Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker
A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Cl
Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records
YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5, Any admin OnPost… handler executes its side effects
A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file
Mastodon is a free, open-source social network server based on ActivityPub. Prior to v4.5.9, v4.4.16, and v4.3.22, Masto
Unexpected Status Code or Return Value vulnerability in ninenines gun (gun_http module) allows a malicious HTTP server t
Improper enforcement of behavioral workflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker w
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4
Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5
Chamilo is a learning management system. Prior to version 1.11.30, a logic vulnerability in the friend request workflow
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent
Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team update API endpoint (PA
A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2,
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to perform unauthorized actio
A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, wher
A weakness has been identified in WonderTrader up to 0.9.9. This vulnerability affects the function MatchEngine::update_
A vulnerability was identified in WonderTrader up to 0.9.9. Affected is the function _undone_qty in the library src/WtCo
A vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality
A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the file /customer/accoun
A vulnerability was detected in WonderTrader up to 0.9.9. Impacted is the function TraderDD::queryTrades of the file src
Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email
IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper enforc
Improper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature in Devolutions Server al
Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both s
Our payment integration with Oppwa-based payment methods did not properly validate payment status responses. An attacke
Our payment integration with Computop-based payment methods did not properly validate payment status responses. An atta
Our payment integration with Mollie did not properly validate payment status responses. An attacker could use a success
Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a s
A pop-up logic flaw in a certain feature of Kids Mode allows users to bypass password verification and use Quick Apps ou
WatchGuard Dimension provides a client-side lock/unlock UI control for management changes. The server-side configuration
A business logic flaw in WatchGuard Dimension allows an authenticated administrator to trigger multiple backend operatio
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, processPercentageRoyaltiesTransfe
Frequently Asked Questions
What is CWE-841?
CWE-841 (CWE-841) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-841?
There are 35 CVE records associated with CWE-841 in our database. Of these, 3 are critical severity, 8 are high severity, and 11 are medium severity.
How can I protect against CWE-841 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-841 using AI-powered security agents.
Detect CWE-841 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-841 vulnerabilities across your infrastructure.
Get Started