VulnSea

CWE-248

CVEs classified under CWE-248, newest first.

90 CVEsRSS

CVE-2024-58368High· 7.5
2mo ago

SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests containing special characters

SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests containing special characters. Unauthenticated attackers can send crafted HTTP requests with malformed header values to trigger a…

▾ TwilightEPSS 0.65%via NVD
CVE-2024-58365Medium· 6.5
2mo ago

SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls to nonexistent built-in functions

SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls to nonexistent built-in functions. Authorized clients can craft pre-parsed queries invoking nonexistent functions to …

▾ SunlitEPSS 0.45%via NVD
CVE-2024-58364Medium· 6.5
2mo ago

SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span rendering when parsing queries with errors on line terminator characters

SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span rendering when parsing queries with errors on line terminator characters. Authorized clients can submit malformed queries that trigger a panic i…

▾ SunlitEPSS 0.45%via NVD
CVE-2024-58361Medium· 6.5
2mo ago

SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser error rendering code when processing empty strings

SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser error rendering code when processing empty strings. Authorized clients can execute malformed queries with empty string conversions to reco…

▾ SunlitEPSS 0.45%via NVD
CVE-2024-58359Medium· 6.5
2mo ago

SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting mechanism when using ORDER BY rand() clause

SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting mechanism when using ORDER BY rand() clause. Authorized clients can execute queries with ORDER BY rand() to trigger a panic in the sorting function,…

▾ SunlitEPSS 0.45%via NVD
CVE-2024-58358Medium· 4.9
2mo ago

SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that allows privileged owner users to define users with nonexistent roles

SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that allows privileged owner users to define users with nonexistent roles. Attackers can trigger an uncaught panic by signing in with a user ass…

▾ SunlitEPSS 0.47%via NVD
CVE-2024-58357Medium· 6.5
2mo ago

SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time() function that panics when unwrap is called on a None result from timestamp_opt

SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time() function that panics when unwrap is called on a None result from timestamp_opt. Authorized clients can repeatedly invoke rand::time() to reli…

▾ SunlitEPSS 0.45%via NVD
CVE-2026-50328High· 7.5
2mo ago

Windows Server Update Service (WSUS) Tampering Vulnerability

Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 1.2%via CVEORG
CVE-2026-59162High· 7.5
2mo ago

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, Excelize parses shared-string cell values with strconv.Atoi and checks only the upper bound before indexing the shared string slice,…

▾ Twilightexcelize · excelizeEPSS 0.66%via NVD
CVE-2026-27844Low· 2.7
2mo ago

Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated and authorized operator to trigger a Controller restart by sending specific requests, resulting in a temporary denia…

Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated and authorized operator to trigger a Controller restart by sending specific requests, resulting in a temporary denia…

▾ Sunlitgallagher · command_centreEPSS 0.39%via NVD
CVE-2026-27790Low· 2.7
2mo ago

Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by sending specific requests, resulting in a temporary denial of service. Version of Command Centre affected: * …

Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by sending specific requests, resulting in a temporary denial of service. Version of Command Centre affected: * …

▾ Sunlitgallagher · command_centreEPSS 0.39%via NVD
CVE-2026-14631Medium· 5.3
2mo ago

webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends either a normal HTTP request with a malformed Host header or a WebSocket upgrade to the default /ws endpoint with a malf…

webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends either a normal HTTP request with a malformed Host header or a WebSocket upgrade to the default /ws endpoint with a malf…

▾ SunlitEPSS 0.52%via NVD
GHSA-c8w6-x74f-vmg3Medium· 6.5
2mo ago

zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers

zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers

▾ Sunlitzebra-rpc · zebra-rpcvia GHSA
GHSA-wjjj-24cx-f28gHigh· 7.5
2mo ago

SurrealDB has unauthenticated remote DoS via malformed RPC `use` call

SurrealDB has unauthenticated remote DoS via malformed RPC `use` call

▾ Twilightsurrealdb · surrealdbvia GHSA
CVE-2026-55517Medium· 4.3
3mo ago

Deno is a JavaScript, TypeScript, and WebAssembly runtime

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.5, a Deno program that opens a client WebSocket connection could be crashed by the remote server. While handling the WebSocket handshake response, Deno parsed the Se…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-12644Medium· 5.3
3mo ago

ts-deepmerge: Prototype Method Override leads to DoS

ts-deepmerge: Prototype Method Override leads to DoS

▾ Sunlitts-deepmerge · ts-deepmergeEPSS 0.51%via GHSA
CVE-2026-54775Medium· 6.5
3mo ago

CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.

CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.

▾ SunlitCoreWCF · CoreWCF.KafkaEPSS 0.60%via GHSA
CVE-2026-48038Medium· 5.3
3mo ago

joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas

joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas

▾ Sunlitjoi · joiEPSS 0.52%via GHSA
CVE-2026-48069High· 7.5
3mo ago

@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash

@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash

▾ Twilightgrpc · @grpc/grpc-jsEPSS 0.88%via GHSA
CVE-2026-48068High· 7.5
3mo ago

@grpc/grpc-js: A malformed request can cause a server crash

@grpc/grpc-js: A malformed request can cause a server crash

▾ Twilightgrpc · @grpc/grpc-jsEPSS 0.88%via GHSA
CVE-2026-44001High· 8.6
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox escape vulnerability in vm2 v3.10.5 allows any sandboxed code to crash the host Node.js process via a single Promise constructor that triggers an unhandled rejectio…

▾ Twilightvm2_project · vm2EPSS 0.66%via NVD
CVE-2026-34986High· 7.5
5mo ago

Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards

Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and …

▾ Twilightgo-jose_project · go-joseEPSS 0.76%via NVD
CVE-2026-33939High· 7.5
6mo ago

Handlebars provides the power necessary to let users build semantic templates

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, when a Handlebars template contains decorator syntax referencing an unregistered decorator (e.g. `{{*n}}`), the compiled temp…

▾ Twilighthandlebarsjs · handlebarsEPSS 0.76%via NVD
CVE-2026-2229High· 7.5
6mo ago

ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension

ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension. When a WebSocket client connects to a server, it automa…

▾ Twilightnodejs · undiciEPSS 0.87%via NVD
CVE-2026-1528High· 7.5
6mo ago

ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length

ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the proces…

▾ Twilightnodejs · undiciEPSS 0.49%via NVD
CVE-2026-31812Medium· 5.3
6mo ago

Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol

Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Prior to 0.11.14, a remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable quinn versions by sending a …

▾ SunlitEPSS 0.89%via NVD
CVE-2026-20068Medium· 5.8
6mo ago

Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspect…

Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspect…

▾ Sunlitcisco · snortEPSS 0.41%via NVD
CVE-2025-59465High· 7.5
8mo ago

A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash by triggering an unhandled `TLSSocket` error `ECONNRESET`

A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash by triggering an unhandled `TLSSocket` error `ECONNRESET`. Instead of safely closing the connection, the process crashes, enabling a remot…

▾ Twilightnodejs · node.jsEPSS 4.0%via NVD
CVE-2025-3891High· 7.5
1y ago

A flaw was found in the mod_auth_openidc module for Apache httpd

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The ser…

▾ Twilightapache · http_serverEPSS 1.6%via NVD
CVE-2024-28835Medium· 5.0
2y ago

A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool --verify-chain" command.

A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool --verify-chain" command.

▾ SunlitEPSS 0.39%via NVD
CWE-248 vulnerabilities (CVEs) — page 3 · VulnSea