Skip to main content

CWE archive

CWE-252 CVEs

Programmatic archive

174 CVEs tagged with CWE-25210 Critical, 67 High, 85 Medium, 12 Low, 0 Unrated.

CVE-2026-21498

Published Jan 7, 2026

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vu…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-21497

Published Jan 7, 2026

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vu…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-21496

Published Jan 7, 2026

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vu…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-21492

Published Jan 6, 2026

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versi…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2025-66565

Published Dec 9, 2025

Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's cryptographic random number generator (crypto/rand) fails, b…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-64169

Published Nov 21, 2025

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 3.7.0 to before 4.12.0, fim_alert() implementation does not check whethe…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62791

Published Oct 29, 2025

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, DecodeCiscat() implementation does not check the return the value of…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62790

Published Oct 29, 2025

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, fim_fetch_attributes_state() implementation does not check whether t…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62789

Published Oct 29, 2025

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, fim_alert() implementation does not check whether the return value o…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62785

Published Oct 29, 2025

Wazuh is a free and open source platform used for threat prevention, detection, and response. fillData() implementation does not check whether value is NULL or not before calling…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-11839

Published Oct 16, 2025

A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing a manipulation results in unchecked return value. Th…

CVSS 1.9 · Low
evidence mentions
8
Buzz score
42.0
Vendor/product tagsBeta · best-effort

CVE-2025-58903

Published Oct 14, 2025

An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API allows an authenticated user to cause a Null Pointer Derefe…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-38602

Published Aug 19, 2025

In the Linux kernel, the following vulnerability has been resolved: iwlwifi: Add missing check for alloc_ordered_workqueue Add check for the return value of alloc_ordered_workqu…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54571

Published Aug 6, 2025

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versions 2.9.11 and below, an attacker can override the HTTP resp…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1394

Published Jul 30, 2025

The Ember ZNet stack’s packet buffer manager may read out of bound memory leading to an assert, causing a Denial of Service (DoS).

CVSS 5.9 · Medium
evidence mentions
4
Buzz score
26.1

CVE-2023-53070

Published May 2, 2025

In the Linux kernel, the following vulnerability has been resolved: ACPI: PPTT: Fix to avoid sleep in the atomic context when PPTT is absent Commit 0c80f9e165f8 ("ACPI: PPTT: Le…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46672

Published Apr 27, 2025

NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-22026

Published Apr 16, 2025

In the Linux kernel, the following vulnerability has been resolved: nfsd: don't ignore the return code of svc_proc_register() Currently, nfsd_proc_stat_init() ignores the return…

CVSS 5.5 · Medium
evidence mentions
8
Buzz score
27.0
Vendor/product tagsBeta · best-effort

CVE-2025-32414

Published Apr 8, 2025

In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an incorrect return value. This occurs in x…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12650

Published Mar 5, 2025

An attacker with low privileges can manipulate the requested memory size, causing the application to use an invalid memory area. This could lead to a crash of the application but…

CVSS 5.4 · Medium

CVE-2025-25724

Published Mar 2, 2025

list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafte…

CVSS 4.0 · Medium
evidence mentions
3
Buzz score
24.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-45775

Published Feb 18, 2025

A flaw was found in grub2 where the grub_extcmd_dispatcher() function calls grub_arg_list_alloc() to allocate memory for the grub's argument list. However, it fails to check in ca…

CVSS 5.2 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2025-0518

Published Jan 16, 2025

Unchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read Sensitive Constants Within an Executable. This vulnerability is associated with program files https…

CVSS 4.8 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort
Showing 26-50 of 174 CVEsPage 2 of 7