Cyber Posture

CWE · MITRE source

CWE-691Insufficient Control Flow Management

Abstraction: Pillar · CVEs in our corpus: 32

The code does not sufficiently manage its control flow during execution, creating conditions in which the control flow can be modified in unexpected ways.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (1)AI

Control Title Family Why it addresses this CWE
SA-24Design For Cyber ResiliencySADesign principles and implementation approaches enforce robust control-flow management to maintain function and enable recovery after disruption.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2023-205591.88.80.00392023-04-02
CVE-2022-206971.78.60.00452022-04-15
CVE-2021-41061.67.80.00042022-02-16
CVE-2025-228931.67.80.00012025-08-12
CVE-2025-252731.67.80.00012025-08-12
CVE-2025-359631.57.40.00012025-11-11
CVE-2023-245871.46.90.00042023-11-14
CVE-2021-331571.47.20.00042024-02-23
CVE-2024-218011.47.10.00062024-08-14
CVE-2024-290791.46.80.00082024-11-13
CVE-2025-200041.47.20.00042025-05-13
CVE-2025-243051.47.20.00012025-08-12
CVE-2024-223741.36.50.00032024-08-14
CVE-2025-257741.36.50.00342025-03-12
CVE-2025-494631.36.50.00162025-07-10
CVE-2024-38471.26.10.00172024-04-17
CVE-2024-336171.25.90.00032024-11-13
CVE-2023-287111.15.50.00072023-08-11
CVE-2023-51021.15.30.00182023-10-09
CVE-2025-200221.15.70.00062025-05-13
CVE-2026-59381.15.50.00022026-04-27
CVE-2022-468281.05.20.00002022-12-08
CVE-2022-484811.05.20.00002023-04-28
CVE-2022-374090.94.70.00102023-05-10
CVE-2022-416460.94.70.00142023-05-10