Skip to main content

CWE archive

CWE-241 CVEs

Programmatic archive

33 CVEs tagged with CWE-2410 Critical, 12 High, 17 Medium, 4 Low, 0 Unrated.

CVE-2026-47110

Published Jun 24, 2026

Tiptap for PHP before version 2.1.1 contains an input validation vulnerability that allows authenticated attackers to cause a denial of service by submitting Tiptap JSON with the…

CVSS 7.1 · High
evidence mentions
4
Buzz score
22.6

CVE-2025-63548

Published May 1, 2026

An issue in Eprosima Micro-XREC-DDS Agent v.3.0.1 allows a remote attacker to cause a denial of service via a packet specially crafted to bear a non-valid value in any Boolean fie…

CVSS 7.5 · High

CVE-2025-66550

Published Dec 5, 2025

Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.17 and 5.2.4, when a malicious user creates a calendar event with a crafted attachment that links to a download li…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21935

Published Sep 23, 2025

Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to manipulate Redfish® API commands to remove files from the local root di…

CVSS 5.0 · Medium

CVE-2024-21927

Published Sep 23, 2025

Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to use certain special characters in manipulated Redfish® API commands, ca…

CVSS 5.0 · Medium

CVE-2025-7339

Published Jul 17, 2025

on-headers is a node.js middleware for listening to when a response writes headers. A bug in on-headers versions `<1.1.0` may result in response headers being inadvertently modifi…

CVSS 3.4 · Low

CVE-2025-2268

Published Mar 14, 2025

The HP LaserJet MFP M232-M237 Printer Series may be vulnerable to a denial of service attack when a specially crafted request message is sent via Internet Printing Protocol (IPP).

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-1004

Published Feb 6, 2025

Certain HP LaserJet Pro printers may potentially experience a denial of service when a user sends a raw JPEG file to the printer via IPP (Internet Printing Protocol).

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-21526

Published Jul 10, 2024

All versions of the package speaker are vulnerable to Denial of Service (DoS) when providing unexpected input types to the channels property of the Speaker object makes it possibl…

CVSS 7.5 · High

CVE-2024-21523

Published Jul 10, 2024

All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to several different functions. This makes it possible to reac…

CVSS 7.5 · High

CVE-2024-37316

Published Jun 14, 2024

Nextcloud Calendar is a calendar app for Nextcloud. Authenticated users could create an event with manipulated attachment data leading to a bad redirect for participants when clic…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25966

Published May 14, 2024

Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an improper handling of unexpected data type vulnerability. A remote unauthenticated attacker could potentially explo…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32268

Published Apr 29, 2024

An issue in Tuya Smart camera U6N v.3.2.5 allows a remote attacker to cause a denial of service via a crafted packet to the network connection component.

CVSS 3.3 · Low

CVE-2024-0151

Published Apr 24, 2024

Insufficient argument checking in Secure state Entry functions in software using Cortex-M Security Extensions (CMSE), that has been compiled using toolchains that implement 'Arm v…

CVSS 6.5 · Medium

CVE-2023-30591

Published Sep 29, 2023

Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking `eventName.startsWith()` or `eventName.toString()`, while processing Sock…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28961

Published Apr 17, 2023

An Improper Handling of Unexpected Data Type vulnerability in IPv6 firewall filter processing of Juniper Networks Junos OS on the ACX Series devices will prevent a firewall filter…

CVSS 5.8 · Medium

CVE-2022-22219

Published Oct 18, 2022

Due to the Improper Handling of an Unexpected Data Type in the processing of EVPN routes on Juniper Networks Junos OS and Junos OS Evolved, an attacker in direct control of a BGP…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3029

Published Sep 13, 2022

In NLnet Labs Routinator 0.9.0 up to and including 0.11.2, due to a mistake in error handling, data in RRDP snapshot and delta files that isn’t correctly base 64 encoded is treate…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-1642

Published Jun 16, 2022

A program using swift-corelibs-foundation is vulnerable to a denial of service attack caused by a potentially malicious source producing a JSON document containing a type mismatch…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29181

Published May 20, 2022

Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX parsers, allowing specially cr…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-20730

Published May 3, 2022

A vulnerability in the Security Intelligence feed feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the Security I…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 33 CVEsPage 1 of 2