CWE-840: CWE-840

25
Total CVEs
2
Critical
9
High
6.3
Avg CVSS

Yearly Trend

2026
4
2025
9
2024
6
2023
2
2022
3

Top Affected Vendors

1 Huawei 8
2 Haxx 3
3 Bdtask 3
4 Splunk 3
5 H2o 2
6 Netapp 2
7 Debian 2
8 Zoom 1
9 Linlinjava 1
10 Gitlab 1

All CWE-840 CVEs (25)

CVE-2022-32207
9.8

CVE-2022-32207 is a privilege escalation vulnerability in curl versions before 7.84.0 where file permission widening occurs during atomic file operati...

Jul 7, 2022
CVE-2024-39671
9.3

This CVE describes an access control vulnerability in Huawei's security verification module that could allow unauthorized access to sensitive informat...

Jul 25, 2024
CVE-2023-6514
8.8

This vulnerability allows attackers to bypass Bluetooth authentication on certain Huawei Smart Screen products, potentially accessing restricted funct...

Dec 6, 2023
CVE-2025-1908
7.7

This vulnerability in GitLab EE/CE allows attackers to track users' browsing activities through a flaw that could lead to full account takeover. It af...

Apr 24, 2025
CVE-2022-27782
7.5

libcurl incorrectly reuses TLS/SSH connections when security settings have changed, potentially allowing sensitive data to be transmitted over less se...

Jun 2, 2022
CVE-2021-22926
7.5

This vulnerability allows attackers to trick libcurl applications into using a malicious client certificate instead of the intended one when running i...

Aug 5, 2021
CVE-2022-1155
7.4

This vulnerability in Snipe-IT allows attackers to bypass authentication by reusing old sessions even after the login enable function is activated. It...

Mar 30, 2022
CVE-2025-54611
7.3

The Gallery module in affected Huawei products contains an EXTRA_REFERRER resource read vulnerability that allows unauthorized access to sensitive inf...

Aug 6, 2025
CVE-2024-51523
7.1

This CVE describes an information management vulnerability in Huawei's Gallery module that could allow unauthorized access to sensitive information. T...

Nov 5, 2024
CVE-2024-1456
7.1

This CVE describes an S3 bucket takeover vulnerability in the h2oai/h2o-3 repository where the 'http://s3.amazonaws.com/h2o-training' bucket was vulne...

Apr 16, 2024
CVE-2023-6017
7.1

This vulnerability in H2O allows attackers to take over S3 bucket URLs by exploiting a reference to a bucket that no longer exists. This affects syste...

Nov 16, 2023
CVE-2024-32999
6.8

This CVE describes a cracking vulnerability in the OS security module of Huawei devices running HarmonyOS. Successful exploitation could allow attacke...

May 14, 2024
CVE-2025-14559
6.5

This vulnerability in Keycloak's token exchange flow allows disabled users to obtain valid access and refresh tokens, enabling unauthorized access to ...

Jan 21, 2026
CVE-2024-58046
6.2

A permission management vulnerability in Huawei device lock screen modules could allow unauthorized access to protected services. This affects Huawei ...

Mar 4, 2025
CVE-2023-7271
5.5

This CVE describes a privilege escalation vulnerability in Huawei's NMS (Network Management System) module. Attackers could exploit this to gain eleva...

Jul 25, 2024
CVE-2024-45424
5.3

A business logic error in certain Zoom Workplace applications allows unauthenticated attackers to access sensitive information via network access. Thi...

Feb 25, 2025
CVE-2025-24425
5.3

This CVE describes a business logic error in Adobe Commerce that allows attackers to bypass security features and modify limited data without user int...

Feb 11, 2025
CVE-2025-4037
4.4

A critical business logic vulnerability in ATM Banking 1.0 allows attackers with local access to manipulate deposit/withdrawal functions, potentially ...

Apr 28, 2025
CVE-2026-1599
4.3

This vulnerability in Bdtask Bhojon Restaurant Management System allows attackers to manipulate checkout parameters (orggrandTotal/vat/service_charge/...

Jan 29, 2026
CVE-2026-1600
4.3

This vulnerability in Bdtask Bhojon All-In-One Restaurant Management System allows attackers to manipulate price calculations through the add-to-cart ...

Jan 29, 2026
CVE-2025-13239
4.3

This vulnerability in Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution 5 allows attackers to manipulate checkout parameters (orde...

Nov 16, 2025
CVE-2025-8991
4.3

A business logic vulnerability in linlinjava litemall up to version 1.8.0 allows remote attackers to manipulate the 'litemall_express_freight_min' par...

Aug 15, 2025
CVE-2025-2323
4.3

This vulnerability in the springboot-openai-chatgpt component allows remote attackers to manipulate the question counting functionality, potentially d...

Mar 15, 2025
CVE-2018-25104
4.3

This vulnerability in the CoinGate PrestaShop plugin allows remote attackers to cause business logic errors in payment processing. It affects PrestaSh...

Oct 17, 2024
CVE-2026-28550
4.0

A race condition vulnerability in Huawei's security control module could allow attackers to disrupt system availability through timing-based attacks. ...

Mar 5, 2026

About CWE-840 (CWE-840)

Our database tracks 25 CVEs classified as CWE-840, with 2 rated critical and 9 rated high severity. The average CVSS score for CWE-840 vulnerabilities is 6.3.

External reference: View CWE-840 on MITRE CWE →

Monitor CWE-840 Vulnerabilities

Get alerted when new CWE-840 CVEs affect your infrastructure.

Start Monitoring Free