CWE-413
14 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-413page 1 of 1
- CVE-2019-17102HIGHCVSS 8.3EG 8.32020-01-27
An exploitable command execution vulnerability exists in the recovery partition of Bitdefender BOX 2, version 2.0.1.91. The API method `/api/update_setup` does not perform firmware signature checks atomically, leading to an exploitable rac…
- CVE-2019-8998HIGHCVSS 7.8EG 7.82019-07-12
An information disclosure vulnerability leading to a potential local escalation of privilege in the procfs service (the /proc filesystem) of BlackBerry QNX Software Development Platform version(s) 6.5.0 SP1 and earlier could allow an attac…
- CVE-2022-20678HIGHCVSS 8.6EG 7.52022-04-15
A vulnerability in the AppNav-XE feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to the inc…
- CVE-2022-24946HIGHCVSS 7.5EG 7.52022-06-15
Improper Resource Locking vulnerability in Mitsubishi Electric MELSEC iQ-R Series R12CCPU-V firmware versions "16" and prior, Mitsubishi Electric MELSEC-Q Series Q03UDECPU the first 5 digits of serial No. "24061" and prior, Mitsubishi Elec…
- CVE-2022-49737HIGHCVSS 7.7EG 7.72025-03-16
In X.Org X server 20.11 through 21.1.16, when a client application uses easystroke for mouse gestures, the main thread modifies various data structures used by the input thread without acquiring a lock, aka a race condition. In particular,…
- CVE-2023-2269MEDIUMCVSS 4.4EG 5.52023-04-25
A denial of service problem was found, due to a possible recursive locking scenario, resulting in a deadlock in table_clear in drivers/md/dm-ioctl.c in the Linux Kernel Device Mapper-Multipathing sub-component.
- CVE-2023-2430MEDIUMCVSS 5.5EG 5.52023-07-23
A vulnerability was found due to missing lock for IOPOLL flaw in io_cqring_event_overflow() in io_uring.c in Linux Kernel. This flaw allows a local attacker with user privilege to trigger a Denial of Service threat.
- CVE-2023-28649HIGHCVSS 8.6EG 8.62023-05-22
The Hub in the Snap One OvrC cloud platform is a device used to centralize and manage nested devices connected to it. A vulnerability exists in which an attacker could impersonate a hub and send device requests to claim already claimed dev…
- CVE-2023-32253MEDIUMCVSS 5.9EG 5.92025-08-02
A flaw was found in the Linux kernel's ksmbd component. A deadlock is triggered by sending multiple concurrent session setup requests, possibly leading to a denial of service.
- CVE-2023-33951MEDIUMCVSS 6.7EG 6.72023-07-24
A race condition vulnerability was found in the vmwgfx driver in the Linux kernel. The flaw exists within the handling of GEM objects. The issue results from improper locking when performing operations on an object. This flaw allows a loca…
- CVE-2025-0003HIGHCVSS 7.3EG 7.32025-11-24
Inadequate lock protection within Xilinx Run time may allow a local attacker to trigger a Use-After-Free condition potentially resulting in loss of confidentiality or availability
- CVE-2025-3450CRITICALCVSS 10.0EG 10.02025-10-07
An Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and before Q4.93 may allow an unauthenticated network-based attacker to delete data causing denial of service conditions.
- CVE-2025-69198MEDIUMCVSS 6.5EG 6.52026-01-19
Pterodactyl is a free, open-source game server management panel. Pterodactyl implements rate limits that are applied to the total number of resources (e.g. databases, port allocations, or backups) that can exist for an individual server. T…
- CVE-2026-44608MEDIUMCVSS 5.9EG 5.92026-05-20
NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain conditions are met (multi-threaded, RPZ XFR reload, RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers) it could result i…
Map vulnerabilities like CWE-413 to your infrastructure
EchelonGraph correlates every CVE — across CWE-413 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →