VYPR

CWE-841

Improper Enforcement of Behavioral Workflow

ClassIncomplete

Description

The product supports a session in which more than one behavior must be performed by an actor, but it does not properly ensure that the actor performs the behaviors in the required sequence.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (62)

page 2 of 4
  • CVE-2025-55682MedOct 14, 2025
    risk 0.40cvss 6.1epss 0.00

    Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

  • CVE-2025-55337MedOct 14, 2025
    risk 0.40cvss 6.1epss 0.00

    Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

  • CVE-2025-55332MedOct 14, 2025
    risk 0.40cvss 6.1epss 0.01

    Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

  • CVE-2025-55330MedOct 14, 2025
    risk 0.40cvss 6.1epss 0.01

    Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

  • CVE-2024-12543MedApr 21, 2025
    risk 0.38cvss epss 0.00

    User Enumeration and Data Integrity in Barcode functionality in OpenText Content Management versions 24.3-25.1on Windows and Linux allows a malicous authenticated attacker to potentially alter barcode attributes.

  • CVE-2025-13751MedDec 3, 2025
    risk 0.36cvss 5.5epss 0.00

    Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated user to connect to the service and trigger an error causing a local denial of service.

  • CVE-2024-44128MedSep 17, 2024
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An Automator Quick Action workflow may be able to bypass Gatekeeper.

  • CVE-2022-46710MedJan 10, 2024
    risk 0.36cvss 5.5epss 0.00

    A logic issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Location data may be shared via iCloud links even if Location metadata is disabled via the Share Sheet.

  • CVE-2026-46540MedJun 10, 2026
    risk 0.35cvss 6.5epss 0.00

    Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, when LightBlockchain::rebranch() adopts a fork chain whose tip is a macro block (checkpoint or election), it only updates self.head but fails…

  • CVE-2026-45023MedMay 28, 2026
    risk 0.35cvss 5.4epss 0.00

    AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.59, POST /api/blocks/{block_id}/execute endpoint executes blocks without consuming any credits, regardless of the user's balance. The credit…

  • CVE-2025-58051MedOct 16, 2025
    risk 0.35cvss 6.5epss 0.01

    Nextcloud Tables allows you to create your own tables with individual columns. Prior 0.7.6, 0.8.8, and 0.9.5, when importing a table, a user was able to specify files on the server and when their format is supported by the used PhpSpreadsheet library they would be included and…

  • CVE-2023-4181MedAug 6, 2023
    risk 0.35cvss 5.4epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester Free Hospital Management System for Small Practices 1.0. Affected by this issue is some unknown functionality of the file /vm/admin/delete-doctor.php?id=2 of the component Redirect Handler. The…

  • CVE-2023-1383MedMay 3, 2023
    risk 0.35cvss 5.4epss 0.00

    An Improper Enforcement of Behavioral Workflow vulnerability in the exchangeDeviceServices function on the amzn.dmgr service allowed an attacker to register services that are only locally accessible. This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. …

  • CVE-2023-0105MedJan 13, 2023
    risk 0.35cvss 6.5epss 0.01

    A flaw was found in Keycloak. This flaw allows impersonation and lockout due to the email trust not being handled correctly in Keycloak. An attacker can shadow other users with the same email and lockout or impersonate them.

  • CVE-2026-13223MedJun 25, 2026
    risk 0.34cvss epss 0.00

    Our payment integration with Computop-based payment methods did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid …

  • CVE-2026-13222MedJun 25, 2026
    risk 0.34cvss epss 0.00

    Our payment integration with Oppwa-based payment methods did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid …

  • CVE-2024-6128MedJun 18, 2024
    risk 0.34cvss 5.3epss 0.01

    A vulnerability, which was classified as problematic, has been found in spa-cartcms 1.9.0.6. This issue affects some unknown processing of the file /checkout of the component Checkout Page. The manipulation of the argument quantity with the input -10 leads to enforcement of…

  • CVE-2026-42303MedMay 12, 2026
    risk 0.33cvss epss 0.00

    Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both subject identity verification and duplicate privacy request detection are affected by a vulnerability in which an administrator can approve a privacy request…

  • CVE-2026-19213MedAug 7, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in WonderTrader up to 0.9.9. Affected is the function _undone_qty in the library src/WtCore/TraderAdapter.h of the component Pending Order Handler. The manipulation of the argument getUndoneQty leads to enforcement of behavioral workflow. The…

  • CVE-2026-19037MedAug 6, 2026
    risk 0.28cvss 4.3epss 0.00

    A weakness has been identified in WonderTrader up to 0.9.9. This vulnerability affects the function MatchEngine::update_lob of the file src/WtBtCore/MatchEngine.cpp of the component Internal Limit Order Book Cache Handler. This manipulation causes enforcement of behavioral…