CWE-684
25 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-684page 1 of 1
- CVE-2020-11054LOWCVSS 3.5EG 3.52020-05-07
In qutebrowser versions less than 1.11.1, reloading a page with certificate errors shows a green URL. After a certificate error was overridden by the user, qutebrowser displays the URL as yellow (colors.statusbar.url.warn.fg). However, whe…
- CVE-2022-23728MEDIUMCVSS 6.1EG 6.12022-01-21
Attacker can reset the device with AT Command in the process of rebooting the device. The LG ID is LVE-SMP-210011.
- CVE-2023-24845CRITICALCVSS 9.1EG 9.12023-08-08
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC, RUGGEDCOM i803, RUGGEDCOM i803NC, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM M2100NC, RUGGEDCOM …
- CVE-2023-4258HIGHCVSS 8.6EG 8.62023-09-25
In Bluetooth mesh implementation If provisionee has a public key that is sent OOB then during provisioning it can be sent back and will be accepted by provisionee.
- CVE-2023-5158MEDIUMCVSS 6.5EG 6.52023-09-25
A flaw was found in vringh_kiov_advance in drivers/vhost/vringh.c in the host side of a virtio ring in the Linux Kernel. This issue may result in a denial of service from guest to host via zero length descriptor.
- CVE-2023-5363HIGHCVSS 7.5EG 7.52023-10-25
Issue summary: A bug has been identified in the processing of key and initialisation vector (IV) lengths. This can lead to potential truncation or overruns during the initialisation of some symmetric ciphers. Impact summary: A truncation…
- CVE-2024-20317HIGHCVSS 7.4EG 7.42024-09-11
A vulnerability in the handling of specific Ethernet frames by Cisco IOS XR Software for various Cisco Network Convergence System (NCS) platforms could allow an unauthenticated, adjacent attacker to cause critical priority packets to be dr…
- CVE-2024-5005MEDIUMCVSS 4.3EG 4.32024-10-11
An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all versions starting from 17.3 before 17.3.5, all versions starting from 17.4 before 17.4.2 It was possible for guest users t…
- CVE-2024-50357CRITICALCVSS 9.8EG 9.82024-11-29
FutureNet NXR series routers provided by Century Systems Co., Ltd. have REST-APIs, which are configured as disabled in the initial (factory default) configuration. But, REST-APIs are unexpectedly enabled when the affected product is powere…
- CVE-2024-6425CRITICALCVSS 9.1EG 9.12024-07-01
Incorrect Provision of Specified Functionality vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can register user accounts without being authenticated from the route "/account/Register/" and in the parameter…
- CVE-2024-6502MEDIUMCVSS 5.7EG 5.72024-08-22
An issue was discovered in GitLab CE/EE affecting all versions starting from 8.2 prior to 17.1.6 starting from 17.2 prior to 17.2.4, and starting from 17.3 prior to 17.3.1, which allows an attacker to create a branch with the same name as …
- CVE-2024-8974LOWCVSS 2.6EG 2.62024-09-26
Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions it was possible to disclose to an unauthorised user the path of a private projec…
- CVE-2025-47227HIGHCVSS 7.5EG 7.52025-07-05
In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandled. Making both a GET and a POST request to login.php.is sufficient. An unauthenticated attacker can…
- CVE-2025-54567MEDIUMCVSS 4.2EG 4.22025-07-25
hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.
- CVE-2025-54568LOWCVSS 3.7EG 3.72025-07-25
Akamai Rate Control alpha before 2025 allows attackers to send requests above the stipulated thresholds because the rate is measured separately for each edge node.
- CVE-2025-55174LOWCVSS 3.2EG 3.22025-11-26
In KDE Skanpage before 25.08.0, an attempt at file overwrite can result in the contents of the new file at the beginning followed by the partial contents of the old file at the end, because of use of QIODevice::ReadWrite instead of QODevic…
- CVE-2025-58325HIGHCVSS 8.2EG 8.22025-10-14
An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0 through 7.0.15, 6.4 all versions may allow a local authenticated attacker to execute system comman…
- CVE-2025-66384HIGHCVSS 8.2EG 8.22025-11-28
app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, related to tmp_name.
- CVE-2026-34478HIGHCVSS 7.5EG 7.52026-04-10
Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CRLF sequences due to undocumented renames of security-releva…
- CVE-2026-35379LOWCVSS 3.3EG 3.32026-04-22
A logic error in the tr utility of uutils coreutils causes the program to incorrectly define the [:graph:] and [:print:] character classes. The implementation mistakenly includes the ASCII space character (0x20) in the [:graph:] class and …
- CVE-2026-35381LOWCVSS 3.3EG 3.32026-04-22
A logic error in the cut utility of uutils coreutils causes the utility to ignore the -s (only-delimited) flag when using the -z (null-terminated) and -d '' (empty delimiter) options together. The implementation incorrectly routes this spe…
- CVE-2026-40684MEDIUMCVSS 5.9EG 5.92026-04-30
In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.
- CVE-2026-40685MEDIUMCVSS 6.5EG 6.52026-04-30
In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of \ skipping.
- CVE-2026-42255HIGHCVSS 7.2EG 7.22026-04-26
Technitium DNS Server before 15.0 allows DNS traffic amplification via cyclic name server delegation.
- CVE-2026-44597LOWCVSS 3.7EG 3.72026-05-07
Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.
Map vulnerabilities like CWE-684 to your infrastructure
EchelonGraph correlates every CVE — across CWE-684 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →