Threats Tagged 'cwe-840'
View all threats tagged with 'cwe-840'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-840'
Click on any threat for detailed analysis and mitigation recommendations
The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebar layout becomes broken and can hide other items. Join the discussion | CVE Database V5 | 09/21/2026, 15:25:33 UTC Added: 09/21/2026, 15:32:23 UTC |
The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from approving or rejecting a file whose contents changed after they reviewed it. The backend only enforced this check when the etag parameter was present and non-empty in the request. An attacker able to intercept and modify the approval request could omit the etag field entirely, bypassing the freshness check and approving or rejecting a file version they never reviewed. Join the discussion | CVE Database V5 | 09/18/2026, 01:26:04 UTC Added: 09/18/2026, 19:47:08 UTC |
A vulnerability exists in macrozheng mall versions 1.0.0 through 1.0.3 in the Payment Status Endpoint (/order/paySuccess). The issue involves manipulation of the orderId argument, which can enforce unintended behavioral workflow remotely. The vendor has not provided a patch or explanation, and the GitHub issue was deleted without comment. The CVSS score is 5.4, indicating a low severity level with limited impact on confidentiality but some impact on integrity and availability. Join the discussion | GCVE Database | 08/30/2026, 00:30:21 UTC Added: 08/30/2026, 15:27:18 UTC |
CVE-2026-75081 is a medium severity vulnerability in Webkul Bagisto up to version 2.4.4. It involves manipulation of parameters (rma_qty, resolution_type, rma_reason_id) in the /customer/account/rma/store endpoint, resulting in enforcement of behavioral workflow. The vulnerability can be exploited remotely without user interaction. The vendor has acknowledged the issue, stating some fixes have been applied and others are planned for future releases. No public patch is currently confirmed. Join the discussion | GCVE Database | 08/17/2026, 23:45:08 UTC Added: 08/18/2026, 00:42:13 UTC |
A vulnerability exists in WonderTrader up to version 0.9.9 in the Pending Order Handler component, specifically in the _undone_qty function. The issue involves manipulation of the getUndoneQty argument, which can enforce unintended behavioral workflow. The vulnerability can be exploited remotely. Public exploit code is available. The vendor has not responded to disclosure requests. The CVSS score is 4.3, indicating a low severity impact. Join the discussion | GCVE Database | 08/07/2026, 17:30:39 UTC Added: 08/08/2026, 14:52:17 UTC |
A vulnerability exists in WonderTrader up to version 0.9.9 affecting the TraderDD::queryTrades function. The issue involves manipulation of the argument FID_JYLB, which can enforce behavioral workflow changes. The attack can be performed remotely but requires high complexity and is difficult to exploit. The vendor has not responded to disclosure, and no patch or fix information is available. The vulnerability has a low CVSS score of 3.7 and no known exploits in the wild. Join the discussion | GCVE Database | 08/07/2026, 15:00:54 UTC Added: 08/08/2026, 14:52:19 UTC |
Permission control vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect service confidentiality. Join the discussion | CVE Database V5 | 07/15/2026, 12:40:08 UTC Added: 07/15/2026, 13:03:54 UTC |
CVE-2026-41973 is a permission control vulnerability in Huawei HarmonyOS related to business logic errors (CWE-840). Successful exploitation may impact system availability. The vulnerability has a medium severity with a CVSS score of 5.9. It affects multiple versions of HarmonyOS including 4.0.0, 4.2.0, 4.3.0, and 4.3.1. No official patch or remediation guidance is currently available from the vendor. Join the discussion | CVE Database V5 | 06/09/2026, 06:56:02 UTC Added: 06/09/2026, 07:33:36 UTC |
Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability. Join the discussion | CVE Database V5 | 05/15/2026, 09:29:45 UTC Added: 05/15/2026, 09:52:46 UTC |
Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability. Join the discussion | CVE Database V5 | 05/15/2026, 09:27:44 UTC Added: 05/15/2026, 09:52:46 UTC |
Showing 1 to 10 of 20 results