Skip to main content

CWE archive

CWE-754 CVEs

Programmatic archive

603 CVEs tagged with CWE-75420 Critical, 249 High, 293 Medium, 41 Low, 0 Unrated.

CVE-2023-32695

Published May 27, 2023

socket.io parser is a socket.io encoder and decoder written in JavaScript complying with version 5 of socket.io-protocol. A specially crafted Socket.IO packet can trigger an uncau…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-21102

Published May 15, 2023

In __efi_rt_asm_wrapper of efi-rt-wrapper.S, there is a possible bypass of shadow stack protection due to a logic error in the code. This could lead to local escalation of privile…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28979

Published Apr 17, 2023

An Improper Check for Unusual or Exceptional Conditions vulnerability in the kernel of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to bypass an integrity…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28976

Published Apr 17, 2023

An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, ne…

CVSS 7.5 · High

CVE-2023-28975

Published Apr 17, 2023

An Unexpected Status Code or Return Value vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated attacker with physical access to the device to cause a…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28974

Published Apr 17, 2023

An Improper Check for Unusual or Exceptional Conditions vulnerability in the bbe-smgd of Juniper Networks Junos OS allows an unauthenticated, adjacent attacker to cause a Denial o…

CVSS 7.4 · High

CVE-2023-28965

Published Apr 17, 2023

An Improper Check or Handling of Exceptional Conditions within the storm control feature of Juniper Networks Junos OS allows an attacker sending a high rate of traffic to cause a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27772

Published Apr 13, 2023

libiec61850 v1.5.1 was discovered to contain a segmentation violation via the function ControlObjectClient_setOrigin() at /client/client_control.c.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30456

Published Apr 10, 2023

An issue was discovered in arch/x86/kvm/vmx/nested.c in the Linux kernel before 6.2.8. nVMX on x86_64 lacks consistency checks for CR0 and CR4.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32846

Published Feb 17, 2023

HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107, function `pci_vtsock_proc_tx` in `virtio-sock` can lead to to uninitialized…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30692

Published Feb 16, 2023

Improper conditions check in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potentially enable denial of service via network access.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29523

Published Feb 16, 2023

Improper conditions check in the Open CAS software maintained by Intel(R) before version 22.3.1 may allow an authenticated user to potentially enable denial of service via local a…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-36794

Published Feb 16, 2023

Improper condition check in some Intel(R) SPS firmware before version SPS_E3_06.00.03.300.0 may allow a privileged user to potentially enable denial of service via local access.

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23626

Published Feb 9, 2023

go-bitfield is a simple bitfield package for the go language aiming to be more performant that the standard library. When feeding untrusted user input into the size parameter of `…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23931

Published Feb 7, 2023

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-45854

Published Feb 7, 2023

An improper check for unusual conditions in Zyxel NWA110AX firmware verisons prior to 6.50(ABTG.0)C0, which could allow a LAN attacker to cause a temporary denial-of-service (DoS)…

CVSS 4.3 · Medium

CVE-2022-45788

Published Jan 30, 2023

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & int…

CVSS 7.5 · High
evidence mentions
3
Buzz score
21.9
Showing 351-375 of 603 CVEsPage 15 of 25