Skip to main content

CWE archive

CWE-392 CVEs

Programmatic archive

12 CVEs tagged with CWE-3921 Critical, 6 High, 2 Medium, 3 Low, 0 Unrated.

CVE-2026-20005

Published Mar 4, 2026

Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine…

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-59398

Published Sep 15, 2025

The OCPP implementation in libocpp before 0.26.2 allows a denial of service (EVerest crash) via JSON input larger than 255 characters, because a CiString<255> object is created wi…

CVSS 3.1 · Low

CVE-2025-23270

Published Jul 17, 2025

NVIDIA Jetson Linux contains a vulnerability in UEFI Management mode, where an unprivileged local attacker may cause exposure of sensitive information via a side channel vulnerabi…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-26268

Published Apr 17, 2025

DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted Redis command. The validity of the scan cursor was not che…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-32743

Published Apr 10, 2025

In ConnMan through 1.44, the lookup string in ns_resolv in dnsproxy.c can be NULL or an empty string when the TC (Truncated) bit is set in a DNS response. This allows attackers to…

CVSS 9.0 · Critical

CVE-2024-12797

Published Feb 11, 2025

Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a server may fail to notice that the server was not authenticated, because handshakes don't abort as ex…

CVSS 6.3 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2024-39697

Published Jul 9, 2024

phonenumber is a library for parsing, formatting and validating international phone numbers. Since 0.3.4, the phonenumber parsing code may panic due to a panic-guarded out-of-boun…

CVSS 8.6 · High

CVE-2023-48430

Published Dec 12, 2023

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The REST API of affected devices does not check the length of parameters in certain conditions…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-42447

Published Sep 19, 2023

blurhash-rs is a pure Rust implementation of Blurhash, software for encoding images into ASCII strings that can be turned into a gradient of colors representing the original image…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-42444

Published Sep 19, 2023

phonenumber is a library for parsing, formatting and validating international phone numbers. Prior to versions `0.3.3+8.13.9` and `0.2.5+8.11.3`, the phonenumber parsing code may…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2017-2342

Published Jul 17, 2017

MACsec feature on Juniper Networks Junos OS 15.1X49 prior to 15.1X49-D100 on SRX300 series does not report errors when a secure link can not be established. It falls back to an un…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1