Skip to main content

CWE archive

CWE-833 CVEs

Programmatic archive

24 CVEs tagged with CWE-8330 Critical, 9 High, 14 Medium, 1 Low, 0 Unrated.

CVE-2026-10647

Published Jun 29, 2026

The USB CDC-NCM device class (subsys/usb/device_next/class/usbd_cdc_ncm.c) ignores the return value of usbd_ep_enqueue() in its ethernet transmit callback cdc_ncm_send(). When the…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-47334

Published May 28, 2026

Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unpriv…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44579

Published May 13, 2026

Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components fea…

CVSS 7.5 · High
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2026-33904

Published Mar 27, 2026

Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, a deadlock in the AMF's SCTP notification handler causes the entire AMF control plane to hang until t…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2024-48077

Published Jan 15, 2026

NanoMQ v0.22.7 is vulnerable to Denial of Service (DoS) due to improper resource throttling. A crafted sequence of requests causes the recv-q queue to saturate, leading to the rap…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-10150

Published Oct 28, 2025

Webserver crash caused by scanning on TCP port 80 in Softing Industrial Automation GmbH gateways and switch.This issue affects smartLink HW-PN: from 1.02 through 1.03 smartLink…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0

CVE-2025-54796

Published Aug 2, 2025

Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows arbitrary RegExes. If this feature is enabled (which is th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-8312

Published Jul 30, 2025

Deadlock in PAM automatic check-in feature in Devolutions Server allows a password to remain valid beyond the end of its intended check-out period due to a deadlock occurring in t…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-36010

Published Jul 29, 2025

IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 could allow an unauthenticated user to cause a denial of service due to executable segments that are waiting for each other to relea…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1713

Published Jul 17, 2025

When setting up interrupt remapping for legacy PCI(-X) devices, including PCI(-X) bridges, a lookup of the upstream bridge is required. This lookup, itself involving acquiring of…

CVSS 7.5 · High
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2024-29172

Published Feb 12, 2025

Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains a deadlock vulnerability. A remote attacker could potentially exploit this vulnerability, leading to…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8447

Published Jan 2, 2025

A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds occurs. If Join is called…

CVSS 5.9 · Medium

CVE-2024-47506

Published Oct 11, 2024

A Deadlock vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial of Se…

CVSS 8.2 · High

CVE-2024-0639

Published Jan 17, 2024

A denial of service vulnerability due to a deadlock was found in sctp_auto_asconf_init in net/sctp/socket.c in the Linux kernel’s SCTP subsystem. This flaw allows guests with loca…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2023-42441

Published Sep 18, 2023

Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). Starting in version 0.2.9 and prior to version 0.3.10, locks of the type `@nonreentrant("")` or…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3436

Published Jun 27, 2023

Xpdf 4.04 will deadlock on a PDF object stream whose "Length" field is itself in another object stream.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-4269

Published Dec 5, 2022

A flaw was found in the Linux kernel Traffic Control (TC) subsystem. Using a specific networking configuration (redirecting egress packets to ingress using TC action "mirred") a l…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1622

Published Sep 23, 2021

A vulnerability in the Common Open Policy Service (COPS) of Cisco IOS XE Software for Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to ca…

CVSS 8.6 · High
Showing 1-24 of 24 CVEsPage 1 of 1