CWE-688: Function Call With Incorrect Variable or Reference as Argument
The product calls a function, procedure, or routine, but the caller specifies the wrong variable or reference as one of the arguments, which may lead to undefined behavior and resultant weaknesses.
3 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-76878 — In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is se
- CVE-2026-33549 — SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the
Recently published
- CVE-2026-76878 — In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is se
- CVE-2026-33549 — SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the