CWE-754 · 561 records
Improper Check for Unusual or Exceptional Conditions
CVEs in this class
561 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
73This week | CVE-2024-3393Weaponized | PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packetpaloaltonetworks · pan-os · CWE-754 | High8.7 | KEV | 28.4% | Dec 27, 2024 |
72This week | CVE-2023-41993Weaponized | The issue was addressed with improved checks.apple · ipados · CWE-754 | High8.8 | KEV | 24.3% | Sep 21, 2023 |
70This week | CVE-2025-39682Weaponized | tls: fix handling of zero-length records on the rx_listlinux · linux kernel · CWE-754 | Critical9.8 | KEV | 2.9% | Sep 5, 2025 |
64This week | CVE-2023-41992Weaponized | The issue was addressed with improved checks.apple · ipados · CWE-754 | High7.8 | KEV | 9.5% | Sep 21, 2023 |
56Plan | CVE-2024-4367Proof of concept | A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context.mozilla · firefox · CWE-754 | High8.8 | — | 70.7% | May 14, 2024 |
48Plan | CVE-2022-39288No exploit | Denial of service in Fastify via Content-Type headerfastify · fastify · CWE-754 | High7.5 | — | 59.2% | Oct 10, 2022 |
44Plan | CVE-2024-43044Proof of concept | Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system byjenkins · jenkins · CWE-754 | High8.8 | — | 28.8% | Aug 7, 2024 |
42Plan | CVE-2022-20130Proof of concept | In transportDec_OutOfBandConfig of tpdec_lib.cpp, there is a possible out of bounds write due to a heap buffer overflow.google · android · CWE-754 | Critical9.8 | — | 8.5% | Jun 15, 2022 |
41Plan | CVE-2020-28037No exploit | is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, whichwordpress · wordpress · CWE-754 | Critical9.8 | — | 8.1% | Nov 2, 2020 |
41Plan | CVE-2019-19646No exploit | pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.sqlite · sqlite · CWE-754 | Critical9.8 | — | 5.4% | Dec 9, 2019 |
40Plan | CVE-2020-10571No exploit | An issue was discovered in psd-tools before 1.9.4.psd-tools project · psd-tools · CWE-754 | Critical9.8 | — | 1.8% | Mar 14, 2020 |
40Plan | CVE-2021-0211No exploit | Junos OS and Junos OS Evolved: Upon receipt of a specific BGP FlowSpec message network traffic may be disrupted.juniper · junos · CWE-754 | Critical10.0 | — | 1.3% | Jan 15, 2021 |
40Plan | CVE-2025-11925No exploit | Incorrect Content-Type Headerazure-access · blu-ic2 firmware · CWE-754 | Critical10.0 | — | 0.3% | Oct 17, 2025 |
39Monitor | CVE-2020-8986No exploit | lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cookie, allowing an attazend · zendto · CWE-754 | Critical9.8 | — | 1.5% | Mar 24, 2020 |
39Monitor | CVE-2017-20166No exploit | Ecto 2.2.0 lacks a certain protection mechanism associated with the interaction between is_nil and raise.ecto project · ecto · CWE-754 | Critical9.8 | — | 1.3% | Jan 10, 2023 |
39Monitor | CVE-2021-33622No exploit | Sylabs Singularity 3.5.x and 3.6.x, and SingularityPRO before 3.5-8, has an Incorrect Check of a Function's Return Value.sylabs · singularity · CWE-754 | Critical9.8 | — | 1.3% | Jun 15, 2021 |
39Monitor | CVE-2022-45788No exploit | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of seschneider-electric · ecostruxure control expert · CWE-754 | Critical9.8 | — | 1.2% | Jan 30, 2023 |
39Monitor | CVE-2023-37303No exploit | An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3.mediawiki · mediawiki · CWE-754 | Critical9.8 | — | 1.0% | Jun 30, 2023 |
39Monitor | CVE-2023-48696No exploit | Azure RTOS USBX Remote Code Execution Vulnerabilityeclipse · threadx usbx · CWE-754 | Critical9.8 | — | 0.9% | Dec 4, 2023 |
39Monitor | CVE-2023-48698No exploit | Azure RTOS USBX Remote Code Execution Vulnerabilityeclipse · threadx usbx · CWE-754 | Critical9.8 | — | 0.9% | Dec 4, 2023 |
39Monitor | CVE-2026-8091No exploit | Incorrect boundary conditions in the Audio/Video: Playback componentmozilla · firefox · CWE-754 | Critical9.8 | — | 0.6% | May 7, 2026 |
39Monitor | CVE-2025-13392No exploit | Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3synology · diskstation manager · CWE-754 | Critical9.8 | — | 0.5% | May 27, 2026 |
39Monitor | CVE-2024-7826No exploit | Unhandled exception vulnerability that can cause the WRSA.exe service to crash and generate a crash dumpwebroot · secureanywhere web shield · CWE-754 | Critical9.8 | — | 0.4% | Oct 3, 2024 |
38Monitor | CVE-2026-77411No exploit | RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstrrabbitmq · amqp091-go · CWE-754 | Critical9.5 | — | 0.5% | Sep 16, 2026 |
37Monitor | CVE-2026-0667No exploit | CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service andschneider electric · scadapack 47x · CWE-754 | Critical9.3 | — | 0.5% | Jul 29, 2026 |
- CVE-2024-339373This week
PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet
HighCVSS 8.7KEVWeaponizedEPSS 28%paloaltonetworks · pan-osDec 27, 2024
- CVE-2023-4199372This week
The issue was addressed with improved checks.
HighCVSS 8.8KEVWeaponizedEPSS 24%apple · ipadosSep 21, 2023
- CVE-2025-3968270This week
tls: fix handling of zero-length records on the rx_list
CriticalCVSS 9.8KEVWeaponizedEPSS 3%linux · linux kernelSep 5, 2025
- CVE-2023-4199264This week
The issue was addressed with improved checks.
HighCVSS 7.8KEVWeaponizedEPSS 10%apple · ipadosSep 21, 2023
- CVE-2024-436756Plan
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context.
HighCVSS 8.8Proof of conceptEPSS 71%mozilla · firefoxMay 14, 2024
- CVE-2022-3928848Plan
Denial of service in Fastify via Content-Type header
HighCVSS 7.5No exploitEPSS 59%fastify · fastifyOct 10, 2022
- CVE-2024-4304444Plan
Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by
HighCVSS 8.8Proof of conceptEPSS 29%jenkins · jenkinsAug 7, 2024
- CVE-2022-2013042Plan
In transportDec_OutOfBandConfig of tpdec_lib.cpp, there is a possible out of bounds write due to a heap buffer overflow.
CriticalCVSS 9.8Proof of conceptEPSS 9%google · androidJun 15, 2022
- CVE-2020-2803741Plan
is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which
CriticalCVSS 9.8No exploitEPSS 8%wordpress · wordpressNov 2, 2020
- CVE-2019-1964641Plan
pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.
CriticalCVSS 9.8No exploitEPSS 5%sqlite · sqliteDec 9, 2019
- CVE-2020-1057140Plan
An issue was discovered in psd-tools before 1.9.4.
CriticalCVSS 9.8No exploitEPSS 2%psd-tools project · psd-toolsMar 14, 2020
- CVE-2021-021140Plan
Junos OS and Junos OS Evolved: Upon receipt of a specific BGP FlowSpec message network traffic may be disrupted.
CriticalCVSS 10.0No exploitEPSS 1%juniper · junosJan 15, 2021
- CVE-2025-1192540Plan
Incorrect Content-Type Header
CriticalCVSS 10.0No exploitEPSS 0%azure-access · blu-ic2 firmwareOct 17, 2025
- CVE-2020-898639Monitor
lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cookie, allowing an atta
CriticalCVSS 9.8No exploitEPSS 2%zend · zendtoMar 24, 2020
- CVE-2017-2016639Monitor
Ecto 2.2.0 lacks a certain protection mechanism associated with the interaction between is_nil and raise.
CriticalCVSS 9.8No exploitEPSS 1%ecto project · ectoJan 10, 2023
- CVE-2021-3362239Monitor
Sylabs Singularity 3.5.x and 3.6.x, and SingularityPRO before 3.5-8, has an Incorrect Check of a Function's Return Value.
CriticalCVSS 9.8No exploitEPSS 1%sylabs · singularityJun 15, 2021
- CVE-2022-4578839Monitor
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of se
CriticalCVSS 9.8No exploitEPSS 1%schneider-electric · ecostruxure control expertJan 30, 2023
- CVE-2023-3730339Monitor
An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3.
CriticalCVSS 9.8No exploitEPSS 1%mediawiki · mediawikiJun 30, 2023
- CVE-2023-4869639Monitor
Azure RTOS USBX Remote Code Execution Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%eclipse · threadx usbxDec 4, 2023
- CVE-2023-4869839Monitor
Azure RTOS USBX Remote Code Execution Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%eclipse · threadx usbxDec 4, 2023
- CVE-2026-809139Monitor
Incorrect boundary conditions in the Audio/Video: Playback component
CriticalCVSS 9.8No exploitEPSS 1%mozilla · firefoxMay 7, 2026
- CVE-2025-1339239Monitor
Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3
CriticalCVSS 9.8No exploitEPSS 1%synology · diskstation managerMay 27, 2026
- CVE-2024-782639Monitor
Unhandled exception vulnerability that can cause the WRSA.exe service to crash and generate a crash dump
CriticalCVSS 9.8No exploitEPSS 0%webroot · secureanywhere web shieldOct 3, 2024
- CVE-2026-7741138Monitor
RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr
CriticalCVSS 9.5No exploitEPSS 1%rabbitmq · amqp091-goSep 16, 2026
- CVE-2026-066737Monitor
CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and
CriticalCVSS 9.3No exploitEPSS 1%schneider electric · scadapack 47xJul 29, 2026