Skip to main content

CWE archive

CWE-248 CVEs

Programmatic archive

239 CVEs tagged with CWE-2484 Critical, 131 High, 98 Medium, 6 Low, 0 Unrated.

CVE-2026-64612

Published Jul 20, 2026

A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image fi…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-63747

Published Jul 20, 2026

SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is set without a namespace. Unauthenticated attackers can send…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-71391

Published Jul 18, 2026

SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated users to crash the database. Attackers can send crafted HTT…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5

CVE-2024-58369

Published Jul 18, 2026

SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or namespace levels, causing server panic. Authorized clients can i…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5

CVE-2024-58368

Published Jul 18, 2026

SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests containing special characters. Unauthenticated attackers can send craft…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2024-58365

Published Jul 18, 2026

SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls to nonexistent built-in functions. Authorized clients can c…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5

CVE-2024-58364

Published Jul 18, 2026

SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span rendering when parsing queries with errors on line terminator characters. Authorized c…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5

CVE-2024-58361

Published Jul 18, 2026

SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser error rendering code when processing empty strings. Authorized clients can execu…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5

CVE-2024-58359

Published Jul 18, 2026

SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting mechanism when using ORDER BY rand() clause. Authorized clients can execute queries with O…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5

CVE-2024-58358

Published Jul 18, 2026

SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that allows privileged owner users to define users with nonexistent roles. Attackers c…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2024-58357

Published Jul 18, 2026

SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time() function that panics when unwrap is called on a None result from timestamp_opt. Aut…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-62994

Published Jul 16, 2026

CoreDNS is a DNS server written in Go. From 1.9.4 until 1.14.5, a network DNS client allowed to request AXFR for a CoreDNS zone can trigger a panic when CoreDNS is configured with…

CVSS 3.7 · Low
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-48069

Published Jul 14, 2026

@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4, an invalid incomin…

CVSS 7.5 · High
evidence mentions
13
Buzz score
31.4

CVE-2026-48068

Published Jul 14, 2026

@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4, an invalid incomin…

CVSS 7.5 · High
evidence mentions
13
Buzz score
31.4

CVE-2026-48038

Published Jul 14, 2026

joi is a schema description language and data validator for JavaScript. Prior to 17.13.4 and 18.2.1, denial of service is possible via an untrapped exception in services validatin…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-47480

Published Jul 14, 2026

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an uncaught exception. A successful exploit of this vulnerability might lead to denia…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-59162

Published Jul 10, 2026

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, Excelize parses shared-string cell values with strconv.Atoi and checks onl…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-55780

Published Jul 10, 2026

NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's .NET single-file bundle handler in NanaZip.Codecs.Archive.DotNetSingleFi…

CVSS 2.4 · Low
evidence mentions
3
Buzz score
18.9

CVE-2026-54775

Published Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service listening on a Kafka topic stops processi…

CVSS 6.5 · Medium
evidence mentions
6
Buzz score
24.5

CVE-2026-58208

Published Jul 8, 2026

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a WebSocket listener could route requests for the MQ…

CVSS 6.8 · Medium
evidence mentions
6
Buzz score
29.5
Vendor/product tagsBeta · best-effort

CVE-2026-59892

Published Jul 8, 2026

OpenTelemetry JavaScript is the OpenTelemetry JavaScript client. Prior to 2.9.0, @opentelemetry/propagator-jaeger decodes incoming uber-trace-id and uberctx-* HTTP header values w…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-59875

Published Jul 8, 2026

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
26.1

CVE-2026-27844

Published Jul 7, 2026

Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated and authorized operator to trigger a Controller restart by…

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-27790

Published Jul 7, 2026

Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by sending specific requests, resulting in a temporary denial…

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 239 CVEsPage 1 of 10