CWE-754
557 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-754page 10 of 12
- CVE-2025-2704HIGHCVSS 7.5EG 7.52025-04-02
OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase
- CVE-2025-30258LOWCVSS 2.7EG 2.72025-03-19
In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing…
- CVE-2025-30655MEDIUMCVSS 5.5EG 5.52025-04-09
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to cause a Denial-of-Service (DoS). When …
- CVE-2025-30660HIGHCVSS 7.5EG 7.52025-04-09
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).When…
- CVE-2025-32051MEDIUMCVSS 5.9EG 5.92025-04-03
A flaw was found in libsoup. The libsoup soup_uri_decode_data_uri() function may crash when processing malformed data URI. This flaw allows an attacker to cause a denial of service (DoS).
- CVE-2025-32088LOWCVSS 3.3EG 3.32025-11-11
Improper conditions check for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow a denial of service. System software adversary with an authenticated user combined with a low complexity atta…
- CVE-2025-32735MEDIUMCVSS 5.5EG 5.52026-02-10
Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enab…
- CVE-2025-32739LOWCVSS 2.8EG 2.82026-02-10
Improper conditions check in some firmware for some Intel(R) Graphics Drivers and Intel LTS kernels within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a hig…
- CVE-2025-32997MEDIUMCVSS 4.0EG 4.02025-04-15
In http-proxy-middleware before 2.0.9 and 3.x before 3.0.5, fixRequestBody proceeds even if bodyParser has failed.
- CVE-2025-33030LOWCVSS 3.3EG 3.32026-02-10
Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attac…
- CVE-2025-33201HIGHCVSS 7.5EG 7.52025-12-03
NVIDIA Triton Inference Server contains a vulnerability where an attacker may cause an improper check for unusual or exceptional conditions issue by sending extra large payloads. A successful exploit of this vulnerability may lead to denia…
- CVE-2025-3359MEDIUMCVSS 6.2EG 6.22025-04-07
A flaw was found in GNUPlot. A segmentation fault via IO_str_init_static_internal may jeopardize the environment.
- CVE-2025-35992MEDIUMCVSS 4.7EG 4.72026-02-10
Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may ena…
- CVE-2025-38334MEDIUMCVSS 5.5EG 5.52025-07-10
In the Linux kernel, the following vulnerability has been resolved: x86/sgx: Prevent attempts to reclaim poisoned pages TL;DR: SGX page reclaim touches the page to copy its contents to secondary storage. SGX instructions do not gracefull…
- CVE-2025-38566HIGHCVSS 7.5EG 7.52025-08-19
In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix handling of server side tls alerts Scott Mayhew discovered a security exploit in NFS over TLS in tls_alert_recv() due to its assumption it can read data from…
- CVE-2025-41241MEDIUMCVSS 4.4EG 4.42025-07-29
VMware vCenter contains a denial-of-service vulnerability. A malicious actor who is authenticated through vCenter and has permission to perform API calls for guest OS customisation may trigger this vulnerability to create a denial-of-serv…
- CVE-2025-43715HIGHCVSS 8.1EG 8.12025-04-17
Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\temp and unprivileged users can …
- CVE-2025-43883MEDIUMCVSS 4.1EG 4.12026-04-16
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or exceptional conditions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to denial…
- CVE-2025-4619MEDIUMCVSS 6.6EG 0.02025-11-13
A denial-of-service (DoS) vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to reboot a firewall by sending a specially crafted packet through the dataplane. Repeated attempts to initiate a reboot caus…
- CVE-2025-4663MEDIUMCVSS 4.9EG 4.92025-07-08
An Improper Check for Unusual or Exceptional Conditions vulnerability in Brocade Fabric OS before 9.2.2.a could allow an authenticated, network-based attacker to cause a Denial-of-Service (DoS). The vulnerability is encountered when su…
- CVE-2025-4675MEDIUMCVSS 6.5EG 6.52026-01-07
Improper Check for Unusual or Exceptional Conditions vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: thro…
- CVE-2025-48581HIGHCVSS 8.4EG 9.82025-09-04
In VerifyNoOverlapInSessions of apexd.cpp, there is a possible way to block security updates due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio…
- CVE-2025-52136LOWCVSS 3.0EG 3.02025-08-10
In EMQX before 5.8.6, administrators can install arbitrary novel plugins via the Dashboard web interface. NOTE: the Supplier's position is that this is the intended behavior; however, 5.8.6 adds a defense-in-depth feature in which a plugin…
- CVE-2025-52931HIGHCVSS 7.5EG 7.52025-08-11
Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to update channel subscription endpoint with an invalid request body.
- CVE-2025-52981HIGHCVSS 7.5EG 7.52025-07-11
An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX1600, SRX2300, SRX 4000 Series, and SRX5000 Series with SPC3 allows an unauthenticat…
- CVE-2025-53359MEDIUMCVSS 6.9EG 0.02025-07-02
ethereum is a common ethereum structs for Rust. Prior to ethereum crate v0.18.0, signature malleability (according to EIP-2) was only checked for "legacy" transactions, but not for EIP-2930, EIP-1559 and EIP-7702 transactions. This is a sp…
- CVE-2025-53514MEDIUMCVSS 5.9EG 5.92025-08-11
Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an invalid request body.
- CVE-2025-53638MEDIUMCVSS 6.9EG 0.02025-07-17
Solady is software that provides Solidity snippets with APIs. Starting in version 0.0.125 and prior to version 0.1.24, when an account is deployed via a proxy, using regular Solidity to call its initialization function may result in a sile…
- CVE-2025-54427MEDIUMCVSS 6.9EG 0.02025-07-28
Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. The extrinsic note_min_gas_price_target is an inherent extrinsic, meaning only the block producer can call it. To ensure correctness, the ProvideInher…
- CVE-2025-54463MEDIUMCVSS 5.9EG 5.92025-08-11
Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an invalid request body.
- CVE-2025-55035MEDIUMCVSS 6.1EG 6.12025-10-16
Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a server that uses basic authentication from accessing their server which allows an attacker that provides a malicious serv…
- CVE-2025-58289MEDIUMCVSS 5.9EG 5.92025-10-11
Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability.
- CVE-2025-58354MEDIUMCVSS 6.9EG 0.02025-09-23
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In Kata Containers versions from 3.20.0 and before, a malicious host can circumvent initdat…
- CVE-2025-59958MEDIUMCVSS 6.5EG 6.52025-10-09
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to cause impact to confidentia…
- CVE-2025-59960HIGHCVSS 7.4EG 7.42026-01-15
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Juniper DHCP service (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows a DHCP client in one subnet to exhaust the address pools of other subnets, …
- CVE-2025-60004HIGHCVSS 7.5EG 7.52025-10-09
An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-Of-Service (Do…
- CVE-2025-60011MEDIUMCVSS 5.8EG 5.82026-01-15
An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause an availability impact …
- CVE-2025-61668HIGHCVSS 8.7EG 0.02025-10-02
Volto is a ReactJS-based frontend for the Plone Content Management System. Versions 16.34.0 and below, 17.0.0 through 17.22.1, 18.0.0 through 18.27.1, and 19.0.0-alpha.1 through 19.0.0-alpha.5, an anonymous user could cause the NodeJS serv…
- CVE-2025-61976HIGHCVSS 7.5EG 7.52025-12-16
CHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper check for unusual or exceptional conditions. If a remote attacker sends a specially crafted request to the Video Download interface, the system may become unresponsive.
- CVE-2025-62605MEDIUMCVSS 4.3EG 4.32025-10-21
Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon version 4.4, support for verifiable quote posts with quote controls was added, but it is possible for an attacker to bypass these controls in Mastodon …
- CVE-2025-62875MEDIUMCVSS 5.5EG 5.52025-11-20
An Improper Check for Unusual or Exceptional Conditions vulnerability in OpenSMTPD allows local users to crash OpenSMTPD. This issue affects openSUSE Tumbleweed: from ? before 7.8.0p0-1.1.
- CVE-2025-64342MEDIUMCVSS 6.9EG 0.02025-11-17
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. When the ESP32 is in advertising mode, if it receives a connection request containing an invalid Access Address (AA) of 0x00000000 or 0xFFFFFFFF, advertising may stop…
- CVE-2025-64704MEDIUMCVSS 4.7EG 4.72025-11-25
WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, WAMR is susceptible to a segmentation fault in v128.store instruction. This issue has been patched in version 2.4.4.
- CVE-2025-66357MEDIUMCVSS 5.3EG 5.32025-12-16
CHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper check for unusual or exceptional conditions. When the Video Download feature is in a specific communication state, the product's resources may be consumed abnormally.
- CVE-2025-69420HIGHCVSS 7.5EG 7.52026-01-27
Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing …
- CVE-2025-8716MEDIUMCVSS 5.8EG 0.02025-09-11
In Content Management versions 20.4- 25.3 authenticated attackers may exploit a complex cache poisoning technique to download unprotected files from the server if the filenames are known.
- CVE-2025-9998MEDIUMCVSS 6.0EG 0.02025-09-05
The sequence of packets received by a Networking server are not correctly checked. An attacker could exploit this vulnerability to send specially crafted messages to force the application to stop.
- CVE-2026-0227HIGHCVSS 7.5EG 7.52026-01-15
A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode.
- CVE-2026-0229MEDIUMCVSS 6.6EG 0.02026-02-11
A denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempt…
- CVE-2026-0235MEDIUMCVSS 5.8EG 5.82026-05-13
A race condition vulnerability in Palo Alto Networks Prisma® Browser enables a locally authenticated non-admin user to bypass certain access and data control policies.
Map vulnerabilities like CWE-754 to your infrastructure
EchelonGraph correlates every CVE — across CWE-754 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →