Fallback
CVSS 8.2
CVE-2025-32996
MEDIUM
http-proxy-middleware <2.0.8, <3.0.4 - Info Disclosure
CVSS 4.0
CVE-2025-2886
MEDIUM
Amazon Tough < 0.20.0 - Incorrect Target Source Validation via Delegation Chain
CVSS 4.5
CVE-2025-29312
CRITICAL
ONOS v2.7.0 - Always-Incorrect Control Flow Implementation via Link Type Change
CVSS 9.1
CVE-2025-24800
CRITICAL
ismp-grandpa < 15.0.1 - Improper Verification of Cryptographic Signature
CVE-2025-21607
HIGH
vyperlang/vyper < 0.4.1 - Always-Incorrect Control Flow Implementation in EcRecover and Identity Precompiles
CVSS 7.5
CVE-2024-53271
HIGH
Envoy 1.31.0-1.31.4 - Denial of Service via HTTP 1.1 Non-101 1xx Response Handling
CVSS 7.1
CVE-2024-53270
HIGH
envoyproxy/envoy < 1.29.12 - Denial of Service via Null Pointer Dereference in sendOverloadError
CVSS 7.5
CVE-2024-53269
MEDIUM
Envoy 1.30.0-1.30.7 - Denial of Service via Happy Eyeballs Address Sorting
CVSS 4.5
CVE-2024-53134
MEDIUM
Linux Kernel 6.1-6.6.62 - Denial of Service via Incorrect Loop Condition in imx93-blk-ctrl Remove Path
CVSS 5.5
CVE-2024-52811
HIGH
ngtcp2 1.9.0 - Heap Buffer Overflow via Invalid ACK Frame in qlog
CVSS 8.2
CVE-2024-8811
HIGH
WinZip < 76.8 - Mark-of-the-Web Protection Mechanism Bypass via Archive Extraction
CVSS 7.8
CVE-2024-30133
MEDIUM
HCL Traveler for Microsoft Outlook - Control Flow Vulnerability
CVSS 5.3
CVE-2024-47745
HIGH
Linux kernel - Privilege Escalation
CVSS 7.8
CVE-2024-38365
HIGH
btcd 0.10.0-0.24.1 - Consensus Failure via Incorrect FindAndDelete Implementation
CVSS 7.4
CVE-2024-25622
LOW
h2o - Info Disclosure
CVSS 3.1
CVE-2024-47168
MEDIUM
gradio < 4.44.0 - Unauthenticated Data Exposure via Monitoring Endpoint
CVSS 4.3
CVE-2024-47763
MEDIUM
Wasmtime 12.0.0-20.0.x (tail calls enabled) and 21.0.0-25.0.1 - Denial of Service via Tail Call Stack Trace Capture
CVSS 5.5
CVE-2024-20480
HIGH
Cisco IOS XE - Denial of Service via DHCP Snooping IPv4 Packet Handling
CVSS 8.6
CVE-2024-45807
HIGH
Envoy 1.31.0-1.31.1 - Denial of Service via oghttp2 Stream Management
CVSS 7.5
CVE-2024-45298
MEDIUM
Wiki.js 2.5.303 - Account Disabling Bypass via Password Reset
CVSS 4.3
CVE-2024-45311
HIGH
quinn 0.11.0-0.11.3 and quinn-proto 0.11.0-0.11.6 - Denial of Service via Unvalidated Connection Retry
CVSS 7.5
CVE-2024-45304
MEDIUM
Cairo-Contracts - Privilege Escalation
CVSS 5.3
CVE-2024-5659
MEDIUM
Rockwell Automation ControlLogix 5580 Firmware - Denial of Service via mDNS Packet
CVSS 6.5
Details
Vulnerabilities
134