CWE-229
16 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-229page 1 of 1
- CVE-2022-22562HIGHCVSS 7.5EG 7.52022-04-12
Dell PowerScale OneFS, versions 8.2.0-9.3.0, contain a improper handling of missing values exploit. An unauthenticated network attacker could potentially exploit this denial-of-service vulnerability.
- CVE-2022-24412HIGHCVSS 7.5EG 7.52022-04-12
Dell EMC PowerScale OneFS 8.2.x - 9.3.0.x contain an improper handling of value vulnerability. An unprivileged network attacker could potentially exploit this vulnerability, leading to denial-of-service.
- CVE-2022-2809HIGHCVSS 8.2EG 8.22022-10-27
A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. When fuzzing the multipart_parser code using AFL++ with address sanitizer enabled to find smallest memory corruptions possible. It detected problem in how…
- CVE-2022-3409HIGHCVSS 8.2EG 7.52022-10-27
A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. This vulnerability was identified during mitigation for CVE-2022-2809. When fuzzing the multipart_parser code using AFL++ with address sanitizer enabled t…
- CVE-2022-4851MEDIUMCVSS 5.3EG 5.32022-12-29
Improper Handling of Values in GitHub repository usememos/memos prior to 0.9.1.
- CVE-2024-0607MEDIUMCVSS 6.6EG 7.82024-01-18
A flaw was found in the Netfilter subsystem in the Linux kernel. The issue is in the nft_byteorder_eval() function, where the code iterates through a loop and writes to the `dst` array. On each iteration, 8 bytes are written, but `dst` is …
- CVE-2024-20431MEDIUMCVSS 5.8EG 5.82024-10-23
A vulnerability in the geolocation access control feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control policy. This vulnerability is due to improper assignm…
- CVE-2024-29460MEDIUMCVSS 6.6EG 6.62024-04-10
An issue in PX4 Autopilot v.1.14.0 allows an attacker to manipulate the flight path allowing for crashes of the drone via the home point location of the mission_block.cpp component.
- CVE-2024-30800MEDIUMCVSS 5.6EG 6.32024-04-23
PX4 Autopilot v.1.14 allows an attacker to fly the drone into no-fly zones by breaching the geofence using flaws in the function.
- CVE-2024-30917MEDIUMCVSS 5.5EG 5.52024-04-11
An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (DoS) and obtain sensitive information via a crafted history_depth parameter in DurabilityService QoS component.
- CVE-2024-3102MEDIUMCVSS 5.3EG 5.32024-06-06
A JSON Injection vulnerability exists in the `mintplex-labs/anything-llm` application, specifically within the username parameter during the login process at the `/api/request-token` endpoint. The vulnerability arises from improper handlin…
- CVE-2024-36737HIGHCVSS 7.5EG 7.52024-06-06
Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting a negative value into the oneflow.full parameter.
- CVE-2024-39531HIGHCVSS 7.5EG 7.52024-07-11
An Improper Handling of Values vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX 7000 Series allows a network-based, unauthenticated attacker to cause a Denial-of-Service (DoS). If a value is …
- CVE-2025-20268MEDIUMCVSS 5.8EG 5.82025-08-14
A vulnerability in the Geolocation-Based Remote Access (RA) VPN feature of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured policies to allow or deny HTTP connections …
- CVE-2025-31648LOWCVSS 3.9EG 3.92026-02-10
Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable escalation o…
- CVE-2025-7964CRITICALCVSS 9.2EG 0.02026-01-30
After receiving a malformed 802.15.4 MAC Data Request the Zigbee Coordinator sends a ‘network leave’ request to Zigbee router resulting in the Zigbee Router getting stuck in a non-rejoinable state. If a suitable parent is not avail…
Map vulnerabilities like CWE-229 to your infrastructure
EchelonGraph correlates every CVE — across CWE-229 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →