Skip to content
Noroxi

CWE-248 · 300 records

Uncaught Exception

CVEs in this class

300 records

  • A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK 828D V4.7 (All vers

    CriticalCVSS 9.8No exploitEPSS 4%

    siemens · sinumerik 808d v4.7 firmwareDec 12, 2018

  • Denial of Service - Protocol Manipulation

    CriticalCVSS 10.0No exploitEPSS 0%

    azure-access · blu-ic2 firmwareOct 28, 2025

  • Namada-apps allows Post-Genesis Validator Bypass

    CriticalCVSS 9.5No exploit

    crates.io · namada-appsFeb 20, 2025

  • MCP SDK Vulnerable to FastMCP Server Validation Error, Leading to Denial of Service

    HighCVSS 8.7No exploitEPSS 9%

    modelcontextprotocol · python-sdkJul 4, 2025

  • vm2 3.10.0 through 3.11.7 Denial of Service via Host Promise

    CriticalCVSS 9.2No exploitEPSS 0%

    patriksimek · vm2Sep 17, 2026

  • Crashing any Qwik Server

    CriticalCVSS 9.2No exploitEPSS 0%

    qwikdev · qwikJul 9, 2025

  • Sysax Multi-Server <= 6.10 SSHD Key Exchange DoS

    HighCVSS 8.7WeaponizedEPSS 2%

    sysax · multi serverAug 5, 2025

  • CVE-2023-0790
    35Monitor

    Uncaught Exception in thorsten/phpmyfaq

    HighCVSS 8.8No exploitEPSS 1%

    phpmyfaq · phpmyfaqFeb 12, 2023

  • websocket-driver: Denial of service via malformed Host header

    HighCVSS 8.9No exploitEPSS 0%

    faye · websocket-driver-rubyAug 17, 2026

  • vm2 before 3.12.2 Host Process Termination via Construct Trap

    HighCVSS 8.9No exploitEPSS 0%

    patriksimek · vm2Sep 26, 2026

  • Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing

    HighCVSS 8.7No exploitEPSS 1%

    quinn-rs · quinnMar 10, 2026

  • go-ethereum has a DoS via malicious p2p message

    HighCVSS 8.7No exploitEPSS 1%

    ethereum · go-ethereumJan 30, 2025

  • JavaScript specification issue may lead to type confusion and pointer dereference in implementations

    HighCVSS 8.6No exploitEPSS 1%

    tc39 · ecma262Aug 15, 2024

  • vm2: Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS)

    HighCVSS 8.6No exploitEPSS 1%

    vm2 project · vm2May 13, 2026

  • SurrealDB before 1.1.0 Denial of Service via HTTP Headers

    HighCVSS 8.7No exploitEPSS 1%

    surrealdb · surrealdbJul 18, 2026

  • A vulnerability in ICMPv6 processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software c

    HighCVSS 8.6No exploitEPSS 1%

    cisco · adaptive security appliance softwareNov 1, 2023

  • vLLM through 0.29.0 Denial of Service via Incomplete NIXL KV Transfer Metadata

    HighCVSS 8.7No exploitEPSS 1%

    vllm · vllmSep 21, 2026

  • Yamux remote Panic via malformed Data frame with SYN set and len = 262145

    HighCVSS 8.7No exploitEPSS 1%

    protocol · yamuxMar 16, 2026

  • Pocketbase: Unhandled panic in worker goroutines

    HighCVSS 8.7No exploitEPSS 1%

    pocketbase · pocketbaseSep 16, 2026

  • CVE-2026-9509
    34Monitor

    Uncaught exception vulnerability in Suprema's BioStar

    HighCVSS 8.7No exploitEPSS 1%

    suprema · biostar 2 (server)May 29, 2026

  • SurrealDB before 3.1.0 Denial of Service via malformed RPC use

    HighCVSS 8.7No exploitEPSS 1%

    surrealdb · surrealdbJul 20, 2026

  • Haraka affected by DoS via `__proto__` email header

    HighCVSS 8.7No exploitEPSS 1%

    haraka project · harakaApr 2, 2026

  • gitoxide before 0.69.0 Denial of Service via gix-pack

    HighCVSS 8.7No exploitEPSS 0%

    gitoxidelabs · gitoxideAug 28, 2026

  • Kanidm: Unauthenticated process abort via SCIM filter stack exhaustion

    HighCVSS 8.7No exploitEPSS 0%

    kanidm · kanidmJun 10, 2026

  • Apache Thrift: Node.js `server.js` ends the process on any per-connection error (+ two triggers)

    HighCVSS 8.7No exploitEPSS 0%

    apache software foundation · apache thriftOct 2, 2026

All vulnerability classes