Threats Tagged 'cwe-841'
View all threats tagged with 'cwe-841'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-841'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-82406 is a high-severity vulnerability in klever-io's klever-go blockchain protocol implementation prior to version 1.7.20. The marketplace Buy function does not properly check if an NFT order is claimed before accepting bids, allowing a seller to settle an auction while leaving the order in a stale state. This can cause a later bidder to be debited without receiving the NFT or recovering funds. The issue is fixed in version 1.7.20. Join the discussion | CVE Database V5 | 09/23/2026, 19:10:23 UTC Added: 09/24/2026, 01:57:14 UTC |
0 NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper enforcement of a behavioral workflow. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure. Join the discussion | CVE Database V5 | 09/22/2026, 14:10:25 UTC Added: 09/22/2026, 14:33:35 UTC |
0 HomeBox is a home inventory and organization system. Prior to 0.26.0, POST /v1/groups/members invokes HandleGroupMemberAdd and GroupService.AddMember using a caller-supplied userID without requiring an owner role, an invitation token, target-user consent, or target-user notification. Any authenticated user can force another account into the caller's group, disclose the target user's email address and name through the resulting member list, and create the membership prerequisite used by a separate cross-group inventory-wipe vulnerability. This issue is fixed in version 0.26.0. Join the discussion | CVE Database V5 | 09/21/2026, 17:42:59 UTC Added: 09/21/2026, 17:47:04 UTC |
0 CVE-2026-67279 is a vulnerability in Mikrotik RouterOS where the SSH service improperly enforces behavioral workflow. Specifically, after a client-requested rekey, the SSH server proceeds with the connection protocol without requiring user authentication. This allows an unauthenticated client to open a session channel and send commands that can create, overwrite, or reconstruct files in the RouterOS managed file namespace, including critical configuration and diagnostic files. The issue affects multiple versions of RouterOS and has been fixed in versions 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable). Join the discussion | CVE Database V5 | 09/09/2026, 00:00:00 UTC Added: 09/05/2026, 20:08:29 UTC |
A vulnerability exists in macrozheng mall versions 1.0.0 through 1.0.3 in the Payment Status Endpoint (/order/paySuccess). The issue involves manipulation of the orderId argument, which can enforce unintended behavioral workflow remotely. The vendor has not provided a patch or explanation, and the GitHub issue was deleted without comment. The CVSS score is 5.4, indicating a low severity level with limited impact on confidentiality but some impact on integrity and availability. Join the discussion | GCVE Database | 08/30/2026, 00:30:21 UTC Added: 08/30/2026, 15:27:18 UTC |
0 CVE-2026-55763 is a high-severity vulnerability in klever-go, the Go implementation of the Klever blockchain protocol. Prior to version 1.7.19, a logic flaw in the processPercentageRoyaltiesTransfer function allows a 100% royalty split to be processed without debiting the source account, resulting in unbounded off-the-books inflation of the KDA token supply. This occurs because the function returns early when royaltiesToPay reaches zero, before subtracting the amount from the sender's balance. The issue is fixed in version 1.7.19. Join the discussion | CVE Database V5 | 08/28/2026, 20:26:43 UTC Added: 08/28/2026, 22:08:06 UTC |
0 CVE-2026-78103 is a medium severity vulnerability in WatchGuard Dimension version 2.0. It involves a server-side configuration endpoint that does not enforce the client-side lock/unlock workflow, allowing an authenticated administrator with read-write access to bypass the intended editing workflow and overwrite configuration changes made by another concurrent administrator session. Join the discussion | CVE Database V5 | 08/27/2026, 23:26:31 UTC Added: 08/28/2026, 02:08:11 UTC |
0 CVE-2026-78618 is a business logic flaw in WatchGuard Dimension version 2.0 that allows an authenticated administrator to trigger multiple backend operations within a single logical flow by sending a specially crafted request. The vulnerability has a medium severity with a CVSS score of 6.9. There is no official patch or remediation level currently provided by the vendor. The flaw requires high privileges (administrator) and does not involve user interaction. No known exploits are reported in the wild. Join the discussion | CVE Database V5 | 08/27/2026, 23:26:30 UTC Added: 08/28/2026, 02:08:14 UTC |
0 Weblate versions prior to 2026.8 contain an authentication bypass vulnerability where an authenticated user can change their account's primary email without verifying the new address. This allows acceptance of team invitations sent to the new email without access to the intended recipient's mailbox. The issue is fixed in version 2026.8. Join the discussion | CVE Database V5 | 08/26/2026, 19:56:59 UTC Added: 08/26/2026, 20:07:53 UTC |
0 CVE-2026-15365 is a low-severity vulnerability in vivo's Kids Mode feature. It involves a pop-up logic flaw that allows users to bypass password verification and access Quick Apps outside the Kids Mode app. The vulnerability is categorized under CWE-841, indicating improper enforcement of behavioral workflow. No affected versions or patches have been specified, and there are no known exploits in the wild. Join the discussion | CVE Database V5 | 08/26/2026, 06:45:35 UTC Added: 08/26/2026, 07:08:16 UTC |
Showing 1 to 10 of 48 results