VYPR

CWE-841

Improper Enforcement of Behavioral Workflow

ClassIncomplete

Description

The product supports a session in which more than one behavior must be performed by an actor, but it does not properly ensure that the actor performs the behaviors in the required sequence.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (76)

page 1 of 4
  • CVE-2026-30783CriMar 5, 2026
    risk 0.64cvss 9.8epss 0.00

    A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Client signaling, API sync loop, config management modules) allows Privilege Abuse. This vulnerability is associated with program files…

  • CVE-2026-3130CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete permission to delete a PAM account that is currently checked out by selecting it alongside at least one non-checked-out account and…

  • CVE-2025-48481CriMay 30, 2025
    risk 0.64cvss 9.8epss 0.01

    FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an attacker with an unactivated email invitation containing invite_hash, can exploit this vulnerability to self-activate their account, despite it being blocked or deleted, by leveraging the…

  • CVE-2022-2105CriJun 24, 2022
    risk 0.61cvss 9.4epss 0.01

    Client-side JavaScript controls may be bypassed to change user credentials and permissions without authentication, including a “root” user level meant only for the vendor. Web server root level access allows for changing of safety critical parameters.

  • CVE-2022-2102CriJun 24, 2022
    risk 0.61cvss 9.4epss 0.01

    Controls limiting uploads to certain file extensions may be bypassed. This could allow an attacker to intercept the initial file upload page response and modify the associated code. This modified code can be forwarded and used by a script loaded later in the sequence, allowing…

  • CVE-2025-48476HigMay 30, 2025
    risk 0.57cvss 8.8epss 0.01

    FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when adding and editing user records using the fill() method, there is no check for the absence of the password field in the data coming from the user, which leads to a mass-assignment…

  • CVE-2026-67279MedKEVSep 5, 2026
    risk 0.54cvss 6.5epss 0.01

    RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling…

  • CVE-2025-48477HigMay 30, 2025
    risk 0.53cvss 8.1epss 0.00

    FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application's logic requires the user to perform a correct sequence of actions to implement a functional capability, but the application allows access to the functional capability without…

  • CVE-2026-34582CriApr 7, 2026
    risk 0.52cvss 9.1epss 0.00

    Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client authentication via certificates can by bypassed…

  • CVE-2026-55763HigAug 28, 2026
    risk 0.50cvss —epss 0.01

    Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, processPercentageRoyaltiesTransfer in core/kapp/accounts/accounts.go calls SubFromBalance after the split loop and after the royaltiesToPay <= 0 early return. computeSplitRoyalties rejects…

  • CVE-2026-43937HigMay 12, 2026
    risk 0.50cvss 8.8epss 0.01

    YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5, Any admin OnPost… handler executes its side effects before the ResultFilterAttribute rewrites the response to a 302 to /Info/4. The most impactful abuse is /Admin/RunSql, whose OnPostRunQuery binds Editor…

  • CVE-2024-0410HigFeb 22, 2024
    risk 0.50cvss 7.7epss 0.00

    An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer could bypass CODEOWNERS approvals by creating a merge conflict.

  • CVE-2026-79083HigAug 25, 2026
    risk 0.49cvss 7.5epss 0.00

    Improper enforcement of behavioral workflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-30574HigMar 27, 2026
    risk 0.49cvss 7.5epss 0.00

    A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file. The application fails to verify if the requested sales quantity (txtqty) exceeds the available stock level. An attacker can manipulate the request to…

  • CVE-2024-46307HigOct 9, 2024
    risk 0.49cvss 7.5epss 0.00

    A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products.

  • CVE-2022-1667HigJun 24, 2022
    risk 0.49cvss 7.5epss 0.01

    Client-side JavaScript controls may be bypassed by directly running a JS function to reboot the PLC (e.g., from the browser console) or by loading the corresponding, browser accessible PHP script

  • CVE-2026-48505HigJun 22, 2026
    risk 0.48cvss 7.4epss 0.00

    Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, a flaw in the handling of recovery codes for app-based multi-factor authentication allows the same recovery code to be reused via concurrent submission. This…

  • CVE-2023-5921HigNov 22, 2023
    risk 0.46cvss 7.1epss 0.00

    Improper Enforcement of Behavioral Workflow vulnerability in DECE Software Geodi allows Functionality Bypass. This issue affects Geodi: before 8.0.0.27396.

  • CVE-2026-78618MedAug 28, 2026
    risk 0.45cvss —epss 0.00

    A business logic flaw in WatchGuard Dimension allows an authenticated administrator to trigger multiple backend operations within a single logical flow by sending a specially crafted request.

  • CVE-2026-87503MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.00

    Inappropriate implementation in Downloads in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)