CWE-642: External Control of Critical State Data
The product stores security-critical state information about its users, or the product itself, in a location that is accessible to unauthorized actors.
14 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-78655 — Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts failures in the session
- CVE-2025-49090 — The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient
- CVE-2024-22387 — External Control of Critical State Data (CWE-642) in the Controller 6000 and Controller 7000 diagnostic web interface al
- CVE-2025-54566 — hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.
- CVE-2024-58265 — The snow crate before 0.9.5 for Rust, when stateful TransportState is used, allows incrementing a nonce and thereby deny
Recently published
- CVE-2026-78655 — Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts failures in the session
- CVE-2025-49090 — The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient
- CVE-2024-58265 — The snow crate before 0.9.5 for Rust, when stateful TransportState is used, allows incrementing a nonce and thereby deny
- CVE-2025-54566 — hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.
- CVE-2024-22387 — External Control of Critical State Data (CWE-642) in the Controller 6000 and Controller 7000 diagnostic web interface al