CWE-754— Improper Check for Unusual or Exceptional Conditions
The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.— MITRE CWE catalog
616 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-754page 6 of 13
- CVE-2022-47111LOWCVSS 2.5EG 2.52025-04-19
7-Zip 22.01 does not report an error for certain invalid xz files, involving block flags and reserved bits. Some later versions are unaffected.
- CVE-2022-47112LOWCVSS 2.5EG 2.52025-04-19
7-Zip 22.01 does not report an error for certain invalid xz files, involving stream flags and reserved bits. Some later versions are unaffected.
- CVE-2023-0572MEDIUMCVSS 5.3EG 5.32023-01-29
Unchecked Error Condition in GitHub repository froxlor/froxlor prior to 2.0.10.
- CVE-2023-21102HIGHCVSS 7.8EG 7.82023-05-15
In __efi_rt_asm_wrapper of efi-rt-wrapper.S, there is a possible bypass of shadow stack protection due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User inte…
- CVE-2023-21137MEDIUMCVSS 5.5EG 5.52023-06-15
In several methods of JobStore.java, uncaught exceptions in job map parsing could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe…
- CVE-2023-21230MEDIUMCVSS 5.5EG 5.52023-08-14
In onAccessPointChanged of AccessPointPreference.java, there is a possible way for unprivileged apps to receive a broadcast about WiFi access point change and its BSSID or SSID due to a precondition check failure. This could lead to local …
- CVE-2023-21246LOWCVSS 3.3EG 3.32023-07-13
In ShortcutInfo of ShortcutInfo.java, there is a possible way for an app to retain notification listening access due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed.…
- CVE-2023-21405MEDIUMCVSS 6.5EG 6.52023-07-25
Knud from Fraktal.fi has found a flaw in some Axis Network Door Controllers and Axis Network Intercoms when communicating over OSDP, highlighting that the OSDP message parser crashes the pacsiod process, causing a temporary unavailability …
- CVE-2023-22290MEDIUMCVSS 6.5EG 6.52023-11-14
Uncaught exception for some Intel Unison software may allow an authenticated user to potentially enable denial of service via network access.
- CVE-2023-22393HIGHCVSS 7.5EG 7.52023-01-13
An Improper Check for Unusual or Exceptional Conditions vulnerability in BGP route processing of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to cause Routing Protocol Daemon (RPD) crash by sending a BGP route with inv…
- CVE-2023-23602MEDIUMCVSS 6.5EG 6.52023-06-02
A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to connections to restricted origins from inside WebWorkers. This vulnerability affec…
- CVE-2023-23626MEDIUMCVSS 5.9EG 5.92023-02-09
go-bitfield is a simple bitfield package for the go language aiming to be more performant that the standard library. When feeding untrusted user input into the size parameter of `NewBitfield` and `FromBytes` functions, an attacker can trig…
- CVE-2023-23931MEDIUMCVSS 4.8EG 4.82023-02-07
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which implement the buffer protocol, but provide only immutable b…
- CVE-2023-25619HIGHCVSS 7.5EG 7.52023-04-19
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service of the controller when communicating over the Modbus TCP protocol.
- CVE-2023-25620MEDIUMCVSS 6.5EG 6.52023-04-19
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service of the controller when a malicious project file is loaded onto the controller by an authenticated user.
- CVE-2023-27772HIGHCVSS 7.5EG 7.52023-04-13
libiec61850 v1.5.1 was discovered to contain a segmentation violation via the function ControlObjectClient_setOrigin() at /client/client_control.c.
- CVE-2023-28910HIGHCVSS 8.0EG 8.02025-06-28
A specific flaw exists within the Bluetooth stack of the MIB3 infotainment system. The issue results from the disabled abortion flag eventually leading to bypassing assertion functions. The vulnerability was originally discovered in Skoda …
- CVE-2023-28965MEDIUMCVSS 6.5EG 6.52023-04-17
An Improper Check or Handling of Exceptional Conditions within the storm control feature of Juniper Networks Junos OS allows an attacker sending a high rate of traffic to cause a Denial of Service. Continued receipt and processing of these…
- CVE-2023-28974HIGHCVSS 7.4EG 7.42023-04-17
An Improper Check for Unusual or Exceptional Conditions vulnerability in the bbe-smgd of Juniper Networks Junos OS allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). In a Broadband Edge / Subscriber Management…
- CVE-2023-28975MEDIUMCVSS 4.6EG 4.62023-04-17
An Unexpected Status Code or Return Value vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated attacker with physical access to the device to cause a Denial of Service (DoS). When certain USB devices are conne…
- CVE-2023-28976HIGHCVSS 7.5EG 7.52023-04-17
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). If …
- CVE-2023-28979MEDIUMCVSS 4.7EG 4.72023-04-17
An Improper Check for Unusual or Exceptional Conditions vulnerability in the kernel of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to bypass an integrity check. In a 6PE scenario and if an additional integrity che…
- CVE-2023-29198MEDIUMCVSS 6.0EG 6.02023-09-06
Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Electron apps using `contextIsolation` and `contextBridge` are affected. This is a context isolation bypass, meaning that code…
- CVE-2023-30456HIGHCVSS 6.5EG 7.82023-04-10
An issue was discovered in arch/x86/kvm/vmx/nested.c in the Linux kernel before 6.2.8. nVMX on x86_64 lacks consistency checks for CR0 and CR4.
- CVE-2023-30591HIGHCVSS 7.5EG 8.12023-09-29
Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking `eventName.startsWith()` or `eventName.toString()`, while processing Socket.IO messages via crafted Socket.IO messages containing arr…
- CVE-2023-32695HIGHCVSS 7.3EG 7.32023-05-27
socket.io parser is a socket.io encoder and decoder written in JavaScript complying with version 5 of socket.io-protocol. A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node…
- CVE-2023-32716MEDIUMCVSS 6.5EG 6.52023-06-01
In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, an attacker can exploit a vulnerability in the {{dump}} SPL command to cause a denial of service by crashing the Splunk d…
- CVE-2023-32726HIGHCVSS 3.9EG 8.12023-12-18
The vulnerability is caused by improper check for check if RDLENGTH does not overflow the buffer in response from DNS server.
- CVE-2023-32871MEDIUMCVSS 5.3EG 5.32024-05-06
In DA, there is a possible permission bypass due to an incorrect status check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS…
- CVE-2023-34099MEDIUMCVSS 5.3EG 5.32023-06-27
Shopware is an open source e-commerce software. The mail validation in the registration process had some flaws, so it was possible to construct different mail addresses, that in the end result in the same address, which is shared by multip…
- CVE-2023-34348HIGHCVSS 7.5EG 7.52024-01-18
AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to remotely crash the PI Message Subsystem of a PI Server, resulting in a denial-of-service condition.
- CVE-2023-34449MEDIUMCVSS 5.3EG 5.32023-06-14
ink! is an embedded domain specific language to write smart contracts in Rust for blockchains built on the Substrate framework. Starting in version 4.0.0 and prior to version 4.2.1, the return value when using delegate call mechanics, eith…
- CVE-2023-34733MEDIUMCVSS 6.8EG 6.82023-06-16
A lack of exception handling in the Volkswagen Discover Media Infotainment System Software Version 0876 allows attackers to cause a Denial of Service (DoS) via supplying crafted media files when connecting a device to the vehicle's USB plu…
- CVE-2023-35849HIGHCVSS 7.5EG 7.52023-06-19
VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 does not properly check whether header sizes would result in accessing data outside of a packet.
- CVE-2023-36835HIGHCVSS 7.5EG 7.52023-07-14
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on QFX10000 Series allows a network based attacker to cause a Denial of Service (DoS). If a specific …
- CVE-2023-37303CRITICALCVSS 9.8EG 9.82023-06-30
An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. In certain situations, an attempt to block a user fails after a temporary browser hang and a DBQueryDisconnectedError error message.
- CVE-2023-37899HIGHCVSS 7.5EG 7.52023-07-19
Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. Feathers socket handler did not catch invalid string conversion errors like `const message = ${{ toString: '' }}` which would cause t…
- CVE-2023-38069LOWCVSS 3.3EG 3.32023-07-12
In JetBrains IntelliJ IDEA before 2023.1.4 license dialog could be suppressed in certain cases
- CVE-2023-38283MEDIUMCVSS 5.3EG 5.32023-08-29
In OpenBGPD before 8.1, incorrect handling of BGP update data (length of path attributes) set by a potentially distant remote actor may cause the system to incorrectly reset a session. This is fixed in OpenBSD 7.3 errata 006.
- CVE-2023-38420LOWCVSS 3.8EG 3.82024-05-16
Improper conditions check in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable information disclosure via local access.
- CVE-2023-39205MEDIUMCVSS 4.3EG 4.32023-11-14
Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access.
- CVE-2023-41304MEDIUMCVSS 5.3EG 5.32023-10-11
Parameter verification vulnerability in the window module.Successful exploitation of this vulnerability may cause the size of an app window to be adjusted to that of a floating window.
- CVE-2023-41992CRITICALCVSS 7.8EG 9.0⚠ KEV2023-09-21
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue ma…
- CVE-2023-41993CRITICALCVSS 8.8EG 9.8⚠ KEV2023-09-21
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions…
- CVE-2023-44099HIGHCVSS 7.5EG 7.52023-12-06
Vulnerability of data verification errors in the kernel module. Successful exploitation of this vulnerability may cause WLAN interruption.
- CVE-2023-44196MEDIUMCVSS 6.5EG 6.52023-10-13
An Improper Check for Unusual or Exceptional Conditions in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS Evolved on PTX10003 Series allows an unauthenticated adjacent attacker to cause an impact to the integrity of the s…
- CVE-2023-44198HIGHCVSS 7.5EG 7.52023-10-13
An Improper Check for Unusual or Exceptional Conditions vulnerability in the SIP ALG of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated network-based attacker to cause an integrity impact in connected netwo…
- CVE-2023-44199HIGHCVSS 7.5EG 7.52023-10-13
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). On…
- CVE-2023-45812HIGHCVSS 7.5EG 7.52023-10-18
The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation. Affected versions are subject to a Denial-of-Service (DoS) type vulnerability which causes the Ro…
- CVE-2023-4583HIGHCVSS 7.5EG 7.52023-09-11
When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then it was assumed to have already been discarded which was not always the case for private channels after the private sess…
Map vulnerabilities like CWE-754 to your infrastructure
EchelonGraph correlates every CVE — across CWE-754 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →