VulnSea

CWE-754

CVEs classified under CWE-754, newest first.

53 CVEsRSS

CVE-2026-56812High· 7.5PoC
2mo ago

Improper Check for Unusual or Exceptional Conditions vulnerability in phoenixframework phoenix (Presence JavaScript client) allows an attacker with ordinary channel access to cause a persistent client-side denial of service against every…

Improper Check for Unusual or Exceptional Conditions vulnerability in phoenixframework phoenix (Presence JavaScript client) allows an attacker with ordinary channel access to cause a persistent client-side denial of service against every…

▾ Midnightphoenixframework · phoenixEPSS 0.80%via NVD
CVE-2026-35369Medium· 5.5
2mo ago

kill: 'kill -1' parsed as PID -1, sending SIGTERM to all processes (system crash / DoS)

kill: 'kill -1' parsed as PID -1, sending SIGTERM to all processes (system crash / DoS)

▾ Sunlituu_kill · uu_killEPSS 0.15%via GHSA
CVE-2026-35366Medium· 4.4
2mo ago

printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection)

printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection)

▾ Sunlituu_printenv · uu_printenvEPSS 0.19%via GHSA
GHSA-c8w6-x74f-vmg3Medium· 6.5
2mo ago

zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers

zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers

▾ Sunlitzebra-rpc · zebra-rpcvia GHSA
GHSA-wjjj-24cx-f28gHigh· 7.5
2mo ago

SurrealDB has unauthenticated remote DoS via malformed RPC `use` call

SurrealDB has unauthenticated remote DoS via malformed RPC `use` call

▾ Twilightsurrealdb · surrealdbvia GHSA
GHSA-4v76-cw68-4vc9Medium· 6.5
2mo ago

SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required

SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required

▾ Sunlitsurrealdb · surrealdbvia GHSA
CVE-2026-54775Medium· 6.5
3mo ago

CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.

CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.

▾ SunlitCoreWCF · CoreWCF.KafkaEPSS 0.60%via GHSA
CVE-2026-54269Medium· 5.3
3mo ago

protobufjs : Schema-derived names can shadow runtime-significant properties

protobufjs : Schema-derived names can shadow runtime-significant properties

▾ Sunlitprotobufjs · protobufjsEPSS 0.40%via GHSA
CVE-2026-0269Medium· 5.7
3mo ago

A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an authenticated user to initiate system reboots using a maliciously crafted packet

A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an authenticated user to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a rebo…

▾ Sunlitpaloaltonetworks · pan-osEPSS 0.22%via NVD
CVE-2026-5946High· 7.5
4mo ago

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question sec…

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question sec…

▾ Twilightisc · bindEPSS 1.7%via NVD
CVE-2026-0241High· 7.2
4mo ago

Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls and perform unauthorized actions on restricted resources.

Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls and perform unauthorized actions on restricted resources.

▾ Twilightpaloaltonetworks · trust_protection_foundationEPSS 0.34%via NVD
CVE-2026-42246High· 7.4
4mo ago

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return "successfully", without s…

▾ Twilightruby-lang · net::imapEPSS 0.40%via NVD
CVE-2026-8091Critical· 9.8
4mo ago

Incorrect boundary conditions in the Audio/Video: Playback component

Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.2.

▾ Midnightmozilla · firefoxEPSS 0.60%via NVD
CVE-2026-33774Medium· 6.5
5mo ago

An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass the configured firewall fil…

An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass the configured firewall fil…

▾ Sunlitjuniper · junosEPSS 0.29%via NVD
CVE-2026-31790High· 7.5
5mo ago

Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive da…

Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive da…

▾ Twilightopenssl · opensslEPSS 1.0%via NVD
CVE-2026-33939High· 7.5
6mo ago

Handlebars provides the power necessary to let users build semantic templates

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, when a Handlebars template contains decorator syntax referencing an unregistered decorator (e.g. `{{*n}}`), the compiled temp…

▾ Twilighthandlebarsjs · handlebarsEPSS 0.76%via NVD
CVE-2026-25639High· 7.5
7mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own proper…

▾ Twilightaxios · axiosEPSS 1.8%via NVD
CVE-2026-23991Medium· 5.9
8mo ago

github.com/theupdateframework/go-tuf/v2: go-tuf client DoS via malformed server response (CVE-2026-23991)

A denial of service flaw has been discovered in go-tuf. If the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic during parsing, causing a denial o…

▾ SunlitRed Hat · OpenShift PipelinesEPSS 0.59%via CSAF
CVE-2025-39682Critical· 9.8CISA KEVPoC⚖ disputed
1y ago

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA re…

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA re…

▾ Hadallinux · linux_kernelEPSS 2.9%via NVD
CVE-2025-32051Medium· 5.9
1y ago

A flaw was found in libsoup

A flaw was found in libsoup. The libsoup soup_uri_decode_data_uri() function may crash when processing malformed data URI. This flaw allows an attacker to cause a denial of service (DoS).

▾ SunlitEPSS 0.55%via NVD
CVE-2024-38355Medium· 7.3PoC
2y ago

socket.io has an unhandled 'error' event

socket.io has an unhandled 'error' event

▾ Twilightsocket.io · socket.ioEPSS 0.81%via GHSA
CVE-2021-47014High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: fix wild memory access when clearing fragments while testing re-assembly/re-fragmentation using act_ct, it's possible to observe a crash like the fo…

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: fix wild memory access when clearing fragments while testing re-assembly/re-fragmentation using act_ct, it's possible to observe a crash like the fo…

▾ Twilightlinux · linux_kernelEPSS 0.23%via NVD
CVE-2020-10571Critical· 9.8
6y ago

Potential buffer overflow in psd-tools

Potential buffer overflow in psd-tools

▾ Midnightpsd-tools · psd-toolsEPSS 1.8%via OSV
CWE-754 vulnerabilities (CVEs) — page 2 · VulnSea