CWE-248 · 300 records
Uncaught Exception
CVEs in this class
300 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2018-11466No exploit | A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK 828D V4.7 (All verssiemens · sinumerik 808d v4.7 firmware · CWE-248 | Critical9.8 | — | 4.0% | Dec 12, 2018 |
40Plan | CVE-2025-12423No exploit | Denial of Service - Protocol Manipulationazure-access · blu-ic2 firmware · CWE-248 | Critical10.0 | — | 0.3% | Oct 28, 2025 |
38Monitor | GHSA-2gw2-qgjg-xh6pNo exploit | Namada-apps allows Post-Genesis Validator Bypasscrates.io · namada-apps · CWE-248 | Critical9.5 | — | — | Feb 20, 2025 |
37Monitor | CVE-2025-53366No exploit | MCP SDK Vulnerable to FastMCP Server Validation Error, Leading to Denial of Servicemodelcontextprotocol · python-sdk · CWE-248 | High8.7 | — | 9.3% | Jul 4, 2025 |
36Monitor | CVE-2026-92954No exploit | vm2 3.10.0 through 3.11.7 Denial of Service via Host Promisepatriksimek · vm2 · CWE-248 | Critical9.2 | — | 0.5% | Sep 17, 2026 |
36Monitor | CVE-2025-53620No exploit | Crashing any Qwik Serverqwikdev · qwik · CWE-248 | Critical9.2 | — | 0.4% | Jul 9, 2025 |
35Monitor | CVE-2013-10065Weaponized | Sysax Multi-Server <= 6.10 SSHD Key Exchange DoSsysax · multi server · CWE-248 | High8.7 | — | 1.7% | Aug 5, 2025 |
35Monitor | CVE-2023-0790No exploit | Uncaught Exception in thorsten/phpmyfaqphpmyfaq · phpmyfaq · CWE-248 | High8.8 | — | 0.7% | Feb 12, 2023 |
35Monitor | CVE-2026-61666No exploit | websocket-driver: Denial of service via malformed Host headerfaye · websocket-driver-ruby · CWE-248 | High8.9 | — | 0.4% | Aug 17, 2026 |
35Monitor | CVE-2026-100722No exploit | vm2 before 3.12.2 Host Process Termination via Construct Trappatriksimek · vm2 · CWE-248 | High8.9 | — | 0.3% | Sep 26, 2026 |
34Monitor | CVE-2026-31812No exploit | Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsingquinn-rs · quinn · CWE-248 | High8.7 | — | 0.9% | Mar 10, 2026 |
34Monitor | CVE-2025-24883No exploit | go-ethereum has a DoS via malicious p2p messageethereum · go-ethereum · CWE-248 | High8.7 | — | 0.7% | Jan 30, 2025 |
34Monitor | CVE-2024-43357No exploit | JavaScript specification issue may lead to type confusion and pointer dereference in implementationstc39 · ecma262 · CWE-248 | High8.6 | — | 0.7% | Aug 15, 2024 |
34Monitor | CVE-2026-44001No exploit | vm2: Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS)vm2 project · vm2 · CWE-248 | High8.6 | — | 0.7% | May 13, 2026 |
34Monitor | CVE-2024-58368No exploit | SurrealDB before 1.1.0 Denial of Service via HTTP Headerssurrealdb · surrealdb · CWE-248 | High8.7 | — | 0.7% | Jul 18, 2026 |
34Monitor | CVE-2023-20086No exploit | A vulnerability in ICMPv6 processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software ccisco · adaptive security appliance software · CWE-248 | High8.6 | — | 0.7% | Nov 1, 2023 |
34Monitor | CVE-2026-94622No exploit | vLLM through 0.29.0 Denial of Service via Incomplete NIXL KV Transfer Metadatavllm · vllm · CWE-248 | High8.7 | — | 0.6% | Sep 21, 2026 |
34Monitor | CVE-2026-32314No exploit | Yamux remote Panic via malformed Data frame with SYN set and len = 262145protocol · yamux · CWE-248 | High8.7 | — | 0.6% | Mar 16, 2026 |
34Monitor | CVE-2026-82410No exploit | Pocketbase: Unhandled panic in worker goroutinespocketbase · pocketbase · CWE-248 | High8.7 | — | 0.6% | Sep 16, 2026 |
34Monitor | CVE-2026-9509No exploit | Uncaught exception vulnerability in Suprema's BioStarsuprema · biostar 2 (server) · CWE-248 | High8.7 | — | 0.5% | May 29, 2026 |
34Monitor | CVE-2026-63747No exploit | SurrealDB before 3.1.0 Denial of Service via malformed RPC usesurrealdb · surrealdb · CWE-248 | High8.7 | — | 0.5% | Jul 20, 2026 |
34Monitor | CVE-2026-34752No exploit | Haraka affected by DoS via `__proto__` email headerharaka project · haraka · CWE-248 | High8.7 | — | 0.5% | Apr 2, 2026 |
34Monitor | CVE-2026-82254No exploit | gitoxide before 0.69.0 Denial of Service via gix-packgitoxidelabs · gitoxide · CWE-248 | High8.7 | — | 0.5% | Aug 28, 2026 |
34Monitor | CVE-2026-46689No exploit | Kanidm: Unauthenticated process abort via SCIM filter stack exhaustionkanidm · kanidm · CWE-248 | High8.7 | — | 0.5% | Jun 10, 2026 |
34Monitor | CVE-2026-94646No exploit | Apache Thrift: Node.js `server.js` ends the process on any per-connection error (+ two triggers)apache software foundation · apache thrift · CWE-248 | High8.7 | — | 0.5% | Oct 2, 2026 |
- CVE-2018-1146640Plan
A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK 828D V4.7 (All vers
CriticalCVSS 9.8No exploitEPSS 4%siemens · sinumerik 808d v4.7 firmwareDec 12, 2018
- CVE-2025-1242340Plan
Denial of Service - Protocol Manipulation
CriticalCVSS 10.0No exploitEPSS 0%azure-access · blu-ic2 firmwareOct 28, 2025
- GHSA-2gw2-qgjg-xh6p38Monitor
Namada-apps allows Post-Genesis Validator Bypass
CriticalCVSS 9.5No exploitcrates.io · namada-appsFeb 20, 2025
- CVE-2025-5336637Monitor
MCP SDK Vulnerable to FastMCP Server Validation Error, Leading to Denial of Service
HighCVSS 8.7No exploitEPSS 9%modelcontextprotocol · python-sdkJul 4, 2025
- CVE-2026-9295436Monitor
vm2 3.10.0 through 3.11.7 Denial of Service via Host Promise
CriticalCVSS 9.2No exploitEPSS 0%patriksimek · vm2Sep 17, 2026
- CVE-2025-5362036Monitor
Crashing any Qwik Server
CriticalCVSS 9.2No exploitEPSS 0%qwikdev · qwikJul 9, 2025
- CVE-2013-1006535Monitor
Sysax Multi-Server <= 6.10 SSHD Key Exchange DoS
HighCVSS 8.7WeaponizedEPSS 2%sysax · multi serverAug 5, 2025
- CVE-2023-079035Monitor
Uncaught Exception in thorsten/phpmyfaq
HighCVSS 8.8No exploitEPSS 1%phpmyfaq · phpmyfaqFeb 12, 2023
- CVE-2026-6166635Monitor
websocket-driver: Denial of service via malformed Host header
HighCVSS 8.9No exploitEPSS 0%faye · websocket-driver-rubyAug 17, 2026
- CVE-2026-10072235Monitor
vm2 before 3.12.2 Host Process Termination via Construct Trap
HighCVSS 8.9No exploitEPSS 0%patriksimek · vm2Sep 26, 2026
- CVE-2026-3181234Monitor
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
HighCVSS 8.7No exploitEPSS 1%quinn-rs · quinnMar 10, 2026
- CVE-2025-2488334Monitor
go-ethereum has a DoS via malicious p2p message
HighCVSS 8.7No exploitEPSS 1%ethereum · go-ethereumJan 30, 2025
- CVE-2024-4335734Monitor
JavaScript specification issue may lead to type confusion and pointer dereference in implementations
HighCVSS 8.6No exploitEPSS 1%tc39 · ecma262Aug 15, 2024
- CVE-2026-4400134Monitor
vm2: Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS)
HighCVSS 8.6No exploitEPSS 1%vm2 project · vm2May 13, 2026
- CVE-2024-5836834Monitor
SurrealDB before 1.1.0 Denial of Service via HTTP Headers
HighCVSS 8.7No exploitEPSS 1%surrealdb · surrealdbJul 18, 2026
- CVE-2023-2008634Monitor
A vulnerability in ICMPv6 processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software c
HighCVSS 8.6No exploitEPSS 1%cisco · adaptive security appliance softwareNov 1, 2023
- CVE-2026-9462234Monitor
vLLM through 0.29.0 Denial of Service via Incomplete NIXL KV Transfer Metadata
HighCVSS 8.7No exploitEPSS 1%vllm · vllmSep 21, 2026
- CVE-2026-3231434Monitor
Yamux remote Panic via malformed Data frame with SYN set and len = 262145
HighCVSS 8.7No exploitEPSS 1%protocol · yamuxMar 16, 2026
- CVE-2026-8241034Monitor
Pocketbase: Unhandled panic in worker goroutines
HighCVSS 8.7No exploitEPSS 1%pocketbase · pocketbaseSep 16, 2026
- CVE-2026-950934Monitor
Uncaught exception vulnerability in Suprema's BioStar
HighCVSS 8.7No exploitEPSS 1%suprema · biostar 2 (server)May 29, 2026
- CVE-2026-6374734Monitor
SurrealDB before 3.1.0 Denial of Service via malformed RPC use
HighCVSS 8.7No exploitEPSS 1%surrealdb · surrealdbJul 20, 2026
- CVE-2026-3475234Monitor
Haraka affected by DoS via `__proto__` email header
HighCVSS 8.7No exploitEPSS 1%haraka project · harakaApr 2, 2026
- CVE-2026-8225434Monitor
gitoxide before 0.69.0 Denial of Service via gix-pack
HighCVSS 8.7No exploitEPSS 0%gitoxidelabs · gitoxideAug 28, 2026
- CVE-2026-4668934Monitor
Kanidm: Unauthenticated process abort via SCIM filter stack exhaustion
HighCVSS 8.7No exploitEPSS 0%kanidm · kanidmJun 10, 2026
- CVE-2026-9464634Monitor
Apache Thrift: Node.js `server.js` ends the process on any per-connection error (+ two triggers)
HighCVSS 8.7No exploitEPSS 0%apache software foundation · apache thriftOct 2, 2026