CWE-684: Incorrect Provision of Specified Functionality
The code does not function according to its published specifications, potentially leading to incorrect usage.
29 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-3598 — RustDesk Server Generates Config Strings Using Reversible Encoding (Base64 + Reverse) Instead of Encryption
- CVE-2026-30791 — RustDesk Client Accepts Pseudo-Encrypted Config Strings Without Cryptographic Validation
- CVE-2025-66384 — app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, rela
- CVE-2025-58325 — An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 t
- CVE-2026-52735 — ZEBRA: Consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser
- CVE-2025-47227 — In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset me
- CVE-2026-79126 — Incorrect provision of specified functionality in Proxy in Google Chrome on on Windows prior to 152.0.7977.65 allowed an
- CVE-2024-20317 — Cisco IOS XR Software Layer 2 Services Denial of Service Vulnerability
- CVE-2026-42255 — Technitium DNS Server before 15.0 allows DNS traffic amplification via cyclic name server delegation.
- CVE-2026-34478 — Apache Log4j Core: Log injection in Rfc5424Layout due to silent configuration incompatibility
- CVE-2026-40685 — In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounter
- CVE-2026-40684 — In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malfor
- CVE-2024-5005 — Incorrect Provision of Specified Functionality in GitLab
- CVE-2025-54567 — hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.
- CVE-2025-54568 — Akamai Rate Control alpha before 2025 allows attackers to send requests above the stipulated thresholds because the rate
- CVE-2025-55174 — In KDE Skanpage before 25.08.0, an attempt at file overwrite can result in the contents of the new file at the beginning
- CVE-2026-44597 — Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload,
- CVE-2026-35381 — uutils coreutils cut Local Logic Error and Data Integrity Issue in Output Filtering
- CVE-2026-35379 — uutils coreutils tr Local Logic Error and Data Integrity Issue in Character Class Handling
Recently published
- CVE-2026-79126 — Incorrect provision of specified functionality in Proxy in Google Chrome on on Windows prior to 152.0.7977.65 allowed an
- CVE-2026-52735 — ZEBRA: Consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser
- CVE-2026-44597 — Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload,
- CVE-2026-40685 — In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounter
- CVE-2026-40684 — In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malfor
- CVE-2026-42255 — Technitium DNS Server before 15.0 allows DNS traffic amplification via cyclic name server delegation.
- CVE-2026-35381 — uutils coreutils cut Local Logic Error and Data Integrity Issue in Output Filtering
- CVE-2026-35379 — uutils coreutils tr Local Logic Error and Data Integrity Issue in Character Class Handling
- CVE-2026-34478 — Apache Log4j Core: Log injection in Rfc5424Layout due to silent configuration incompatibility
- CVE-2026-30791 — RustDesk Client Accepts Pseudo-Encrypted Config Strings Without Cryptographic Validation
- CVE-2026-3598 — RustDesk Server Generates Config Strings Using Reversible Encoding (Base64 + Reverse) Instead of Encryption
- CVE-2025-66384 — app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, rela
- CVE-2025-55174 — In KDE Skanpage before 25.08.0, an attempt at file overwrite can result in the contents of the new file at the beginning
- CVE-2025-58325 — An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 t
- CVE-2025-54568 — Akamai Rate Control alpha before 2025 allows attackers to send requests above the stipulated thresholds because the rate
- CVE-2025-54567 — hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.
- CVE-2025-47227 — In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset me
- CVE-2024-5005 — Incorrect Provision of Specified Functionality in GitLab
- CVE-2024-20317 — Cisco IOS XR Software Layer 2 Services Denial of Service Vulnerability