VulnSea

CWE-404

CVEs classified under CWE-404, newest first.

82 CVEsRSS

CVE-2026-8266Medium· 4.3
4mo ago

A vulnerability was detected in Open5GS up to 2.7.7

A vulnerability was detected in Open5GS up to 2.7.7. This affects the function gsm_build_pdu_session_establishment_accept of the file /src/smf/gsm-build.c of the component SMF. The manipulation results in denial of service. The attack ca…

▾ Sunlitopen5gs · open5gsEPSS 0.68%via NVD
CVE-2026-8251Medium· 4.3
4mo ago

A vulnerability was found in Open5GS up to 2.7.7

A vulnerability was found in Open5GS up to 2.7.7. This impacts the function update_authorized_pcc_rule_and_qos of the file /src/smf/npcf-handler.c of the component SMF. Performing a manipulation results in denial of service. The attack i…

▾ Sunlitopen5gs · open5gsEPSS 0.68%via NVD
CVE-2026-8250Medium· 4.3
4mo ago

A vulnerability has been found in Open5GS up to 2.7.7

A vulnerability has been found in Open5GS up to 2.7.7. This affects the function smf_n4_build_qos_flow_to_modify_list of the file /src/smf/n4-build.c of the component SMF. Such manipulation leads to denial of service. The attack can be e…

▾ Sunlitopen5gs · open5gsEPSS 0.68%via NVD
CVE-2026-8249Medium· 4.3
4mo ago

A flaw has been found in Open5GS up to 2.7.7

A flaw has been found in Open5GS up to 2.7.7. The impacted element is the function update_authorized_pcc_rule_and_qos of the file /src/smf/npcf-handler.c of the component SMF. This manipulation causes denial of service. Remote exploitati…

▾ Sunlitopen5gs · open5gsEPSS 0.68%via NVD
CVE-2026-8248Medium· 4.3
4mo ago

A vulnerability was detected in Open5GS up to 2.7.7

A vulnerability was detected in Open5GS up to 2.7.7. The affected element is the function update_authorized_pcc_rule_and_qos of the file /src/smf/npcf-handler.c of the component SMF. The manipulation results in denial of service. The att…

▾ Sunlitopen5gs · open5gsEPSS 0.68%via NVD
CVE-2026-8232Low· 3.5
4mo ago

A vulnerability was found in Dotouch XproUPF 2.0.0-release-088aa7c4

A vulnerability was found in Dotouch XproUPF 2.0.0-release-088aa7c4. This impacts the function vlib_worker_loop in the library /usr/xpro/upf/tools/libs/libvlib.so of the component UPF Process. The manipulation results in denial of servic…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-8226Medium· 5.3
4mo ago

A security flaw has been discovered in Open5GS up to 2.7.7

A security flaw has been discovered in Open5GS up to 2.7.7. This vulnerability affects the function ogs_pcc_rule_install_flow_from_media in the library /lib/proto/types.c. The manipulation results in denial of service. The attack can be …

▾ Sunlitopen5gs · open5gsEPSS 0.85%via NVD
CVE-2026-8225Medium· 5.3
4mo ago

A vulnerability was identified in Open5GS up to 2.7.7

A vulnerability was identified in Open5GS up to 2.7.7. This affects the function pcf_npcf_smpolicycontrol_handle_delete of the file src/pcf/sm-sm.c of the component delete Endpoint. The manipulation leads to denial of service. The attack…

▾ Sunlitopen5gs · open5gsEPSS 0.85%via NVD
CVE-2026-8224Medium· 5.3
4mo ago

A vulnerability was determined in Open5GS up to 2.7.7

A vulnerability was determined in Open5GS up to 2.7.7. Affected by this issue is the function pcf_sess_set_ipv6prefix of the file /src/pcf/context.c of the component PCF. Executing a manipulation of the argument SmPolicyContextData.ipv6A…

▾ Sunlitopen5gs · open5gsEPSS 0.88%via NVD
CVE-2026-8223Medium· 5.3
4mo ago

A vulnerability was found in Open5GS up to 2.7.7

A vulnerability was found in Open5GS up to 2.7.7. Affected by this vulnerability is the function pcf_sess_sbi_discover_and_send of the component sm-policies Endpoint. Performing a manipulation results in denial of service. It is possible…

▾ Sunlitopen5gs · open5gsEPSS 0.85%via NVD
CVE-2026-8222Medium· 5.3
4mo ago

A vulnerability has been found in Open5GS up to 2.7.7

A vulnerability has been found in Open5GS up to 2.7.7. Affected is the function pcf_nbsf_management_handle_register of the file src/pcf/nbsf-handler.c of the component sm-policies Endpoint. Such manipulation leads to denial of service. T…

▾ Sunlitopen5gs · open5gsEPSS 0.85%via NVD
CVE-2025-13901Medium· 5.3
6mo ago

CWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine Expert protocol when an unauthenticated attacker sends malicious payload to occupy active communication channels.

CWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine Expert protocol when an unauthenticated attacker sends malicious payload to occupy active communication channels.

▾ SunlitEPSS 0.46%via NVD
CVE-2025-9784High· 7.5PoC
1y ago

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive serv…

▾ Midnightredhat · build_of_apache_camel_for_spring_bootEPSS 2.3%via NVD
CVE-2025-8732Low· 3.3
1y ago

A vulnerability was found in libxml2 up to 2.14.5

A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking …

▾ SunlitEPSS 0.21%via NVD
CVE-2022-35191Medium· 6.5
4y ago

D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via a crafted HTTP connection request.

D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via a crafted HTTP connection request.

▾ Sunlitdlink · dsl-3782_firmwareEPSS 1.0%via NVD
CVE-2022-25762High· 8.6
4y ago

If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use…

If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use…

▾ Twilightapache · tomcatEPSS 8.4%via NVD
CVE-2021-41441High· 7.4
4y ago

A DoS attack in the web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to reboot the router via sending a specially crafted URL to an authenticated victim

A DoS attack in the web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to reboot the router via sending a specially crafted URL to an authenticated victim. The authenticated victim need to…

▾ Twilightdlink · dir-x1860_firmwareEPSS 1.7%via NVD
CVE-2020-28874High· 7.5PoC
5y ago

reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic

reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not properly considered (an invalid token parameter).

▾ Midnightprojectsend · projectsendEPSS 2.4%via NVD
CVE-2020-3555Medium· 6.8
5y ago

A vulnerability in the SIP inspection process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a crash and reload of an affecte…

A vulnerability in the SIP inspection process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a crash and reload of an affecte…

▾ Sunlitcisco · adaptive_security_applianceEPSS 1.7%via NVD
CVE-2020-8619Medium· 4.9
6y ago

In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at le…

In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at le…

▾ Sunlitisc · bindEPSS 2.1%via NVD
CVE-2019-1708High· 8.6
7y ago

A vulnerability in the Internet Key Exchange Version 2 Mobility and Multihoming Protocol (MOBIKE) feature for the Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthent…

A vulnerability in the Internet Key Exchange Version 2 Mobility and Multihoming Protocol (MOBIKE) feature for the Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthent…

▾ Twilightcisco · secure_firewall_threat_defenseEPSS 2.0%via NVD
CVE-2018-8120High· 7.0CISA KEV0dayPoC
8y ago

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Serve…

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Serve…

▾ Abyssalmicrosoft · windows_7EPSS 73%via NVD
CWE-404 vulnerabilities (CVEs) — page 3 · VulnSea