CWE-754 · 561 записей
Improper Check for Unusual or Exceptional Conditions
CVE этого класса
561 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
73На этой неделе | CVE-2024-3393Готовый эксплойт | PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packetpaloaltonetworks · pan-os · CWE-754 | Высокая8,7 | KEV | 28,4 % | 27 дек. 2024 г. |
72На этой неделе | CVE-2023-41993Готовый эксплойт | The issue was addressed with improved checks.apple · ipados · CWE-754 | Высокая8,8 | KEV | 24,3 % | 21 сент. 2023 г. |
70На этой неделе | CVE-2025-39682Готовый эксплойт | tls: fix handling of zero-length records on the rx_listlinux · linux kernel · CWE-754 | Критическая9,8 | KEV | 2,9 % | 5 сент. 2025 г. |
64На этой неделе | CVE-2023-41992Готовый эксплойт | The issue was addressed with improved checks.apple · ipados · CWE-754 | Высокая7,8 | KEV | 9,5 % | 21 сент. 2023 г. |
56В плане | CVE-2024-4367Proof of concept | A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context.mozilla · firefox · CWE-754 | Высокая8,8 | — | 70,7 % | 14 мая 2024 г. |
48В плане | CVE-2022-39288Эксплойта нет | Denial of service in Fastify via Content-Type headerfastify · fastify · CWE-754 | Высокая7,5 | — | 59,2 % | 10 окт. 2022 г. |
44В плане | CVE-2024-43044Proof of concept | Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system byjenkins · jenkins · CWE-754 | Высокая8,8 | — | 28,8 % | 7 авг. 2024 г. |
42В плане | CVE-2022-20130Proof of concept | In transportDec_OutOfBandConfig of tpdec_lib.cpp, there is a possible out of bounds write due to a heap buffer overflow.google · android · CWE-754 | Критическая9,8 | — | 8,5 % | 15 июн. 2022 г. |
41В плане | CVE-2020-28037Эксплойта нет | is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, whichwordpress · wordpress · CWE-754 | Критическая9,8 | — | 8,1 % | 2 нояб. 2020 г. |
41В плане | CVE-2019-19646Эксплойта нет | pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.sqlite · sqlite · CWE-754 | Критическая9,8 | — | 5,4 % | 9 дек. 2019 г. |
40В плане | CVE-2020-10571Эксплойта нет | An issue was discovered in psd-tools before 1.9.4.psd-tools project · psd-tools · CWE-754 | Критическая9,8 | — | 1,8 % | 14 мар. 2020 г. |
40В плане | CVE-2021-0211Эксплойта нет | Junos OS and Junos OS Evolved: Upon receipt of a specific BGP FlowSpec message network traffic may be disrupted.juniper · junos · CWE-754 | Критическая10,0 | — | 1,3 % | 15 янв. 2021 г. |
40В плане | CVE-2025-11925Эксплойта нет | Incorrect Content-Type Headerazure-access · blu-ic2 firmware · CWE-754 | Критическая10,0 | — | 0,3 % | 17 окт. 2025 г. |
39Наблюдать | CVE-2020-8986Эксплойта нет | lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cookie, allowing an attazend · zendto · CWE-754 | Критическая9,8 | — | 1,5 % | 24 мар. 2020 г. |
39Наблюдать | CVE-2017-20166Эксплойта нет | Ecto 2.2.0 lacks a certain protection mechanism associated with the interaction between is_nil and raise.ecto project · ecto · CWE-754 | Критическая9,8 | — | 1,3 % | 10 янв. 2023 г. |
39Наблюдать | CVE-2021-33622Эксплойта нет | Sylabs Singularity 3.5.x and 3.6.x, and SingularityPRO before 3.5-8, has an Incorrect Check of a Function's Return Value.sylabs · singularity · CWE-754 | Критическая9,8 | — | 1,3 % | 15 июн. 2021 г. |
39Наблюдать | CVE-2022-45788Эксплойта нет | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of seschneider-electric · ecostruxure control expert · CWE-754 | Критическая9,8 | — | 1,2 % | 30 янв. 2023 г. |
39Наблюдать | CVE-2023-37303Эксплойта нет | An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3.mediawiki · mediawiki · CWE-754 | Критическая9,8 | — | 1,0 % | 30 июн. 2023 г. |
39Наблюдать | CVE-2023-48696Эксплойта нет | Azure RTOS USBX Remote Code Execution Vulnerabilityeclipse · threadx usbx · CWE-754 | Критическая9,8 | — | 0,9 % | 4 дек. 2023 г. |
39Наблюдать | CVE-2023-48698Эксплойта нет | Azure RTOS USBX Remote Code Execution Vulnerabilityeclipse · threadx usbx · CWE-754 | Критическая9,8 | — | 0,9 % | 4 дек. 2023 г. |
39Наблюдать | CVE-2026-8091Эксплойта нет | Incorrect boundary conditions in the Audio/Video: Playback componentmozilla · firefox · CWE-754 | Критическая9,8 | — | 0,6 % | 7 мая 2026 г. |
39Наблюдать | CVE-2025-13392Эксплойта нет | Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3synology · diskstation manager · CWE-754 | Критическая9,8 | — | 0,5 % | 27 мая 2026 г. |
39Наблюдать | CVE-2024-7826Эксплойта нет | Unhandled exception vulnerability that can cause the WRSA.exe service to crash and generate a crash dumpwebroot · secureanywhere web shield · CWE-754 | Критическая9,8 | — | 0,4 % | 3 окт. 2024 г. |
38Наблюдать | CVE-2026-77411Эксплойта нет | RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstrrabbitmq · amqp091-go · CWE-754 | Критическая9,5 | — | 0,5 % | 16 сент. 2026 г. |
37Наблюдать | CVE-2026-0667Эксплойта нет | CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service andschneider electric · scadapack 47x · CWE-754 | Критическая9,3 | — | 0,5 % | 29 июл. 2026 г. |
- CVE-2024-339373На этой неделе
PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet
ВысокаяCVSS 8,7KEVГотовый эксплойтEPSS 28 %paloaltonetworks · pan-os27 дек. 2024 г.
- CVE-2023-4199372На этой неделе
The issue was addressed with improved checks.
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 24 %apple · ipados21 сент. 2023 г.
- CVE-2025-3968270На этой неделе
tls: fix handling of zero-length records on the rx_list
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 3 %linux · linux kernel5 сент. 2025 г.
- CVE-2023-4199264На этой неделе
The issue was addressed with improved checks.
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 10 %apple · ipados21 сент. 2023 г.
- CVE-2024-436756В плане
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context.
ВысокаяCVSS 8,8Proof of conceptEPSS 71 %mozilla · firefox14 мая 2024 г.
- CVE-2022-3928848В плане
Denial of service in Fastify via Content-Type header
ВысокаяCVSS 7,5Эксплойта нетEPSS 59 %fastify · fastify10 окт. 2022 г.
- CVE-2024-4304444В плане
Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by
ВысокаяCVSS 8,8Proof of conceptEPSS 29 %jenkins · jenkins7 авг. 2024 г.
- CVE-2022-2013042В плане
In transportDec_OutOfBandConfig of tpdec_lib.cpp, there is a possible out of bounds write due to a heap buffer overflow.
КритическаяCVSS 9,8Proof of conceptEPSS 9 %google · android15 июн. 2022 г.
- CVE-2020-2803741В плане
is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %wordpress · wordpress2 нояб. 2020 г.
- CVE-2019-1964641В плане
pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %sqlite · sqlite9 дек. 2019 г.
- CVE-2020-1057140В плане
An issue was discovered in psd-tools before 1.9.4.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %psd-tools project · psd-tools14 мар. 2020 г.
- CVE-2021-021140В плане
Junos OS and Junos OS Evolved: Upon receipt of a specific BGP FlowSpec message network traffic may be disrupted.
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %juniper · junos15 янв. 2021 г.
- CVE-2025-1192540В плане
Incorrect Content-Type Header
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %azure-access · blu-ic2 firmware17 окт. 2025 г.
- CVE-2020-898639Наблюдать
lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cookie, allowing an atta
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %zend · zendto24 мар. 2020 г.
- CVE-2017-2016639Наблюдать
Ecto 2.2.0 lacks a certain protection mechanism associated with the interaction between is_nil and raise.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ecto project · ecto10 янв. 2023 г.
- CVE-2021-3362239Наблюдать
Sylabs Singularity 3.5.x and 3.6.x, and SingularityPRO before 3.5-8, has an Incorrect Check of a Function's Return Value.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sylabs · singularity15 июн. 2021 г.
- CVE-2022-4578839Наблюдать
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of se
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %schneider-electric · ecostruxure control expert30 янв. 2023 г.
- CVE-2023-3730339Наблюдать
An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mediawiki · mediawiki30 июн. 2023 г.
- CVE-2023-4869639Наблюдать
Azure RTOS USBX Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %eclipse · threadx usbx4 дек. 2023 г.
- CVE-2023-4869839Наблюдать
Azure RTOS USBX Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %eclipse · threadx usbx4 дек. 2023 г.
- CVE-2026-809139Наблюдать
Incorrect boundary conditions in the Audio/Video: Playback component
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mozilla · firefox7 мая 2026 г.
- CVE-2025-1339239Наблюдать
Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %synology · diskstation manager27 мая 2026 г.
- CVE-2024-782639Наблюдать
Unhandled exception vulnerability that can cause the WRSA.exe service to crash and generate a crash dump
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %webroot · secureanywhere web shield3 окт. 2024 г.
- CVE-2026-7741138Наблюдать
RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr
КритическаяCVSS 9,5Эксплойта нетEPSS 1 %rabbitmq · amqp091-go16 сент. 2026 г.
- CVE-2026-066737Наблюдать
CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %schneider electric · scadapack 47x29 июл. 2026 г.