Skip to content
Noroxi

CWE-754 · 561 records

Improper Check for Unusual or Exceptional Conditions

CVEs in this class

561 records

  • CVE-2024-3393
    73This week

    PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet

    HighCVSS 8.7KEVWeaponizedEPSS 28%

    paloaltonetworks · pan-osDec 27, 2024

  • CVE-2023-41993
    72This week

    The issue was addressed with improved checks.

    HighCVSS 8.8KEVWeaponizedEPSS 24%

    apple · ipadosSep 21, 2023

  • CVE-2025-39682
    70This week

    tls: fix handling of zero-length records on the rx_list

    CriticalCVSS 9.8KEVWeaponizedEPSS 3%

    linux · linux kernelSep 5, 2025

  • CVE-2023-41992
    64This week

    The issue was addressed with improved checks.

    HighCVSS 7.8KEVWeaponizedEPSS 10%

    apple · ipadosSep 21, 2023

  • A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context.

    HighCVSS 8.8Proof of conceptEPSS 71%

    mozilla · firefoxMay 14, 2024

  • Denial of service in Fastify via Content-Type header

    HighCVSS 7.5No exploitEPSS 59%

    fastify · fastifyOct 10, 2022

  • Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by

    HighCVSS 8.8Proof of conceptEPSS 29%

    jenkins · jenkinsAug 7, 2024

  • In transportDec_OutOfBandConfig of tpdec_lib.cpp, there is a possible out of bounds write due to a heap buffer overflow.

    CriticalCVSS 9.8Proof of conceptEPSS 9%

    google · androidJun 15, 2022

  • is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which

    CriticalCVSS 9.8No exploitEPSS 8%

    wordpress · wordpressNov 2, 2020

  • pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.

    CriticalCVSS 9.8No exploitEPSS 5%

    sqlite · sqliteDec 9, 2019

  • An issue was discovered in psd-tools before 1.9.4.

    CriticalCVSS 9.8No exploitEPSS 2%

    psd-tools project · psd-toolsMar 14, 2020

  • Junos OS and Junos OS Evolved: Upon receipt of a specific BGP FlowSpec message network traffic may be disrupted.

    CriticalCVSS 10.0No exploitEPSS 1%

    juniper · junosJan 15, 2021

  • Incorrect Content-Type Header

    CriticalCVSS 10.0No exploitEPSS 0%

    azure-access · blu-ic2 firmwareOct 17, 2025

  • CVE-2020-8986
    39Monitor

    lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cookie, allowing an atta

    CriticalCVSS 9.8No exploitEPSS 2%

    zend · zendtoMar 24, 2020

  • Ecto 2.2.0 lacks a certain protection mechanism associated with the interaction between is_nil and raise.

    CriticalCVSS 9.8No exploitEPSS 1%

    ecto project · ectoJan 10, 2023

  • Sylabs Singularity 3.5.x and 3.6.x, and SingularityPRO before 3.5-8, has an Incorrect Check of a Function's Return Value.

    CriticalCVSS 9.8No exploitEPSS 1%

    sylabs · singularityJun 15, 2021

  • A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of se

    CriticalCVSS 9.8No exploitEPSS 1%

    schneider-electric · ecostruxure control expertJan 30, 2023

  • An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3.

    CriticalCVSS 9.8No exploitEPSS 1%

    mediawiki · mediawikiJun 30, 2023

  • Azure RTOS USBX Remote Code Execution Vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    eclipse · threadx usbxDec 4, 2023

  • Azure RTOS USBX Remote Code Execution Vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    eclipse · threadx usbxDec 4, 2023

  • CVE-2026-8091
    39Monitor

    Incorrect boundary conditions in the Audio/Video: Playback component

    CriticalCVSS 9.8No exploitEPSS 1%

    mozilla · firefoxMay 7, 2026

  • Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3

    CriticalCVSS 9.8No exploitEPSS 1%

    synology · diskstation managerMay 27, 2026

  • CVE-2024-7826
    39Monitor

    Unhandled exception vulnerability that can cause the WRSA.exe service to crash and generate a crash dump

    CriticalCVSS 9.8No exploitEPSS 0%

    webroot · secureanywhere web shieldOct 3, 2024

  • RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr

    CriticalCVSS 9.5No exploitEPSS 1%

    rabbitmq · amqp091-goSep 16, 2026

  • CVE-2026-0667
    37Monitor

    CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and

    CriticalCVSS 9.3No exploitEPSS 1%

    schneider electric · scadapack 47xJul 29, 2026

All vulnerability classes