Skip to main content

CWE archive

CWE-230 CVEs

Programmatic archive

12 CVEs tagged with CWE-2302 Critical, 6 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2026-25659

Published Jun 5, 2026

Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulnerability where an attacker continuously sending a specially…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-25658

Published Jun 5, 2026

Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulnerability where an attacker continuously sending a specially…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-20086

Published Mar 25, 2026

A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) packets of Cisco IOS XE Wireless Controller Software for the Catalyst CW9800 Famil…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-1461

Published Feb 19, 2026

The Simple Membership plugin for WordPress is vulnerable to Improper Handling of Missing Values in all versions up to, and including, 4.7.0 via the Stripe webhook handler. This is…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2025-23225

Published Feb 28, 2025

IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user to cause a denial of service due to the improper handling of invalid headers sent to the queue.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-11024

Published Nov 26, 2024

The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.6. This is due to t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-10508

Published Nov 9, 2024

The RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-9781

Published Oct 10, 2024

AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet injection or crafted capture file

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-0048

Published Mar 11, 2024

In Session of AccountManagerService.java, there is a possible method to retain foreground service privileges due to incorrect handling of null responses. This could lead to local…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-0208

Published Jan 3, 2024

GVCP dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1