CWE-691Pillar

Insufficient Control Flow Management

Draft in the CWE catalog · 33 CVEs mapped

33
CVEs mapped
6.8
Median CVSS
What it is

The code does not sufficiently manage its control flow during execution, creating conditions in which the control flow can be modified in unexpected ways.

Recent examples
8.6cvss
CVE-2026-20276

CVE-2026-20276 - HIGH Severity Vulnerability

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20276 are related to insufficient control flow management issues that are grouped under the Common Weakness Enumeration (CWE) CWE-691.

HIGHno explanation yet
0%
epss
7.5cvss
CVE-2025-51675

CVE-2025-51675 - HIGH Severity Vulnerability

An issue was discovered in openRISC OR1200 commit 83ac6b. An inaccurate update of program counter (PC) values when SPR changes can lead to a Denial of Service (DoS).

HIGHno explanation yet
0%
epss
8.8cvss
CVE-2026-79033

CVE-2026-79033 - HIGH Severity Vulnerability

Insufficient control flow management in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-691
Abstraction
Pillar
Structure
Simple
Status
Draft