Skip to main content

CWE archive

CWE-228 CVEs

Programmatic archive

20 CVEs tagged with CWE-2281 Critical, 8 High, 9 Medium, 2 Low, 0 Unrated.

CVE-2026-50103

Published Jul 23, 2026

A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser, which may allow a network-adjacent attacker to crash a subscribing application by sending a crafted GOOSE fra…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-59174

Published Jun 5, 2026

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degra…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2026-25657

Published Jun 5, 2026

Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Syntactically Invalid Structure (CWE-228) vulnerability where an attacker continuously se…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42100

Published May 19, 2026

Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) attack to be executed by sending an specially crafted SQL query. This…

CVSS 7.1 · High
evidence mentions
4
Buzz score
36.1
Vendor/product tagsBeta · best-effort

CVE-2026-34232

Published Apr 17, 2026

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the xdr_status_vector() function does not handle the isc_arg_cstrin…

CVSS 7.5 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2024-53828

Published Apr 1, 2026

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degra…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-20125

Published Mar 25, 2026

A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E could allow an authenticated, remote attacker to cause an affected device to…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-2529

Published Oct 15, 2025

Applications using affected versions of Ehcache 3.x can experience degraded cache-write performance if the application using Ehcache utilizes keys sourced from (malicious) externa…

CVSS 2.9 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-47736

Published May 9, 2025

dialect/mod.rs in the libsql-sqlite3-parser crate through 0.13.0 before 14f422a for Rust can crash if the input is not valid UTF-8.

CVSS 2.9 · Low

CVE-2024-55594

Published Mar 14, 2025

An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows attacke…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-42784

Published Mar 11, 2025

An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows attacker…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0343

Published Jan 15, 2025

Swift ASN.1 can be caused to crash when parsing certain BER/DER constructions. This crash is caused by a confusion in the ASN.1 library itself which assumes that certain objects c…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2024-6382

Published Jul 2, 2024

Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including dat…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21612

Published Jan 12, 2024

An Improper Handling of Syntactically Invalid Structure vulnerability in Object Flooding Protocol (OFP) service of Juniper Networks Junos OS Evolved allows an unauthenticated, net…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-38443

Published May 5, 2022

Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write arbitrary values in the XML parser.

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-27847

Published May 28, 2021

A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation. This flaw allows an attacker to bypass SAML authentica…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-20 of 20 CVEsPage 1 of 1