Skip to main content

CWE archive

CWE-754 CVEs

Programmatic archive

604 CVEs tagged with CWE-75420 Critical, 249 High, 293 Medium, 42 Low, 0 Unrated.

CVE-2024-1556

Published Feb 20, 2024

The incorrect object was checked for NULL in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This issue only affects the applic…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25739

Published Feb 12, 2024

create_empty_lvol in drivers/mtd/ubi/vtbl.c in the Linux kernel through 6.7.4 can attempt to allocate zero bytes, and crash, because of a missing check for ubi->leb_size.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23650

Published Jan 31, 2024

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit client or frontend could craft a reques…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24567

Published Jan 30, 2024

Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. Vyper compiler allows passing a value in builtin raw_call even if the call is a delegatecall or a sta…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22422

Published Jan 19, 2024

AnythingLLM is an application that turns any document, resource, or piece of content into context that any LLM can use as references during chatting. In versions prior to commit `…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34348

Published Jan 18, 2024

AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to remotely crash the PI Message Subsystem of a PI Server…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-21614

Published Jan 12, 2024

An Improper Check for Unusual or Exceptional Conditions vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, un…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-21603

Published Jan 12, 2024

An Improper Check for Unusual or Exceptional Conditions vulnerability in the kernel of Juniper Network Junos OS on MX Series allows a network based attacker with low privileges to…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6742

Published Jan 11, 2024

The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'envira_…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-52079

Published Dec 28, 2023

msgpackr is a fast MessagePack NodeJS/JavaScript implementation. Prior to 1.10.1, when decoding user supplied MessagePack messages, users can trigger stuck threads by crafting mes…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32726

Published Dec 18, 2023

The vulnerability is caused by improper check for check if RDLENGTH does not overflow the buffer in response from DNS server.

CVSS 3.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-48431

Published Dec 12, 2023

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected software does not correctly validate the response received by an UMC server. An attac…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48429

Published Dec 12, 2023

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The Web UI of affected devices does not check the length of parameters in certain conditions.…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-49607

Published Dec 12, 2023

Mattermost fails to validate the type of the "reminder" body request parameter allowing an attacker to crash the Playbook Plugin when updating the status dialog.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-44099

Published Dec 6, 2023

Vulnerability of data verification errors in the kernel module. Successful exploitation of this vulnerability may cause WLAN interruption.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-48698

Published Dec 5, 2023

Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause remote code execution due to exp…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48696

Published Dec 5, 2023

Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause remote code execution due to exp…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49286

Published Dec 4, 2023

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Incorrect Check of Function Return Value bug Squid is vulnerable to a Denial of Service attac…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-5967

Published Nov 6, 2023

Mattermost fails to properly validate requests to the Calls plugin, allowing an attacker sending a request without a User Agent header to cause a panic and crash the Calls plugin

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 301-325 of 604 CVEsPage 13 of 25