CWE-840: CWE-840
Yearly Trend
Top Affected Vendors
All CWE-840 CVEs (25)
CVE-2022-32207 is a privilege escalation vulnerability in curl versions before 7.84.0 where file permission widening occurs during atomic file operati...
Jul 7, 2022This CVE describes an access control vulnerability in Huawei's security verification module that could allow unauthorized access to sensitive informat...
Jul 25, 2024This vulnerability allows attackers to bypass Bluetooth authentication on certain Huawei Smart Screen products, potentially accessing restricted funct...
Dec 6, 2023This vulnerability in GitLab EE/CE allows attackers to track users' browsing activities through a flaw that could lead to full account takeover. It af...
Apr 24, 2025libcurl incorrectly reuses TLS/SSH connections when security settings have changed, potentially allowing sensitive data to be transmitted over less se...
Jun 2, 2022This vulnerability allows attackers to trick libcurl applications into using a malicious client certificate instead of the intended one when running i...
Aug 5, 2021This vulnerability in Snipe-IT allows attackers to bypass authentication by reusing old sessions even after the login enable function is activated. It...
Mar 30, 2022The Gallery module in affected Huawei products contains an EXTRA_REFERRER resource read vulnerability that allows unauthorized access to sensitive inf...
Aug 6, 2025This CVE describes an information management vulnerability in Huawei's Gallery module that could allow unauthorized access to sensitive information. T...
Nov 5, 2024This CVE describes an S3 bucket takeover vulnerability in the h2oai/h2o-3 repository where the 'http://s3.amazonaws.com/h2o-training' bucket was vulne...
Apr 16, 2024This vulnerability in H2O allows attackers to take over S3 bucket URLs by exploiting a reference to a bucket that no longer exists. This affects syste...
Nov 16, 2023This CVE describes a cracking vulnerability in the OS security module of Huawei devices running HarmonyOS. Successful exploitation could allow attacke...
May 14, 2024This vulnerability in Keycloak's token exchange flow allows disabled users to obtain valid access and refresh tokens, enabling unauthorized access to ...
Jan 21, 2026A permission management vulnerability in Huawei device lock screen modules could allow unauthorized access to protected services. This affects Huawei ...
Mar 4, 2025This CVE describes a privilege escalation vulnerability in Huawei's NMS (Network Management System) module. Attackers could exploit this to gain eleva...
Jul 25, 2024A business logic error in certain Zoom Workplace applications allows unauthenticated attackers to access sensitive information via network access. Thi...
Feb 25, 2025This CVE describes a business logic error in Adobe Commerce that allows attackers to bypass security features and modify limited data without user int...
Feb 11, 2025A critical business logic vulnerability in ATM Banking 1.0 allows attackers with local access to manipulate deposit/withdrawal functions, potentially ...
Apr 28, 2025This vulnerability in Bdtask Bhojon Restaurant Management System allows attackers to manipulate checkout parameters (orggrandTotal/vat/service_charge/...
Jan 29, 2026This vulnerability in Bdtask Bhojon All-In-One Restaurant Management System allows attackers to manipulate price calculations through the add-to-cart ...
Jan 29, 2026This vulnerability in Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution 5 allows attackers to manipulate checkout parameters (orde...
Nov 16, 2025A business logic vulnerability in linlinjava litemall up to version 1.8.0 allows remote attackers to manipulate the 'litemall_express_freight_min' par...
Aug 15, 2025This vulnerability in the springboot-openai-chatgpt component allows remote attackers to manipulate the question counting functionality, potentially d...
Mar 15, 2025This vulnerability in the CoinGate PrestaShop plugin allows remote attackers to cause business logic errors in payment processing. It affects PrestaSh...
Oct 17, 2024A race condition vulnerability in Huawei's security control module could allow attackers to disrupt system availability through timing-based attacks. ...
Mar 5, 2026About CWE-840 (CWE-840)
Our database tracks 25 CVEs classified as CWE-840, with 2 rated critical and 9 rated high severity. The average CVSS score for CWE-840 vulnerabilities is 6.3.
External reference: View CWE-840 on MITRE CWE →
Monitor CWE-840 Vulnerabilities
Get alerted when new CWE-840 CVEs affect your infrastructure.
Start Monitoring Free